« Mac Users Celebrate Macworld Keynote With Their Own Scam Security App | Main | New Yorker: NSA's McConnell Still Sort of Creepy »

January 15, 2008

US-CERT: Attack Vector Targets UPnP

"US-CERT is aware of an attack vector targeting networking devices that support UPnP (Universal Plug and Play). This specific attack occurs via a maliciously crafted SWF file that is contained in a web site. When the web site is visited, changes may occur to a router's configuration via UPnP. This may allow an attacker to change any parameter on the router or device that can be set by UPnP.

"US-CERT recommends that users consider disabling UPnP. (Note: Disabling UPnP may cause applications that rely on UPnP to fail or operate with reduced functionality.)"

(Link)

GNUCitizen published details on the vector as well as a demonstration: http://www.gnucitizen.org/projects/hacking-the-interwebs/Test.mxml

E-mail   0 Comments    Digg This    add to del.icio.us

Posted by mhall at 1:40 PM | Add Comment

Leave a comment











Type the characters you see in the picture above.

 




JupiterOnlineMedia

internet.comearthweb.comDevx.commediabistro.comGraphics.com

Search:

Jupitermedia Corporation has two divisions: Jupiterimages and JupiterOnlineMedia

Jupitermedia Corporate Info


Legal Notices, Licensing, Reprints, & Permissions, Privacy Policy.

Advertise | Newsletters | Tech Jobs | Shopping | E-mail Offers