From NCCT: We originally covered this two weeks ago:
http://blog.nccomputertech.com/2013/01/31/millions-of-pcs-exposed-through-network-bugs-security-researchers-find/
This is a very serious issue and we urge our clients and anybody else to go to:
https://www.grc.com/shieldsup
Click on the “proceed button”, on the next page click on the big yellow button that says “GRC’s Instant UPnP Exposure Test”.
Let it do it’s thing.
If you get a message in a green box that says “THE EQUIPMENT AT THE TARGET IP ADDRESS DID NOT RESPOND TO OUR UPnP PROBES“…. you’re o.k.. there’s nothing further that needs to be done. Your router does not have this flaw.
If you get a red message saying your “THE EQUIPMENT AT THE TARGET IP ADDRESS DID RESPOND TO OUR UPnP PROBES!“..you have a serious problem. UPnP would have to be disabled on your router and rechecked. In some cases even disabling it will not correct this on the WAN side, people could still get in on certain routers.
In simple terms this flaw allows somebody on the WAN (Wide Area Network..the entire outside world) side of the router with this flaw to access your internal network LAN(Local Area Network..all of the computers and devices inside you house).
Here’s a message you don’t want when you run the test mentioned above, this is just a sample page of what a warning looks like.
https://www.grc.com/su/UPnP-Exposed.htm
Once they get in(and it’s not hard to with this flaw) it’s the same as having somebody come into your house or business and plug a computer into your router and look at all of your devices, shares, files, change your router settings, etc..Essentially they can do what they want and you wouldn’t know and your anti-virus wouldn’t know. By the way this flaw was found not only in routers, but in network capable appliances/devices, security cameras, printers, T.V.’s, etc…The key thing is to check if your router is at risk since the other devices sit behind that…or they should.
If you find your router is exposed and don’t know how to disable UPnP give us a call. We can disable it and run all the tests for you and recommend what to do and let you know if you may need to update your firmware if available(which we can do), buy a new router if disabling UPnP doesn’t work on your current one or set up a another hardware firewall. We can deal with it.
Or your ISP can block port 1900.
We can not emphasize enough how important this is, this is not a “oh well, whatever” situation, this in our opinion and in many other people’s opinion worse than a virus. You may be giving people complete access to your network and everything on it and not even know it.
Here is two videos featuring Leo Laporte and Steve Gibson(GRC.COM) on the topic.