Recommended Posts

My main router is an old (and I mean REALLY old) Netgear RP614 v2, and it is not vulnerable. :huh:

Edit: Happy Birthday, Budman!!!! :punk: :pint: :pint: :pint: :pint: :pint: :pint: :pint: :pint: :pint: :pint: :pint: :pint:

To those who don't get it and want the short version:

The problem is that some routers will respond to UPnP requests, wherever they're coming from. If they're coming from the LAN--no problem (unless you don't trust other machines/devices within your own LAN). If they're coming from the WAN port--then that's bad and you should disable it.

If you need more details than that, then listen to the podcast on the GRC site.

I disable it anyway. The fact that UPnP, by design, lets any application communicate with the router and open ports should make any security conscious user uneasy.

Not really. At this point you have already lost and been invaded anyway, and the route out should be of much more concern than than the route in, and if the program in question can open a route in, it's also capable to two way communication without opening a port.

that site is scaremongering at best anyway. notice how it ONLY reports how many "open" routers has been found with the test, not how many secure ones.

It would allow any malicious program to actively contact your router, open whatever ports it wants, and then transmit data through those ports all without your knowledge.... pretty big security hole if you ask me.

From the inside, at which point you've already lost and UPnP isn't needed anyway

THE EQUIPMENT AT THE TARGET IP ADDRESS

DID NOT RESPOND TO OUR UPnP PROBES!

Amped Wireless R20000G Passed! UPnP Enabled

Also mine's not on the affected devices list either!!!! Go Amped!!!!

Also mine shipped with uPnP disabled as well as WPS disabled. Extra points for them!

So is this a just rubbish. Default settings on router since I bought it and I got a pass.

I just have a forward to my web server.

Router is

Netgear DG834GT with the firmware updated to the latest.

I have an Airport Extreme router. I don't see an option for UPnP on the Airport Utility. Then again, it doesn't have many options at all.

THE EQUIPMENT AT THE TARGET IP ADDRESS

SUED OUR UPnP PROBES!

Today I had to help setup a computer for a little old lady. While I was there I ran the UPnP test. Her's failed! She had a D-link (Go figure) .... logged into the router and turned off UPnP, ran the test again and then it passed. So the rest does work!

Still not sure how people think this is suddenly new... it's been like that for a while. Didn't one of the US agencies mention this years ago?

I've always suggested to disable UPnP.

Because UPnP should NEVER be on the WAN side (internet). This means a bad guy could send a packet to your IP and if your router responds (Which is what this test is for) he could open a port in your route from the outside (Internet)

pfSense, enough said.

Not practical for the average consumer, enough said.

From the inside, at which point you've already lost and UPnP isn't needed anyway

Not from the inside, the exploit is that it responds to UPnP from the WAN side, that's the problem.

Not really. At this point you have already lost and been invaded anyway, and the route out should be of much more concern than than the route in, and if the program in question can open a route in, it's also capable to two way communication without opening a port.

that site is scaremongering at best anyway. notice how it ONLY reports how many "open" routers has been found with the test, not how many secure ones.

I think your failing to understand the exploit, typically the packet is formed on the LAN side from an application, which is passed to the router, the router opens up the ports requested. The problem is here, if you are running one of the exploitable routers, ANYONE from the WAN side, can sent a correctly formed packet to your router, over the net, and your router will open the port for them. This should never be allowed on the WAN interface.

that site is scaremongering at best anyway. notice how it ONLY reports how many "open" routers has been found with the test, not how many secure ones.

That is because MOST routers SHOULD pass the test!!! There shouldn't be very many routers that by default have UPnP on the WAN. The people who have run this test in this thread have proven that.

It's a MUCH bigger deal if you fail the test than if you pass it.

uPnP is the dumbest idea. whats the point of the firewall if applications are just going to open dat dere ports anyways? if you get a piece of malware that runs a server on your pc,it will just open the ports it wants,and runs beautifully. if you open your own ports,you at least know what you're getting yourself into. you don't even have to have malware. you might have a vulnerable application that is actively listening on a port.

guys please be sure you specify the router you are using for the tests... some of you didn't and that's not helpful...

That is because MOST routers SHOULD pass the test!!! There shouldn't be very many routers that by default have UPnP on the WAN. The people who have run this test in this thread have proven that.

