Yeah, even a video tutorial didn't seem to work:
https://www.youtube.com/watch?v=VHnacMKb2ro


-----Original Message----- From: Bill Prince Sent: Monday, May 18, 2015 2:04 PM To: [email protected] Subject: Re: [AFMUG] how much to worry about SSDP vulnerable customers We've seen this in a small handful of cases. The end-user impact is that it eats their upstream bandwidth. In the cases that I've seen we have been able to update the firmware, so I guess they all had been using the latest hardware. However, we have had to hand-hold the users involved because they could not do it on their own.

bp
<part15sbs{at}gmail{dot}com>

On 5/18/2015 9:18 AM, Ken Hohhof wrote:
I finally started getting ShadowServer reports which are nice.

One thing I notice is that about 5% of customers still have routers with SSDP (the discovery protocol for UPnP) exposed on the WAN side. This despite the fact that I scanned the network earlier this year and sent notices to every single customer with this vulnerability. It tells me very few did anything about it. Most of these are DLink DIR-615 routers, and except for the very last version of that router, there is no FW update, their only solution is to disable UPnP in the menus. Apparently that's too difficult for customers.

My question: is this serious enough to worry about? Should I just wait for those DLink routers (or their owners) to die?

I guess another solution would be to block ports 1900/2049/5783 but these might be legitimately in use as ephemeral ports and I don't like blocking high numbered ports.



Reply via email to