Yeah, even a video tutorial didn't seem to work:
https://www.youtube.com/watch?v=VHnacMKb2ro
-----Original Message-----
From: Bill Prince
Sent: Monday, May 18, 2015 2:04 PM
To: [email protected]
Subject: Re: [AFMUG] how much to worry about SSDP vulnerable customers
We've seen this in a small handful of cases. The end-user impact is that
it eats their upstream bandwidth. In the cases that I've seen we have
been able to update the firmware, so I guess they all had been using the
latest hardware. However, we have had to hand-hold the users involved
because they could not do it on their own.
bp
<part15sbs{at}gmail{dot}com>
On 5/18/2015 9:18 AM, Ken Hohhof wrote:
I finally started getting ShadowServer reports which are nice.
One thing I notice is that about 5% of customers still have routers
with SSDP (the discovery protocol for UPnP) exposed on the WAN side.
This despite the fact that I scanned the network earlier this year and
sent notices to every single customer with this vulnerability. It
tells me very few did anything about it. Most of these are DLink
DIR-615 routers, and except for the very last version of that router,
there is no FW update, their only solution is to disable UPnP in the
menus. Apparently that's too difficult for customers.
My question: is this serious enough to worry about? Should I just
wait for those DLink routers (or their owners) to die?
I guess another solution would be to block ports 1900/2049/5783 but
these might be legitimately in use as ephemeral ports and I don't like
blocking high numbered ports.