Software // Enterprise Applications
News
1/15/2008
03:01 PM
Connect Directly
Google+
LinkedIn
Twitter
RSS
E-Mail
50%
50%

Severe UPnP Flaw Allows Router Hijacking

Security researchers warn that 99% of home routers are vulnerable to this attack.

A vulnerability in networking devices that support UPnP (Universal Plug and Play) can be exploited through a malicious SWF (Flash) file on a Web site, US-CERT warned Monday.

Visiting such a Web site may allow an attacker to reconfigure or take over devices connected to the victim's system that support UPnP. This includes routers, cameras, printers, mobile phones, and digital entertainment systems.

The attack has been explored in more detail on GNUCitizen.org, a security consultancy.

Petko D. Petkov, the group's founder, describes the UPnP/Flash vulnerability as "highly severe." Successfully executing the attack allows the attacker to take over the affected router, allowing him or her to bypass firewalls, access Web router administration pages, attack Internet hosts through the router, and alter networking settings.

"The most malicious of all malicious things is to change the primary DNS server," Petkov explains. "That will effectively turn the router and the network it controls into a zombie which the attacker can take advantage of [at will]. It is also possible to reset the admin credentials and create the sort of onion routing network all the bad guys want."

Petkov warns that 99% of home routers are vulnerable to this attack. Along with US-CERT, he warns that anyone with UPnP devices turn off the UPnP protocol (consult your router manual). UPnP is typically turned on by default and contains no form of authentication to prevent this attack, according to Petkov.

Disabling Adobe's Flash software may not be effective, Petkov cautions, because other Web technologies may also provide a means to exploit the UPnP flaw.

Comment  | 
Print  | 
More Insights
Building A Mobile Business Mindset
Building A Mobile Business Mindset
Among 688 respondents, 46% have deployed mobile apps, with an additional 24% planning to in the next year. Soon all apps will look like mobile apps and it's past time for those with no plans to get cracking.
Register for InformationWeek Newsletters
White Papers
Current Issue
InformationWeek Government Tech Digest Oct. 27, 2014
To meet obligations -- and avoid accusations of cover-up and incompetence -- federal agencies must get serious about digitizing records.
Video
Slideshows
Twitter Feed
InformationWeek Radio
Archived InformationWeek Radio
A roundup of the top stories and community news at InformationWeek.com.
Sponsored Live Streaming Video
Everything You've Been Told About Mobility Is Wrong
Attend this video symposium with Sean Wisdom, Global Director of Mobility Solutions, and learn about how you can harness powerful new products to mobilize your business potential.