Re: Firewall (Router) "automatic" entries (msmsgs)

From: Lars M. Hansen (badnews_at_hansenonline.net)
Date: 02/18/04


Date: Wed, 18 Feb 2004 16:17:59 GMT

On Wed, 18 Feb 2004 16:05:04 GMT, Joe Stevenson spoketh

>Actually, I think UPnP is great feature. The computer(s) can actually
>communicate with the firewall/router to open up ports that it needs for
>applications to work correctly and after a specified time, the ports are
>closed again until its needed. Using the old school way involves setting up
>ports and applications manually. It's like comparing to the old school
>computers where you need to set jumpers, irqs and dmas to avoid conflicts.
>
>Usually, technology is a good thing...
>

No, people should configure firewalls, not programs. With this type of
"feature", what's to stop a malware program to reconfigure your firewall
and allow all sorts of nastiness taking place? What if someone wrote a
worm that'll identify and connect to many popular broadband routers, and
change the configuration to allow connections inbound on ports 135 or
445 or other vulnerable ports?

If your router has a UPnP feature, I recommend you turn it off.

Lars M. Hansen
www.hansenonline.net
Remove "bad" from my e-mail address to contact me.
"If you try to fail, and succeed, which have you done?"



Relevant Pages

  • Re: Blocking Ports
    ... Bob wrote: ... ports except 80. ... This is something you really need to do in your firewall/router. ... disregard the replies and advice from anyone you choose, ...
    (microsoft.public.windows.server.general)
  • Re: Firewall (Router) "automatic" entries (msmsgs)
    ... I think UPnP is great feature. ... communicate with the firewall/router to open up ports that it needs for ... applications to work correctly and after a specified time, the ports are ...
    (comp.security.firewalls)
  • Re: not receiving external mail
    ... Is the firewall/router doing any kind of NAT? ... config, I can see the commends to open the ports and even reentered them just ... I've called my isp asking them to check the ports ...
    (microsoft.public.exchange.admin)
  • Re: Lingo VoIP ATA / UTStarcom iAN-02EX remote access vulnerability
    ... On Thu, 10 Mar 2005, Ryan Cummings wrote: ... > set your ATA device up behind a firewall/router just as long as your ... > forward these ports to it. ... i've got mine running behind a firewall/router without opening any ports ...
    (Bugtraq)
  • Re: I only want stable software
    ... system' and the 'ports tree' since the desirable procedures ... FreeBSD project does ... and research 'stability' on a case by case basis. ... available applications on the basis of 'stability'. ...
    (freebsd-questions)