Severe UPnP Flaw Allows Router Hijacking - InformationWeek
IoT
IoT
Software // Enterprise Applications
News
1/15/2008
03:01 PM
Connect Directly
Google+
LinkedIn
Twitter
RSS
E-Mail
50%
50%
RELATED EVENTS
[Dark Reading Crash Course] Finding & Fixing Application Security Vulnerabilitie
Sep 14, 2017
Hear from a top applications security expert as he discusses key practices for scanning and securi ...Read More>>

Severe UPnP Flaw Allows Router Hijacking

Security researchers warn that 99% of home routers are vulnerable to this attack.

A vulnerability in networking devices that support UPnP (Universal Plug and Play) can be exploited through a malicious SWF (Flash) file on a Web site, US-CERT warned Monday.

Visiting such a Web site may allow an attacker to reconfigure or take over devices connected to the victim's system that support UPnP. This includes routers, cameras, printers, mobile phones, and digital entertainment systems.

The attack has been explored in more detail on GNUCitizen.org, a security consultancy.

Petko D. Petkov, the group's founder, describes the UPnP/Flash vulnerability as "highly severe." Successfully executing the attack allows the attacker to take over the affected router, allowing him or her to bypass firewalls, access Web router administration pages, attack Internet hosts through the router, and alter networking settings.

"The most malicious of all malicious things is to change the primary DNS server," Petkov explains. "That will effectively turn the router and the network it controls into a zombie which the attacker can take advantage of [at will]. It is also possible to reset the admin credentials and create the sort of onion routing network all the bad guys want."

Petkov warns that 99% of home routers are vulnerable to this attack. Along with US-CERT, he warns that anyone with UPnP devices turn off the UPnP protocol (consult your router manual). UPnP is typically turned on by default and contains no form of authentication to prevent this attack, according to Petkov.

Disabling Adobe's Flash software may not be effective, Petkov cautions, because other Web technologies may also provide a means to exploit the UPnP flaw.

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
[Interop ITX 2017] State Of DevOps Report
[Interop ITX 2017] State Of DevOps Report
The DevOps movement brings application development and infrastructure operations together to increase efficiency and deploy applications more quickly. But embracing DevOps means making significant cultural, organizational, and technological changes. This research report will examine how and why IT organizations are adopting DevOps methodologies, the effects on their staff and processes, and the tools they are utilizing for the best results.
Register for InformationWeek Newsletters
White Papers
Current Issue
Digital Transformation Myths & Truths
Transformation is on every IT organization's to-do list, but effectively transforming IT means a major shift in technology as well as business models and culture. In this IT Trend Report, we examine some of the misconceptions of digital transformation and look at steps you can take to succeed technically and culturally.
Video
Slideshows
Twitter Feed
Sponsored Live Streaming Video
Everything You've Been Told About Mobility Is Wrong
Attend this video symposium with Sean Wisdom, Global Director of Mobility Solutions, and learn about how you can harness powerful new products to mobilize your business potential.
Flash Poll