Recommended Posts

As of recently it has been discovered that most routers expose UPnP to the outside world, which is not good at all. This allows attackers "from the internet" to open ports in your routers.

It is recommended you DISABLE UPnP in your router. Below is a test to see if your router is vulnerable. Steve Gibson, the creator of the very popular "Shields-up" which scans your IP for open ports in your router has recently added a test for the upnp vulnerability. Simply click the link then click the "proceed" button. You will then see a button for the UPnP test. Good luck!

The Test

https://www.grc.com/x/ne.dll?bh0bkyd2

It is recommended you DISABLE UPnP in your router.

No; It is recommened that you get a good router. I have UPnP on my router enabled and

THE EQUIPMENT AT THE TARGET IP ADDRESS

DID NOT RESPOND TO OUR UPnP PROBES!

So either I have a good router or the test sucks.

It's only recommended to disable UPnP on your routers if they don't pass that test, which means they are exposing you to the outer world.

Just passed the test on three touters with UPnP enabled. Two of them are running DD-WRT.

post-203976-0-34939600-1359915937.png

THE EQUIPMENT AT THE TARGET IP ADDRESS

DID NOT RESPOND TO OUR UPnP PROBES!

Why would you disable uPnP anyways? It allows internal hosts to dynamically open ports like XBL or PSN for gaming and voice. Without it you'd have to manually open every single port those services and similar ones use. Just keep your internal hosts clean.

THE EQUIPMENT AT THE TARGET IP ADDRESS

DID NOT RESPOND TO OUR UPnP PROBES!

Why would you disable uPnP anyways? It allows internal hosts to dynamically open ports like XBL or PSN for gaming and voice. Without it you'd have to manually open every single port those services and similar ones use. Just keep your internal hosts clean.

Yeah I agree with keeping uPnP enabled also.

I ran many different servers over the years, long time ago now, so I had many ports opened for access, and that site's port tests always showed me as being safe and secure.

All depends on what type of security you're running on your computers.

There should be no issue with running UPnP/NAT-PMP on your router if it's properly configured, I knew mine would pass this test from the start since it exposes it's configuration in a good manner (It only allows hosts on the 192.168/16 subnet to create a forwarding rule, and said rule has to point at the host that requested it, otherwise it's rejected), and shows what ports are forwarded on what protocol.

Never mind the fact that the firewall should reject outside communication before it even gets to the UPnP/NAT-PMP daemon anyway, if it isn't being blocked you have bigger issues.

"Without it you'd have to manually open every single port those services and similar ones use."

So -- your talking a handful of ports at most.. UPnP is to allow unsolicted inbound traffic to get through your nat router. Traffic initiated by you, or in answer to your traffic is allowed.

Most people have no use of UPnP, it has been a nightmare since it was created -- who in their right mind thought, hey lets allow ports to be opened on your gateway/firewall without any sort of auth at all!!

And no UPnP should not be reachable via your public IP that is for damn sure.

I disable it anyway. The fact that UPnP, by design, lets any application communicate with the router and open ports should make any security conscious user uneasy.

If you trust what's in your network and have the routers firewall up I don't see how it could.

^ the point is UPnP can remove your firewall settings. Without even a nod to you that its doing so, nor any sort of auth method to allow it.

There really needs to be some form of notification and auth to the mechanism - and then sure it would be a valid tool in opening firewall ports for the masses.

THE EQUIPMENT AT THE TARGET IP ADDRESS

DID NOT RESPOND TO OUR UPnP PROBES!

Why would you disable uPnP anyways? It allows internal hosts to dynamically open ports like XBL or PSN for gaming and voice. Without it you'd have to manually open every single port those services and similar ones use. Just keep your internal hosts clean.

It would allow any malicious program to actively contact your router, open whatever ports it wants, and then transmit data through those ports all without your knowledge.... pretty big security hole if you ask me.

Steve Gibson, the person who creates the most FUD on the internet with his crazy rants and observations!!!

I'm not going to argue that the fact that he is crazy, which he probably is, but he is also very smart. And Facts do not = FUD.

Are you up to date on this UPnP issue? The typical way UPnP works is, an active program on one of the systems on your network will contact the router and open ports for whatever program/service to pass data through. Sounds ok right, well there is an exploit on a TON of routers that allows that request to be made from the OUTSIDE over the WAN, so if you have one of these affected routers, anyone outside your network, can open up ports into your network using a little bit of packet "magic". It's a pretty big deal.

