Filet-O-Firewall exposes millions of home routers to attacks
Security vulnerabilities in UPnP continue to crop up and continue to put millions of home networking devices at risk for compromise. The latest was revealed in early August, but prompted an advisory yesterday from the DHS-sponsored CERT at the Software Engineering Institute at Carnegie Mellon University. Its called Filet-o-Firewall and it combines a number vulnerabilities and weaknesses in routing protocols and browsers, conspiring to expose networked devices behind a firewall to the open Internet.
Disable UPnP If at all possible, mitigate this vulnerability by simply disabling UPnP. Instructions on how to do so should be provided by the router's manufacturer.
Agreed. uPnP was an obvious disaster from the start and I'm proud to say it's never ever been active on any network I've set up and never will be. It's one of the last things Microsoft pushed out in their "stupid-time" and in all fairness they haven't done anything this bad since (Win 10 still TBD, though).
quote:The attacks, Harrelsons research concludes, work using either Chrome or Firefox to visit a website hosting exploit code. If the browser is configured to run JavaScript, the attack will force the browser to make UPnP requests to their firewall, exposing the network to attack.