It's a MUCH bigger deal if you fail the test than if you pass it.

My Amped Wireless R20000G and my R10000 both shipped with UPNP disabled.

I enabled on both and they pass the test and "do not respond"

guys please be sure you specify the router you are using for the tests... some of you didn't and that's not helpful...

My Amped Wireless R20000G and my R10000 both shipped with UPNP disabled.

I enabled on both and they pass the test and "do not respond"

I agree they could list their router. But we are already more than 4 pages in. So people could either flip through the pages looking to see if someone who ran the test has the same router than them, or they could just go to the site and click the button.

This thread was created not really as a list of routers affected but as away people can test themselves against the issue.

uPnP is the dumbest idea. whats the point of the firewall if applications are just going to open dat dere ports anyways? if you get a piece of malware that runs a server on your pc,it will just open the ports it wants,and runs beautifully. if you open your own ports,you at least know what you're getting yourself into. you don't even have to have malware. you might have a vulnerable application that is actively listening on a port.

It's so that when somebodies mother who views the computer as a magic box wants to make a Skype call with somebody, she doesn't have to reconfigure the firewall to let things pass through.

I'm running a dual stack (v4/v6) setup, and the UPnP daemon I'm running doesn't support the v6 side yet so any open ports only happen for v4 traffic. It's surprisingly annoying to track down what uses what ports to add them to the firewall.

This topic is now closed to further replies.
  • Recently Browsing   0 members

    • No registered users viewing this page.
  • Posts

    • Microsoft raises Xbox console prices by up to $150, discontinues 2TB version by Pulasthi Ariyasinghe Back in March, Sony increased PlayStation 5 prices, and now, it's Microsoft's turn. Today, the company announced a major price increase that will affect all of its Xbox consoles, and one storage option is being discontinued entirely. There is some time before the new prices go into effect. Starting on August 1, 2026, any Xbox Series X|S model with 512GB of storage will cost $100 more than now. The price of 1TB models will go up by $150 instead. At the same time, all 2TB models are being discontinued. "The entire consumer electronics industry is struggling with the current components crisis, but the effects are particularly hard on consoles," said the company. "Unlike phones, computers, speakers, and other consumer devices, consoles are typically not sold at a profit, but instead for less than they cost to make." As the hikes hit, Microsoft is beginning to offer more options to make its consoles more accessible to potential customers, including financing, buy now, pay later schemes, and refurbished options: Buy Now, Pay Later: We’ve made it easier for players to use Buy Now, Pay Later options on eligible XBOX hardware purchases through Microsoft Stores, making it possible to break up your payment into predictable short-term, interest-free installments. Interest-Free Financing: Players purchasing eligible XBOX hardware through Amazon can take advantage of 0% APR financing for up to 12 months, giving players more flexibility with lower monthly payments and more budgeting control. Previously Played Consoles: We are working with retail partners on new programs to provide previously played consoles at lower prices. Players who are ready to upgrade or no longer use their console will be able to trade it in with participating retail partners for cash or store credit. Those consoles will then be made available at lower prices for players. Certified Refurbished Consoles: XBOX Certified Refurbished Consoles are available at Microsoft Stores for up to US$100 off MSRP. Microsoft said that the rising cost of storage and memory prices is behind this decision, with costs going up by over 2.5 times since the last time it raised prices of its consoles. The company says these parts are expected to double in price by the fall of 2027.
    • Vivaldi 8.0.4033.54 by Razvan Serea Vivaldi is a cross-platform web browser built for – and with – the web. A browser based on the Blink engine (same in Chrome and Chromium) that is fast, but also a browser that is rich in functionality, highly flexible and puts the user first. A browser that is made for you. Vivaldi is produced with love by a founding team of browser pioneers, including former CEO Jon Stephenson von Tetzchner, who co-founded and led Opera Software. Vivaldi’s interface is very customizable. Vivaldi combines simplicity and fashion to create a basic, highly customizable interface that provides everything a internet user could need. The browser allows users to customize the appearance of UI elements such as background color, overall theme, address bar and tab positioning, and start pages. Vivaldi features the ability to "stack" and "tile" tabs, annotate web pages, add notes to bookmarks and much more. Vivaldi 8.0.4033.54 changes: [Ad Blocker] Blocks first-party request for third-party rules (VB-129201) [Chromium] Update to 148.0.7778.282 ESR (includes security fixes from 149.0.7827.196/197) [Scroll] Not possible when cursor at the edge of the window (VB-128008) Download: Vivaldi 64-bit | 139.0 MB (Freeware) Download: Vivaldi 32-bit | ARM64 View: Vivaldi Home Page | Screenshot Get alerted to all of our Software updates on Twitter at @NeowinSoftware
    • Save 70% on AcePDF Editor + Converter: Lifetime License for Mac by Steven Parker Today's highlighted deal comes via our Apps + Software section of the Neowin Deals store, where you can save 70% on a lifetime license to AcePDF Editor + Converter. This all-in-one PDF converter and creator software enables you to convert PDF documents into a variety of formats or processes and create PDF files from other formats in just a few clicks. The super high output quality is ensured as all the original layouts, images, texts, hyperlinks, etc. will be preserved without any quality loss. With the lasted technology, the software can convert PDF at ultra-fast speed while the quality won't be compromised. It works stable and has been trusted by numerous personal and business users. Whenever you need a PDF document conversion tool, AceThinker PDF Converter Pro can be your first choice. Convert from PDF: Change and backup your PDF files to Microsoft Word, Excel, PowerPoint, Text, HTML, PNG, and JPG for conveniently editing and viewing. Convert to PDF: It's also an excellent PDF converter to create PDF from Word, Excel, PPT, and image for easier transferring and backup. Convert Scanned PDF: Thanks to the built-in OCR technology, now it’s possible to extract text from image-based PDF documents with the original format and graph. More Features Merge PDF. Merge multiple PDF files into a single PDF document as you wish easily and quickly. Split PDF. You can extract every page into PDF or split only the selected PDF pages you need freely. Extract Images from PDF. This feature enables you to extract all the JPGs and PNGs from a PDF file in 1 click. Compress PDF. If your PDF is too large and you want to reduce the size, you can compress it to a smaller size. Unlock PDF. You can unlock your PDF document by entering the password to remove the password protection. Protect PDF. Simply enter the password you want and click Convert to encrypt and protect your PDF immediately. What's New Improvement of overall interface Added OCR function for extracting texts in multiple languages from scans Added batch process for converting multiple PDF documents Added supports for more document formats Merged with the editing functions, including annotation, change text, add/remove image, etc. Fixed some bugs Good to know Length of access: lifetime Redemption deadline: redeem your code within 30 days of purchase Access options: desktop Max number of devices: 2 Version: v1.4.6.0 Updates included This AcePDF Editor + Converter lifetime license normally costs $99.99, but you can pick it up for just $29.99 - that's a savings of $60 (66% off). For a full description, spec, and license info, click the link below. Get AcePDF Editor + Converter deal for just $24 (was $99.99) Use coupon code EXTRA20 for the above price Although priced in U.S. dollars, this deal is available for digital purchase worldwide. Support queries If you have queries or need support for any of the Neowin Deals, please use the contact form here. Neowin Deals are managed and sold by StackCommerce who represent Neowin on an affiliate basis. Why we post these deals We post these because we earn commission on each sale so as not to rely solely on advertising, which many of our readers block. It all helps toward paying staff reporters, servers and hosting costs. So for those that keep moaning and complaining, be thankful we're still online for you to even do that. Other ways to support Neowin Whitelist Neowin by not blocking our ads Create a free member account to see fewer ads Make a donation to support our day to day running costs Subscribe to Neowin - for $14 a year, or $28 a year for an ad-free experience Disclosure: Neowin benefits from revenue of each sale made through our branded deals site powered by StackCommerce.
  • Recent Achievements

    • First Post
      kinowa earned a badge
      First Post
    • Rookie
      krychek57 went up a rank
      Rookie
    • Grand Master
      Jaybonaut went up a rank
      Grand Master
    • One Year In
      Philsl earned a badge
      One Year In
    • Dedicated
      Scoobystu earned a badge
      Dedicated
  • Popular Contributors

    1. 1
      +primortal
      409
    2. 2
      +Edouard
      168
    3. 3
      PsYcHoKiLLa
      132
    4. 4
      Xenon
      73
    5. 5
      Michael Scrip
      73
  • Tell a friend

    Love Neowin? Tell a friend!