Hacker News new | past | comments | ask | show | jobs | submit login
CallStranger UPnP vulnerability exposes routers, gaming systems, TVs, printers (geekslop.com)
2 points by geek_slop on June 11, 2020 | hide | past | favorite | 1 comment



Researchers just announced the discovery of a UPnP vulnerability that impacts any UPnP device exposed on the Internet. The attack, called CallStranger (CVE-2020-12695), is being used for massive DDoS attacks , to exfiltrate data, and to scan ports from Internet-facing UPnP devices.

The attack takes advantage of a Callback header value in the SUBSCRIBE function so you can block all SUBSCRIBE and NOTIFY HTTP packets in ingress and egress traffic for protection. DDoS protection can be configured to block NOTIFY packets too.




Consider applying for YC's Spring batch! Applications are open till Feb 11.

Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: