PDA

View Full Version : WinAll Users : Firewalled under own PC? Use UPNP - Get rid of it + more security !!


Azo-999
October 16th, 2002, 03:28 AM
Hello Again and Good securities for all...

Go to http://grc.com/UnPnP/UnPnP.htm , and get a good solution :
UPNP ("Un Plug & Pray") for WinAll users (especially XP), it will disable the Window's unsecure UPNP-feature and does some other small tricks for Your Windows too.
No need to understand it completely, it just for me did a good job (1 month ago) for Kazaa and especially for e2k apps as eDonkey / Overnet saying I'm not firewalled at my own PC anymore (Open) and begun to show me much bigger list of Users / Files at e2k and more sources at Kazaa...

AND THE BEST - More security for all Windows users using that feature !!! The article(s) are quite old (dec 2001), leads U further to CNet's coluns and MS-Knowledgebase , but it still does it's job after MicroSofts 20+ vulnerative-fixes...

Some point from the main page :

"The FBI has Strongly Recommended that
All Users Immediately Disable Windows'
Universal Plug n' Play Support !"

"Our 22 Kbyte "UnPlug n' Pray" utility makes that very
easy to do . . . and if ever needed to, later undo it :
It's now compatible with ALL Versions of Windows!"

"What is all the fuss about?
On Thursday, December 20, 2001 Microsoft revealed that the hackers at eEye had discovered multiple critical security flaws in all versions of Windows using Universal Plug and Play: "

Quoting from eEye's press release:

"eEye has discovered three vulnerabilities within Microsoft's UPnP implementation: a remotely exploitable buffer overflow that allows an attacker gain SYSTEM level access to any default installation of Windows XP, a Denial of Service (DoS) attack, and a Distributed Denial of Service (DDoS) attack. eEye would like to stress the extreme seriousness of this vulnerability. Network administrators are urged to immediately install the patch released by Microsoft at http://www.microsoft.com/technet/security/bulletin/MS01-059.asp"

"The most serious of the three Windows XP vulnerabilities is the remotely exploitable buffer overflow. It is possible for an attacker to write custom exploit code that will allow them to execute commands with SYSTEM level access, the highest level of access within Windows XP."

"The other two vulnerabilities are types of denial of service attacks. The first is a fairly straightforward denial of service attack, which allows an attacker to remotely crash any Windows XP system. The crash will require Windows XP users to physically power down their machines and start them up again before the system will function. The second denial of service attack is a distributed denial of service attack. This vulnerability allows attackers to remotely command many Windows XP systems at once in an effort to make them flood/attack a single host."

Translating eEye's and Microsoft's statements into consequences, this means that without the security update patch, and with the Universal Plug and Play (UPnP) system in its default "enabled" state, any of the many millions of Internet-connected UPnP-equipped Windows systems could be remotely commandeered and forced to download and run any malicious code of a hacker's design. This includes using the machine to launch potent Denial of Service (DoS) and Distributed Denial of Service (DDoS) attacks.

This means that extremely damaging CodeRed and Nimda-style worms can now be written for millions of Windows machines. Whereas the Microsoft IIS server worms of 2001 found and infested 'only' several hundred thousand IIS servers, a Windows "Universal Plug and Play" worm would have more than ten million XP systems, in addition to many more Windows 98/ME systems, upon which to prey today.

The highly respected Gartner Group has said that they expect hackers to incorporate the UPnP vulnerabilities into their attack tools by the end of the first quarter of 2002. Here's Gartner's Commentary. http://news.cnet.com/news/0-1003-201-8254545-0.html?tag=prntfr

Comment are taken awards : Did it something / nothing for Your PC? Did U lose Your Op.system? :wings

Peace and no need to understand it all !

:sw :sw :sw :sw

Azo-999
October 16th, 2002, 03:40 AM
Forgot to mention :
If it shows in green background that "UPNP is NOT installed on this System" , then U're safe for this one, and no use of that app further needed

Bless U and Health (and happy p2p) 4 All :wings

:sw :sw :sw :sw

Sephiroth
October 16th, 2002, 08:24 AM
If you got the patch that was released last december then you should be perfectly fine and secure with Upnp. Its almost been a year and the gloom and doom theories like this one and others of gibson havent come true..

Azo-999
October 16th, 2002, 10:36 AM
Originally posted by Sephiroth
If you got the patch that was released last december then you should be perfectly fine and secure with Upnp. Its almost been a year and the gloom and doom theories like this one and others of gibson havent come true..
Yes, Sephi - I'm gone thru MS-KB mostly as with security related stuff, posted with them as a sw-developer a lot, and they admit between lines that vulneraties like this still exists, even though they have lately published the cumulative patch (mostly for IE-Browsing, not for malicious new scripts and port-scanning methods that are evolving thru all the time). Mostly taken, they have put their gloves to pocket and left futher attack-handlinc to Symantec, McAfee, OnTrack and Powerquest, sometimes paying them money to get pacth-ideas to those every 2 weeks coming-up "secutity-fixes".
Mostly they take the honour to themselves and says it's an important 'GatesWarez' fix done by them, although it's just an issue given them from well-known security companies.

BTW, I was not advertising this thing as a FIX, but for the good work it did for my computer with file-sharing issues. This is the the case, we mostly talk here. I got that link from a friend from US when we vere discussing about eDonkey and Overnet related stuff. I asked him, why da hex I was firewalled by default by e2k apps and he said : just load da app (or now I just can do it manually with those 3 basic services it's dealing with). He did not either know, why this issue not related originally to file-sharing, fixed his and mine (and thousands of others) situation in that problem..?

BTW2 : I just now feel happy, that my e2k apps finds servers soon, get much larger list of users and files and says now, that I'm connected directly (before there was reading "Firewalled").

BTW3 : It had an issue for FT (KaZaA) too, much more search results, much more sources. Heaven knows why?

But - I am happy with that, maybe someone else would like to be happy, too! (for this unknown side-effect)

P.S. I am SOCKS5-Firewalled with a possibility to bypass the firewall at my ISP, I can even change my ADSL protocol from ANSI T1.413 Issue 2 to ITU G.992.1 Annex A (G.dmt) and even switch (illegally) to competitor ISP's network with absolutely zero firewalls (only routers). Still I was "Firewalled by my XP" untill I made the UPNP-thing...

Piece and Health and Happy P2P (Non-Firewalled)

:sw :sw :sw :sw