funsec mailing list archives

Re: Routers


From: Martin Wehlou <martin () wehlou com>
Date: Sun, 27 Nov 2005 18:24:57 +0100

On 27 Nov 2005, at 15:40, Rob, grandpa of Ryan, Trevor, Devon & Hannah wrote:


  - Disable UPnP (I hate this protocol)


Interesting. I don't think I've got anything net-connected that requires it. Might
one ask why the hatred?  (And also how to diable, if non-obvious?)



Well, AFAIK, it is intended to let applications configure the firewall automatically, so they can work transparently. Great idea, having your app open inbound ports for you, so you don't need to worry.

Except... that app that is doing it may not actually be one you wanted to have. IOW, trojans now can control your firewall. Oops.

[...]


J. Martin Wehlou MD, CISSP, CSDP
Uppsala/Sweden, www.wehlou.com
PGP keyId: 0xC7D56E11 http://www.wehlou.com/files/jmwpubkey.asc
blog: urSecta.com

_______________________________________________
Fun and Misc security discussion for OT posts.
https://linuxbox.org/cgi-bin/mailman/listinfo/funsec
Note: funsec is a public and open mailing list.


Current thread: