Is uPnP a Security Risk if Enabled in DD-WRT?

Post new topic   Reply to topic    DD-WRT Forum Index -> Broadcom SoC based Hardware

Is uPnP Safe to Enable in DD-WRT??
Yes
20%
 20%  [ 2 ]
No
40%
 40%  [ 4 ]
Could Be
40%
 40%  [ 4 ]
Total Votes : 10

Author Message
RCShadows
DD-WRT User


Joined: 17 Aug 2008
Posts: 437

PostPosted: Sun Jul 19, 2009 0:13    Post subject: Is uPnP a Security Risk if Enabled in DD-WRT? Reply with quote
Do you feel that uPnP is safe in DD-WRT?

If you answer "Could Be", please leave a message giving the reason's why if you will.
Sponsor
crashfly
DD-WRT Guru


Joined: 24 Feb 2009
Posts: 2026
Location: Sol System > Earth > USA > Arkansas

PostPosted: Sun Jul 19, 2009 0:19    Post subject: Reply with quote
It would depend on how "accessible" your network is going to be. If you have an open WiFi *or* allow any one 'willy nilly' to just connect to your network, yes, there can be a *MAJOR* security risk. However, if you are *extremely* cautious about who and what devices are on your network, your wireless is secured, etc, then no, it is not a risk at all (depending on the programs that are used).
_________________
E3000 22200M KongVPN K26
WRT600n v1.1 refirb mega 18767 BS K24 NEWD2 [not used]
WRT54G v2 16214 BS K24 [access point]

Try Dropbox for syncing files - get 2.5gb online for free by signing up.

Read! Peacock thread
*PLEASE* upgrade PAST v24SP1 or no support.
RCShadows
DD-WRT User


Joined: 17 Aug 2008
Posts: 437

PostPosted: Sun Jul 19, 2009 0:22    Post subject: Reply with quote
Thanks CrashFly...I'm a pilot and your handle scares me! lol

Seriously though, what if you have teenagers that download "whatever"?
PUNiZZLE
DD-WRT User


Joined: 06 Apr 2008
Posts: 79

PostPosted: Sun Jul 19, 2009 0:49    Post subject: Reply with quote
As crashfly stated it depends on your application and network.

If you have teenagers that are downloading "whatever" and option you have is to not install the uPnP client on their particular PCs.

_________________
I'll short all the pins on my router before I ever build a JTAG. Twisted Evil
RCShadows
DD-WRT User


Joined: 17 Aug 2008
Posts: 437

PostPosted: Sun Jul 19, 2009 1:23    Post subject: Reply with quote
Good point Smile
phuzi0n
DD-WRT Guru


Joined: 10 Oct 2006
Posts: 10141

PostPosted: Sun Jul 19, 2009 4:16    Post subject: Reply with quote
UPnP isn't safe on anything but to exploit is is a multi-step process. The short explanation is that anything running on your computer, including your browser, can request ports to be opened. Any website you visit can potentially poke holes in your firewall. After that all depends on whether any of the services you're running are vulnerable.
_________________
Read the forum announcements thoroughly! Be cautious if you're inexperienced.
Available for paid consulting. (Don't PM about complicated setups otherwise)
Looking for bricks and spare routers to expand my collection. (not interested in G spec models)
autobot
DD-WRT Guru


Joined: 07 May 2009
Posts: 1596

PostPosted: Sun Jul 19, 2009 7:14    Post subject: Reply with quote
No more dangerous than having a telnet server running, or any other exploitable service really. A good hacker can write code, manipulate the tcp/ip stack like linkin' logs, and cause a buffer overflow as freely as we type. But in the end they usually take the easy path, like manipulating an existing exploit in a known service like upnp. I use upnp, I like it, if I lose sensitive information because of it then I'm more important than I thought.
Display posts from previous:    Page 1 of 1
Post new topic   Reply to topic    DD-WRT Forum Index -> Broadcom SoC based Hardware All times are GMT

Navigation

 
Jump to:  
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You can attach files in this forum
You can download files in this forum