Recommended Posts

As of recently it has been discovered that most routers expose UPnP to the outside world, which is not good at all. This allows attackers "from the internet" to open ports in your routers.

It is recommended you DISABLE UPnP in your router. Below is a test to see if your router is vulnerable. Steve Gibson, the creator of the very popular "Shields-up" which scans your IP for open ports in your router has recently added a test for the upnp vulnerability. Simply click the link then click the "proceed" button. You will then see a button for the UPnP test. Good luck!

The Test

https://www.grc.com/x/ne.dll?bh0bkyd2

  • Like 4

It is recommended you DISABLE UPnP in your router.

No; It is recommened that you get a good router. I have UPnP on my router enabled and

THE EQUIPMENT AT THE TARGET IP ADDRESS

DID NOT RESPOND TO OUR UPnP PROBES!

So either I have a good router or the test sucks.

It's only recommended to disable UPnP on your routers if they don't pass that test, which means they are exposing you to the outer world.

Just passed the test on three touters with UPnP enabled. Two of them are running DD-WRT.

post-203976-0-34939600-1359915937.png

THE EQUIPMENT AT THE TARGET IP ADDRESS

DID NOT RESPOND TO OUR UPnP PROBES!

Why would you disable uPnP anyways? It allows internal hosts to dynamically open ports like XBL or PSN for gaming and voice. Without it you'd have to manually open every single port those services and similar ones use. Just keep your internal hosts clean.

THE EQUIPMENT AT THE TARGET IP ADDRESS

DID NOT RESPOND TO OUR UPnP PROBES!

Why would you disable uPnP anyways? It allows internal hosts to dynamically open ports like XBL or PSN for gaming and voice. Without it you'd have to manually open every single port those services and similar ones use. Just keep your internal hosts clean.

Yeah I agree with keeping uPnP enabled also.

I ran many different servers over the years, long time ago now, so I had many ports opened for access, and that site's port tests always showed me as being safe and secure.

All depends on what type of security you're running on your computers.

There should be no issue with running UPnP/NAT-PMP on your router if it's properly configured, I knew mine would pass this test from the start since it exposes it's configuration in a good manner (It only allows hosts on the 192.168/16 subnet to create a forwarding rule, and said rule has to point at the host that requested it, otherwise it's rejected), and shows what ports are forwarded on what protocol.

Never mind the fact that the firewall should reject outside communication before it even gets to the UPnP/NAT-PMP daemon anyway, if it isn't being blocked you have bigger issues.

"Without it you'd have to manually open every single port those services and similar ones use."

So -- your talking a handful of ports at most.. UPnP is to allow unsolicted inbound traffic to get through your nat router. Traffic initiated by you, or in answer to your traffic is allowed.

Most people have no use of UPnP, it has been a nightmare since it was created -- who in their right mind thought, hey lets allow ports to be opened on your gateway/firewall without any sort of auth at all!!

And no UPnP should not be reachable via your public IP that is for damn sure.

I disable it anyway. The fact that UPnP, by design, lets any application communicate with the router and open ports should make any security conscious user uneasy.

If you trust what's in your network and have the routers firewall up I don't see how it could.

^ the point is UPnP can remove your firewall settings. Without even a nod to you that its doing so, nor any sort of auth method to allow it.

There really needs to be some form of notification and auth to the mechanism - and then sure it would be a valid tool in opening firewall ports for the masses.

THE EQUIPMENT AT THE TARGET IP ADDRESS

DID NOT RESPOND TO OUR UPnP PROBES!

Why would you disable uPnP anyways? It allows internal hosts to dynamically open ports like XBL or PSN for gaming and voice. Without it you'd have to manually open every single port those services and similar ones use. Just keep your internal hosts clean.

It would allow any malicious program to actively contact your router, open whatever ports it wants, and then transmit data through those ports all without your knowledge.... pretty big security hole if you ask me.

Steve Gibson, the person who creates the most FUD on the internet with his crazy rants and observations!!!

I'm not going to argue that the fact that he is crazy, which he probably is, but he is also very smart. And Facts do not = FUD.

Are you up to date on this UPnP issue? The typical way UPnP works is, an active program on one of the systems on your network will contact the router and open ports for whatever program/service to pass data through. Sounds ok right, well there is an exploit on a TON of routers that allows that request to be made from the OUTSIDE over the WAN, so if you have one of these affected routers, anyone outside your network, can open up ports into your network using a little bit of packet "magic". It's a pretty big deal.

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • Thank you for the feedback! I updated the image
    • Hmm wonder if I can share/resell the 'physical' edition like I can now.
    • Movavi Video Editor Plus 26.18.0 by Razvan Serea With Movavi Video Editor Plus, you can either enhance your video files with two or three simple steps, or turn them into something completely new. Create your own movies using multiple filters, transitions, and special effects: show multiple videos on one screen with the Picture in picture effect or change the background with the Chroma Key effect, imitate the camera zoom or make your video look like an old-style movie. Adjust video parameters such as brightness, contrast and colors. Stabilize shaky footage, improve video quality and remove defects. Create video presentations, tutorials or educational videos: add titles and record your own narration to create a video with voiceover. Import video from any source: TV-tuner, webcam, camcorder, or VHS. Drop multiple media files onto a timeline and let your imagination do the rest! Features at a glance: Video and audio editing on a timeline Edit, enhance videos Add background music Apply titles and effects Image quality improvement Hollywood-worthy effects High-grade titles and fades Digitize VHS tapes, record video from TV tuners Stabilize any shaky sections Support for a wide range of formats Prepare your videos for uploading to YouTube, Facebook, Vimeo, or any other website New in Movavi Video Editor 2026: 30+ fresh subtitle styles. Upgrade your automatic captions with new designs. Customize your text in the Styles tab with a single click. Optional advanced settings are also available in the dedicated Design tab. Subtitles in English – instantly! Translate auto-subtitles into English with a click – no dictionaries or online services needed. Once translated, configure and fine-tune the subtitles using the standard editing tools. 40+ adjustable effects. Enhance your videos in a click with new realistic effects – from dust particles and light leaks to retro-style and VHS. Every effect is fully customizable – so it will fit any clip perfectly and bring an extra spark to your edits. Ultra-fast playback. Show more in less time with video speed control of up to 100x. Perfect for epic time-lapses, long process recaps, or whenever you want to add some extra energy to your content. Magnetic zones are marked with dots, and the 1x value is indicated by a vertical line. Silence removal – in a click. Cut out unwanted pauses automatically or fine-tune the pause length and volume threshold yourself. Skip the tedious cleanup and make your videos more dynamic. Fast effect copying. Effortlessly duplicate any effect from one video to another: click Clip effects in the dropdown menu and proceed to copy or paste. Movavi Video Editor Plus 26.18.0 changes: This version includes small improvements for better editing. Download: Movavi Video Editor Plus 26.18.0 | 2.7 MB (Shareware) View: Movavi Video Editor Plus Website | Screenshot Get alerted to all of our Software updates on Twitter at @NeowinSoftware
    • JBL BAR 800 5.1.2 Dolby Atmos soundbar is an amazing deal today by Sayan Sen This Amazon Prime Day 2026 sales so far we have had a couple of nice deals related to sound and audio. First we have the Sennheiser HD 600 at its lowest ever price of just $225. Next we also have the Beats Studio Pro at its lowest price ever at just $150. However perhaps you prefer your gear to sound great on a larger scale, like throughout the room. In that case an all-in-one soundbar system can help and currently JBL's BAR 800 is a great deal for sure as it's up for grabs at just $600 (purchase link under the specs table down below). One thing that should be appreciated a lot about these JBL soundbars is their spec sheet and the frequency response data it provides. The firm is honest about it as JBL confirms the subwoofer is able to go down to 35 Hz at -6dB or F6. This means it should be covering 40Hz and up very well, where most of the bass lies. You miss out on a lot of sub-bass but that is to be expected given the price point and the subwoofer driver size. Speaking of which, it is a 10-inch driver and promises a max output power of 300 watts at 1% THD (total harmonic distortion). JBL also claims the system will provide you with a "True Dolby Atmos" experience. The surround speakers are wireless and battery-powered which means setting them up should be really convenient. The technical specs of the JBL BAR 800 are given in the table below: Specification Value Channel Configuration 5.1.2-channel soundbar system Dolby Atmos Yes, with 2 up-firing drivers Total System Power Output 720 W Soundbar Power Output 340 W Surround Speaker Power Output 2 × 40 W Subwoofer Power Output 300 W Soundbar Drivers 3 × 46×90 mm