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • AMD releases hotfix for driver install issues on Windows 10 PCs by Taras Buria Earlier this week, AMD released an important graphics driver update. Version 26.6.2 brought AMD FSR 4.1 support to the previous-gen Radeon lineup, the RX 7000 series, giving users better upscaling tech that was previously locked to the newest GPUs. However, the driver turned out to be a little buggy, with users reporting installation issues on systems still running Windows 10. AMD quickly acknowledged the bug and today released a hotfix to resolve the problem. The AMD 26.6.3 Hotfix update is now available for download from the official website. Given that it is a hotfix release, it has only one change in its release notes: AMD announced the update on its official X account and added that a WHQL driver update with the necessary fixes would be released next week. Meanwhile, users can apply the hotfix or roll back to the previous driver using the official AMD Cleanup Utility. You can download AMD Software: Adrenalin Edition 26.6.3 Hotfix Preview Driver from the official website here. It is compatible with all currently supported graphics cards and 64-bit Windows 10 and 11. Full release notes are available on the same page.
    • With Microsoft now listening to its core audience and acting upon received feedback, fans can finally expect a much better version of Windows 11 than what was available five years ago. Here is to five more years, Windows 11! I guess we all need a good laugh now and again...
    • Amazon Prime Day 2026 deal sees Samsung Odyssey 49" 240Hz QD-OLED monitor at lowest price by Sayan Sen Earlier today we covered a very good deal on JBL's BAR 800 Dolby Atmos soundbar system as the unit is available for just $600 as part of Amazon Prime Day 2026 deals. That's not all though as there are many more discounts to choose from. If you are looking for a high-end monitor, Samsung's 49 inch G9 QD-OLED gaming monitor is a solid deal too as it's currently just $855 (purchase link under the specs table down below). It is a super-ultrawide (32:9) 1440p curved gaming monitor and as such should offer a very immersive experience. The G93SC is a 49-inch QD-OLED (Quantum Dot OLED) screen and that means it should have excellent contrast as well as color reproduction. Brightness is a bit lacking though so if you are looking to set it up in a relatively bright room, you may be better off with something else. Speaking of external light and brightness, the major difference on the G93SC vs the newer G93SD is that the latter comes with Samsung's "Glare Free" technology to reduce glare while the C model packs a glossy finish. The technical specifications of the Samsung G93SC are given in the table below: Specification Value Panel Type OLED Screen Shape Curved Screen Curvature 1800R Resolution DQHD (5120 × 1440) Aspect Ratio 32:9 Brightness (Typical) 250 cd/m² Brightness (Minimum) 200 cd/m² Contrast Ratio 1,000,000:1 HDR Support VESA DisplayHDR True Black 400 HDR10+ HDR10+ Gaming Response Time 0.03 ms (GTG) Refresh Rate Up to 240 Hz Viewing Angle 178° Horizontal / 178° Vertical Color Support 1 Billion Colors Color Gamut 99% DCI-P3 (CIE1976) Adaptive Sync FreeSync Premium Pro / G-SYNC Compatible DisplayPort 1 × DisplayPort 1.4 HDMI 1 × HDMI 2.1 Micro HDMI 1 × Micro HDMI 2.1 USB Hub 3 × USB 3.0 Speakers Built-in Speaker Output 5W × 2 Channels Operating Temperature 10°C – 40°C Operating Humidity 10–80% (Non-condensing) Stand Type Height Adjustable Stand (HAS) Height Adjustment 120.0 ± 5.0 mm Tilt -2° (±2°) to 15° (±2°) Wall Mount 100 × 100 mm (VESA) Included HDMI Cable HDMI-to-Micro HDMI Cable Included DisplayPort Cable Yes Get it at the link below: Samsung 49" Odyssey G93SC Series Curved Gaming Monitor, QD-OLED: $854.99 (Sold and Shipped by Amazon US with Prime) Prime subscription can be cancelled within three business days at no cost. Good to know This Amazon deal is U.S. specific, and not available in other regions unless specified. We only use first-party seller links (at the time of article publishing); ensure that you purchase from a first-party seller link only. Check out Today's Deals on Amazon | or our recent tech deals. Become a Prime member (for Students or SNAP) via Neowin Get Prime Access - Prime for half price (for qualifying Medicaid, EBT, SNAP) Subscribe to Prime Video, Audible Plus, Music Unlimited or Kindle Unlimited via Neowin As an Amazon Associate, we earn from qualifying purchases.
    • Actually Windows 11 is the GUI from Windows 10 X slapped onto Windows 10. Hence the many performance issues and initial limitations of the UI, like all the restrictions on the task bar placement and features. You could not even right click on the Taskbar and bring up task manager when it first shipped. Windows 10X was truly a new OS from the ground up. Basically a lightweight OS that ran containers for various app types. Win32 got its own container. Performance was not good and OEM’s pushed back on it, but wanted a new OS to push Pc sales. Hence Windows 11. https://en.wikipedia.org/wiki/Windows_10X
    • Windows 10 was 6 years old when Microsoft revealed Windows 11. Does this mean Windows 12 is due next year?
  • Recent Achievements

    • Dedicated
      Scoobystu earned a badge
      Dedicated
    • First Post
      Tom Schmidt earned a badge
      First Post
    • One Month Later
      D0nn13 earned a badge
      One Month Later
    • Rookie
      +ChiefOfNeo went up a rank
      Rookie
    • One Year In
      Tom Schmidt earned a badge
      One Year In
  • Popular Contributors

    1. 1
      +primortal
      458
    2. 2
      +Edouard
      177
    3. 3
      PsYcHoKiLLa
      123
    4. 4
      Michael Scrip
      81
    5. 5
      Xenon
      76
  • Tell a friend

    Love Neowin? Tell a friend!