Re: Microsoft MS01-059, Universal Plug-n-Play vulnerability.

From: 'ken'@FTU
Date: 12/22/01


Date: Fri, 21 Dec 2001 18:06:03 -0500
From: "'ken'@FTU" <franklin_tech_bulletins@yahoo.com>
To: Mark Medici <mark@dbma.com>

Try port 5000 for TCP and 1900 for UDP.

'ken'

Mark Medici wrote:

> Does anyone have any information on the protocols and/or ports used
> by Universal Plug-n-Play (uPnP)? I'm not looking for specific
> sample code or a working exploit. However, I do want to know if
> this vulnerability can be exploited from the Internet, and if so,
> how to block it at our firewalls and border routers.
>
> Microsoft and CERT announced a vulnerability affecting Windows/XP,
> Windows/Me and, potentially, Windows/98 with Universal Plug-n-Play.
> See http://www.microsoft.com/technet/security/bulletin/MS01-059.asp
> for details.
>
> Obviously, installing Microsoft's patch (Q315000 for Windows/XP, the
> most critical platform) is essential. But users (our own and our
> customers) frequently get new machines or reload existing ones and
> put them on the network for several days before a SysAdmin learns of
> their presence to properly patch them.
>
> If there are specific protocols and/or ports that can be associated
> with Universal Plug-n-Play, then these can be blocked by our
> firewalls, border routers and personal firewalls to protect against
> exploits even if one of our users is remiss in installing patches.
>
> Further information is welcome.
>
>



Relevant Pages

  • Re: PLINK and/or PuTTY -- Logon to Linux with no Privileges
    ... There are firewalls that can detect this sort of thing, ... We've tried just regular VNC, with no luck, then tried it on port 80, ... were easily broken out of because, well, they're shell scripts! ...
    (comp.security.ssh)
  • Re: How to Stealth POP3 Port 110 using NIS2000?
    ... > What do you want to protect by 'stealth-ports'? ... > stealthed port protects your privacy, 'cause I really don't get it. ... I can't answer that as I am no expert on firewalls. ...
    (comp.security.firewalls)
  • Re: How to Stealth POP3 Port 110 using NIS2000?
    ... >> how a stealthed port protects your privacy, 'cause I really don't get it. ... > I can't answer that as I am no expert on firewalls. ... The only thing you risk when not stealthing port 110 is for people to find ...
    (comp.security.firewalls)
  • Re: firewall question
    ... > I posted this to the security basics list but nobody answered the ... > answer since they are the ones who have to get around firewalls. ... > connection to me via netcat with a destination port of 80, ... > SecurityFocus' SIA service which automatically alerts you to the ...
    (Pen-Test)
  • Re: PLINK and/or PuTTY -- Logon to Linux with no Privileges
    ... behind restrictive firewalls so VNC can be tunneled through it. ... tried just regular VNC, with no luck, then tried it on port 80, with no ... or to use a sort-of-restrictive shell for the users. ...
    (comp.security.ssh)