racetrack drivers, 3 × 20 mm tweeters, 2 × 70 mm up-firing full-range drivers Surround Speaker Drivers 1 × 46×90 mm racetrack driver (each speaker) Subwoofer Driver 10-inch (260 mm) wireless subwoofer Frequency Response 35 Hz – 20 kHz (-6 dB) Audio Inputs Optical, Bluetooth, Chromecast built-in, AirPlay, Alexa Multi-Room Music (MRM), USB* HDMI Inputs 1 HDMI video input HDMI Output 1 HDMI eARC output HDCP Version 2.3 HDR Pass-Through HDR10, Dolby Vision Bluetooth Version 5.0 Wi-Fi Version 6, 6E Streaming Services Chromecast built-in, Apple AirPlay, Alexa MRM Get it at the link below: JBL Bar 800-5.1.2-Channel Dolby Atmos soundbar with Detachable Surround Speakers (Black): $599.85 (Sold and Shipped by Amazon US with Prime) Prime subscription can be cancelled within three business days. Good to know This Amazon deal is U.S. specific, and not available in other regions unless specified. We only use first-party seller links (at the time of article publishing); ensure that you purchase from a first-party seller link only. Check out Today's Deals on Amazon | or our recent tech deals. Become a Prime member (for Students or SNAP) via Neowin Get Prime Access - Prime for half price (for qualifying Medicaid, EBT, SNAP) Subscribe to Prime Video, Audible Plus, Music Unlimited or Kindle Unlimited via Neowin As an Amazon Associate, we earn from qualifying purchases.
    • Microsoft releases PowerToys v0.100.1, fixes a bug that made remapped keys misbehave by Ivan Jenic Microsoft just released PowerToys v0.100.1, a patch update that addresses several stability and behavior issues found in v0.100.0. The v0.100.0 patch was a significant update for PowerToys, as it introduced all sorts of new features and additions, such as a rebuilt Shortcut Guide, a Command Palette Extension Gallery, webcam overlay support in ZoomIt, and more. However, the v0.100.0 version also introduced some bugs and stability issues. And now, Microsoft is addressing these issues in the new patch. The most impactful fix in this release perhaps is in Keyboard Manager, where remapped modifier keys were being delivered as system-key events, causing unexpected behavior in apps. The clearest example of this was Alt-to-Backspace remaps, deleting whole words instead of a single character. So, if you thought there was an issue with your keyboard, Microsoft just confirmed that it was PowerToys. Beyond the Keyboard Manager fix, v0.100.1 also addresses several other issues. It fixes a bug with Power Display that was preventing monitors from waking from standby correctly. Additionally, the new update patches Quick Access crashes on launch, and resolves a Shortcut Guide crash that occurred when switching between sidebar sections. Here’s the full changelog: Color Picker Fixed a bug where the main Color Picker window could appear inside the zoomed-in picker view Command Palette Fixed Run history initialization in AOT builds Fixed a bug where the Performance Monitor dock item could show ??? after restart Fixed the Hibernate command using the Sleep icon Limited the "pin to dock" dialog to displays where the dock is enabled Keyboard Manager Fixed modifier keys remapped to non-modifier keys being delivered as system-key events, which caused unexpected behavior in apps such as Alt-to-Backspace deleting whole words Power Display Fixed a bug where selecting On in the monitor power-state control did not wake a monitor from standby Fixed built-in display detection and brightness control on dual-GPU laptops where the internal panel is driven by the discrete GPU PowerToys Run Fixed VS Code Workspaces discovery after VS Code moved recently opened workspace data to shared storage Quick Access Fixed Quick Access flyout crashes caused by unhandled XAML exceptions during launch or page navigation Shortcut Guide Fixed a crash when navigating between Shortcut Guide sidebar sections Fixed number-key rendering in shortcut manifests and added a Postman shortcut manifest Updated bundled shortcut manifests to use the literal number-key token so number keys render correctly across apps ZoomIt Fixed a race condition in audio initialization for ZoomIt video recording You can download PowerToys v0.100.1 from the official GitHub releases page.
  • Recent Achievements

    • One Year In
      OHI Accounting earned a badge
      One Year In
    • First Post
      Almohandis earned a badge
      First Post
    • Rookie
      DaviKar went up a rank
      Rookie
    • Dedicated
      HidekoYamamoto94 earned a badge
      Dedicated
    • One Month Later
      timbobit earned a badge
      One Month Later
  • Popular Contributors

    1. 1
      +primortal
      473
    2. 2
      +Edouard
      175
    3. 3
      PsYcHoKiLLa
      122
    4. 4
      Michael Scrip
      82
    5. 5
      Xenon
      75
  • Tell a friend

    Love Neowin? Tell a friend!