Protect yourself. What we do with pfsense is we created a group for "bad users" and put their IP in the group. This firewall group blocks incoming ssh/ntp/dns/ftp/telnet/upnp/etc.
If it's a problem, they'll call us back (finally). If not, the problem is still resolved as far as we care. On May 18, 2015 8:18:11 AM AKDT, Ken Hohhof <[email protected]> wrote: >I finally started getting ShadowServer reports which are nice. > >One thing I notice is that about 5% of customers still have routers >with >SSDP (the discovery protocol for UPnP) exposed on the WAN side. This >despite the fact that I scanned the network earlier this year and sent >notices to every single customer with this vulnerability. It tells me >very >few did anything about it. Most of these are DLink DIR-615 routers, >and >except for the very last version of that router, there is no FW update, > >their only solution is to disable UPnP in the menus. Apparently that's >too >difficult for customers. > >My question: is this serious enough to worry about? Should I just >wait for >those DLink routers (or their owners) to die? > >I guess another solution would be to block ports 1900/2049/5783 but >these >might be legitimately in use as ephemeral ports and I don't like >blocking >high numbered ports. -- Sent from my Android device with K-9 Mail. Please excuse my brevity.
