[aklug] Re: OT: security problems with UPnP devices

From: Royce Williams <royce@tycho.org>
Date: Mon Feb 04 2013 - 06:27:55 AKST

On Mon, Feb 4, 2013 at 6:21 AM, Royce Williams <royce@tycho.org> wrote:
> On Sun, Feb 3, 2013 at 10:22 PM, <bryanm@acsalaska.net> wrote:
>> "To prevent hacking, disable Universal Plug and Play now"
>> http://arstechnica.com/security/2013/01/to-prevent-hacking-disable-universal-plug-and-play-now/
>>
>> In summary, many devices, in the name of usability, disregard
>> security principles and even open up holes in your firewall to
>> allow access to your LAN.
>
> Yeah, it's disappointing. I can just see, movie-scene-like, where the
> geeks at Big Device Company are saying "Noooo!!" but the people
> running the helpdesk override them because it keeps the call volume
> down. :-(

Also, be aware that the "free" Rapid7 Windows scanner *requires* you
to put in your name, email, address, business names, etc before it
will run. Ironically, it also requires Java (=:-O). Stick to nmap.
:-)

--
Royce Williams
---------
To unsubscribe, send email to <aklug-request@aklug.org>
with 'unsubscribe' in the message body.
Received on Mon Feb 4 06:28:24 2013

This archive was generated by hypermail 2.1.8 : Mon Feb 04 2013 - 06:28:24 AKST