Menu

Universal Plug and Play (UPnP): What You Need to Know
📰
0

Universal Plug and Play (UPnP): What You Need to Know

Akamai·Akamai SIRT·about 1 month ago
#eS8zWGwh
Reading 0:00
15s threshold

Originally posted April 2018, updated in 2022 \r\n Universal Plug and Play (UPnP) is a widely used protocol with a decade-long history of flawed implementations across a wide range of consumer devices. In this paper, we will cover how these aws are still present on devices, how these vulnerabilities are actively being abused, and how a feature/vulnerability set that seems to be mostly forgotten could lead to continued problems in the future with DDoS, account takeover , and malware distribution. \r\n Readers must be aware that this is an active vector currently in use to conceal the traffic of attackers. The location of the origin of the traffic is effectively hidden by using vulnerable devices as proxies. Carriers and ISPs need to be aware of the vulnerability, as end users and customers may appear to be hosting content or the source of attacks when the responsible party is actually behind one or several layers of compromised routers.…

Continue reading — create a free account

Join HashtagPLUS to read full articles, follow hashtags, vote, and join the conversation.

Read More