Re: "Universal Plug and Play technology exploit code"

From: Florian Weimer (Weimer@CERT.Uni-Stuttgart.DE)
Date: 12/24/01


To: "Sebastian Wells" <alterego@negaverse.org>
From: Florian Weimer <Weimer@CERT.Uni-Stuttgart.DE>
Date: 24 Dec 2001 22:59:20 +0100


"Sebastian Wells" <alterego@negaverse.org> writes:

> Is this an exploit to the most recent UPnP hole that was posted to bugtraq?
> In the discussion of that vulnerability it was stated that UPnP was on UDP
> port 1900.
>
> Am I just confused?

UPnP support comes with a web server on TCP port 5000 (which processes
SOAP requests, IIRC). Another UDP-based web server seems to be
listening on port 1900, implementing SSDP (yes, there's an IETF draft
floating around for HTTP over UDP).

-- 
Florian Weimer 	                  Florian.Weimer@RUS.Uni-Stuttgart.DE
University of Stuttgart           http://cert.uni-stuttgart.de/
RUS-CERT                          +49-711-685-5973/fax +49-711-685-5898



Relevant Pages

  • Re: Turning on Media Sharing in WMP11
    ... I believe it forms quite a reasonable network media device. ... Turning on SSDP (it was disabled as was uPnP) to Manual and then UPnP ... If there is a firewall, or NAT, built into your ... You need to open port s: ...
    (microsoft.public.windowsmedia.player)
  • Re: Turning on Media Sharing in WMP11
    ... picture frame to my server and the frame could view the pictures remotely. ... Turning on SSDP (it was disabled as was uPnP) to Manual and then UPnP also ... If there is a firewall, or NAT, built into your router, ... You need to open port s: ...
    (microsoft.public.windowsmedia.player)
  • VideoConf Nightmare
    ... Firewall Router so you can read the instructions on How ... >instructions (from your reply to "audio on messenger" on ... >But as stated, all appeared to work, however, the UPnP ... More on firewall and port opening can be ...
    (microsoft.public.windowsxp.messenger)
  • Re: Turning on Media Sharing in WMP11
    ... the uPnP to run on the network. ... found it better to use that than a software firewall like the one in XP ... If it is started then check and make sure the Windows Media Player Network ... You need to open port s: ...
    (microsoft.public.windowsmedia.player)
  • Re: IP addresses for embedded device with ethernet
    ... As far as I can see, UPnP works in this way (though it has ... you can use one of a number of various dynamic DNS services to locate ... you run on your own web server. ... label, go to your web site, and use the ID to look up his IP address. ...
    (comp.arch.embedded)