Protect yourself.

What we do with pfsense is we created a group for "bad users" and put their IP 
in the group. This firewall group blocks incoming 
ssh/ntp/dns/ftp/telnet/upnp/etc.

If it's a problem, they'll call us back (finally). If not, the problem is still 
resolved as far as we care.

On May 18, 2015 8:18:11 AM AKDT, Ken Hohhof <[email protected]> wrote:
>I finally started getting ShadowServer reports which are nice.
>
>One thing I notice is that about 5% of customers still have routers
>with 
>SSDP (the discovery protocol for UPnP) exposed on the WAN side.  This 
>despite the fact that I scanned the network earlier this year and sent 
>notices to every single customer with this vulnerability.  It tells me
>very 
>few did anything about it.  Most of these are DLink DIR-615 routers,
>and 
>except for the very last version of that router, there is no FW update,
>
>their only solution is to disable UPnP in the menus.  Apparently that's
>too 
>difficult for customers.
>
>My question:  is this serious enough to worry about?  Should I just
>wait for 
>those DLink routers (or their owners) to die?
>
>I guess another solution would be to block ports 1900/2049/5783 but
>these 
>might be legitimately in use as ephemeral ports and I don't like
>blocking 
>high numbered ports. 

-- 
Sent from my Android device with K-9 Mail. Please excuse my brevity.

Reply via email to