{"id":84662,"date":"2020-06-10T01:42:15","date_gmt":"2020-06-09T23:42:15","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/uyazvimost-v-upnp-podhodyashhaya-dlya-usileniya-ddos-atak-i-skanirovaniya-vnutrennej-seti"},"modified":"2020-06-10T01:42:15","modified_gmt":"2020-06-09T23:42:15","slug":"uyazvimost-v-upnp-podhodyashhaya-dlya-usileniya-ddos-atak-i-skanirovaniya-vnutrennej-seti","status":"publish","type":"post","link":"https:\/\/prohoster.info\/en\/blog\/news\/uyazvimost-v-upnp-podhodyashhaya-dlya-usileniya-ddos-atak-i-skanirovaniya-vnutrennej-seti","title":{"rendered":"A vulnerability in UPnP suitable for amplifying DDoS attacks and scanning the internal network","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p><noindex><a rel=\"nofollow\" href=\"https:\/\/www.tenable.com\/blog\/cve-2020-12695-callstranger-vulnerability-in-universal-plug-and-play-upnp-puts-billions-of\">Revealed<\/a><\/noindex> information about <noindex><a rel=\"nofollow\" href=\"https:\/\/kb.cert.org\/vuls\/id\/339275\">a vulnerability<\/a><\/noindex> (<noindex><a rel=\"nofollow\" href=\"https:\/\/security-tracker.debian.org\/tracker\/CVE-2020-12695\">CVE-2020-12695<\/a><\/noindex>) in the UPnP protocol, allowing for the sending of traffic to any recipient, using the standard operation 'SUBSCRIBE'. The vulnerabilities have been assigned the code name <noindex><a rel=\"nofollow\" href=\"https:\/\/callstranger.com\/\">CallStranger<\/a><\/noindex>. This vulnerability can be exploited to extract data from networks protected by Data Loss Prevention (DLP) systems, to perform port scanning on computers within the internal network, and to enhance DDoS attacks using millions of UPnP-connected devices such as cable modems, home routers, gaming consoles, IP cameras, TV boxes, media centers, and printers.<\/p>\n<p>The Problem <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/yunuscadirci\/CallStranger\/blob\/master\/CallStranger%20-%20Technical%20Report.pdf\">is caused by<\/a><\/noindex> that the function 'SUBSCRIBE' specified in the documentation allows any external attacker to send HTTP packets with a Callback header and use the UPnP device as a proxy to send requests to other hosts. The 'SUBSCRIBE' function is defined in the UPnP specification and is used to track changes in other devices and services. Using the HTTP header Callback, any URL can be specified, to which the device will attempt to connect. <\/p>\n<p><center><noindex><a rel=\"nofollow\" href=\"https:\/\/www.tenable.com\/sites\/drupal.dmz.tenablesecurity.com\/files\/images\/blog\/CVE-2020-12695%20-%20CallStranger%20Vulnerability.png\"><img decoding=\"async\" alt=\"A vulnerability in UPnP suitable for amplifying DDoS attacks and scanning the internal network\" src=\"\/wp-content\/uploads\/2020\/06\/dcee8b0bfd93ce0ce40d1104963a024c.png\" style=\"display:block;margin: 0 auto;\" \/><\/a><\/noindex><\/center><\/p>\n<p>The issue affects almost all UPnP implementations based on <noindex><a rel=\"nofollow\" href=\"https:\/\/openconnectivity.org\/upnp-specs\/UPnP-arch-DeviceArchitecture-v2.0-20200417.pdf\">the specification<\/a><\/noindex>, released before April 17. Including the existence of the vulnerability <noindex><a rel=\"nofollow\" href=\"https:\/\/w1.fi\/security\/2020-1\/upnp-subscribe-misbehavior-wps-ap.txt\">is confirmed<\/a><\/noindex> in the open package <noindex><a rel=\"nofollow\" href=\"http:\/\/w1.fi\/hostapd\/\">hostapd<\/a><\/noindex> with the implementation of a wireless access point (WPS AP). A fix is currently available in the form of <noindex><a rel=\"nofollow\" href=\"https:\/\/w1.fi\/security\/2020-1\/\">of patches<\/a><\/noindex>. Updates have not yet been released in the distributions (<noindex><a rel=\"nofollow\" href=\"https:\/\/security-tracker.debian.org\/tracker\/CVE-2020-12695\">Debian<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/openwrt.org\/advisory\/start\">OpenWRT<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/people.canonical.com\/~ubuntu-security\/cve\/CVE-2020-12695\">Ubuntu<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=CVE-2020-12695\">SUSE\/openSUSE<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/bugzilla.suse.com\/show_bug.cgi?id=CVE-2020-12695\">openSUSE<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/bodhi.fedoraproject.org\/updates\/?releases=F32&#038;type=security\">Alpine<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/security.archlinux.org\/\">ALT<\/a><\/noindex>). The problem is also <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/pupnp\/pupnp\/issues\/180\">affects<\/a><\/noindex> solutions based on the open UPnP stack <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/pupnp\/pupnp\/\">pupnp<\/a><\/noindex>, for which there is currently no information about fixes.<\/p>\n<p>The UPnP protocol defines a mechanism for automatically discovering devices on a local network and interacting with them. The protocol was originally designed for use within internal local networks and does not provide any forms of authentication and verification. Despite this, millions of devices do not disable UPnP support on external network interfaces and <noindex><a rel=\"nofollow\" href=\"https:\/\/www.shodan.io\/search?query=upnp\">remain accessible<\/a><\/noindex> for requests from the global network. An attack can be carried out through any such UPnP device.<br \/>\nFor example, Xbox One consoles can be attacked through network port 2869, as they allow tracking of changes such as content sharing through the SUBSCRIBE command.<\/p>\n<p> The Open Connectivity Foundation (OCF) was notified of the issue late last year, but initially refused to consider it as a vulnerability in the specification. Following a subsequent, more detailed report, the existence of the problem was acknowledged and a provision was added to the specification requiring the use of UPnP only on LAN interfaces. Since the problem arises from a shortcoming in the standard, fixing the vulnerability in individual devices may take considerable time, and firmware updates for older devices may not be released.<\/p>\n<p>As protective workarounds, it is recommended to isolate UPnP devices from external requests using a firewall, block external HTTP requests 'SUBSCRIBE' and 'NOTIFY' on intrusion prevention systems, or disable the UPnP protocol on external network interfaces. Manufacturers are advised to disable the SUBSCRIBE function in default settings and limit enabling it only to requests from the internal network.<br \/>\nTo test your devices for susceptibility to the vulnerability  <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/yunuscadirci\/CallStranger\">has been published<\/a><\/noindex> a special toolkit written in Python and distributed under the MIT license. <\/p>\n<p><noindex><a rel=\"nofollow\" name=\"link\"><\/a><\/noindex><\/p>\n<p>Source: <a \ncontent=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=53123\">opennet.ru<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0420\u0430\u0441\u043a\u0440\u044b\u0442\u044b \u0441\u0432\u0435\u0434\u0435\u043d\u0438\u044f \u043e\u0431 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 (CVE-2020-12695) \u0432 \u043f\u0440\u043e\u0442\u043e\u043a\u043e\u043b\u0435 UPnP, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0435\u0439 \u043e\u0440\u0433\u0430\u043d\u0438\u0437\u043e\u0432\u0430\u0442\u044c \u043e\u0442\u043f\u0440\u0430\u0432\u043a\u0443 \u0442\u0440\u0430\u0444\u0438\u043a\u0430 \u043f\u0440\u043e\u0438\u0437\u0432\u043e\u043b\u044c\u043d\u043e\u043c\u0443 \u043f\u043e\u043b\u0443\u0447\u0430\u0442\u0435\u043b\u044e, \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u044f \u043f\u0440\u0435\u0434\u0443\u0441\u043c\u043e\u0442\u0440\u0435\u043d\u043d\u0443\u044e \u0432 \u0441\u0442\u0430\u043d\u0434\u0430\u0440\u0442\u0435 \u043e\u043f\u0435\u0440\u0430\u0446\u0438\u044e &#171;SUBSCRIBE&#187;. \u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u043f\u0440\u0438\u0441\u0432\u043e\u0435\u043d\u043e \u043a\u043e\u0434\u043e\u0432\u043e\u0435 \u0438\u043c\u044f CallStranger. \u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u043c\u043e\u0436\u0435\u0442 \u043f\u0440\u0438\u043c\u0435\u043d\u044f\u0442\u044c\u0441\u044f \u0438\u0437\u0432\u043b\u0435\u0447\u0435\u043d\u0438\u044f \u0434\u0430\u043d\u043d\u044b\u0445 \u0438\u0437 \u0441\u0435\u0442\u0435\u0439, \u0437\u0430\u0449\u0438\u0449\u0451\u043d\u043d\u044b\u0445 \u0441\u0438\u0441\u0442\u0435\u043c\u0430\u043c\u0438 \u043f\u0440\u0435\u0434\u043e\u0442\u0432\u0440\u0430\u0449\u0435\u043d\u0438\u044f \u0443\u0442\u0435\u0447\u0435\u043a \u0434\u0430\u043d\u043d\u044b\u0445 (DLP), \u043e\u0440\u0433\u0430\u043d\u0438\u0437\u0430\u0446\u0438\u0438 \u0441\u043a\u0430\u043d\u0438\u0440\u043e\u0432\u0430\u043d\u0438\u044f \u043f\u043e\u0440\u0442\u043e\u0432 \u043a\u043e\u043c\u043f\u044c\u044e\u0442\u0435\u0440\u043e\u0432 \u0432\u043e \u0432\u043d\u0443\u0442\u0440\u0435\u043d\u043d\u0435\u0439 \u0441\u0435\u0442\u0438, \u0430 \u0442\u0430\u043a\u0436\u0435 \u0434\u043b\u044f \u0443\u0441\u0438\u043b\u0435\u043d\u0438\u044f DDoS-\u0430\u0442\u0430\u043a \u043f\u0440\u0438 \u043f\u043e\u043c\u043e\u0449\u0438 \u043c\u0438\u043b\u043b\u0438\u043e\u043d\u043e\u0432 \u043f\u043e\u0434\u043a\u043b\u044e\u0447\u0451\u043d\u043d\u044b\u0445 \u043a [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":84663,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-84662","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.2 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0420\u0430\u0441\u043a\u0440\u044b\u0442\u044b \u0441\u0432\u0435\u0434\u0435\u043d\u0438\u044f \u043e\u0431\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/en\/blog\/news\/uyazvimost-v-upnp-podhodyashhaya-dlya-usileniya-ddos-atak-i-skanirovaniya-vnutrennej-seti\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.2\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 UPnP, \u043f\u043e\u0434\u0445\u043e\u0434\u044f\u0449\u0430\u044f \u0434\u043b\u044f \u0443\u0441\u0438\u043b\u0435\u043d\u0438\u044f DDoS-\u0430\u0442\u0430\u043a \u0438 \u0441\u043a\u0430\u043d\u0438\u0440\u043e\u0432\u0430\u043d\u0438\u044f \u0432\u043d\u0443\u0442\u0440\u0435\u043d\u043d\u0435\u0439 \u0441\u0435\u0442\u0438 | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0420\u0430\u0441\u043a\u0440\u044b\u0442\u044b \u0441\u0432\u0435\u0434\u0435\u043d\u0438\u044f \u043e\u0431\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/en\/blog\/news\/uyazvimost-v-upnp-podhodyashhaya-dlya-usileniya-ddos-atak-i-skanirovaniya-vnutrennej-seti\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2020-06-09T23:42:15+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2020-06-09T23:42:15+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Vulnerability in UPnP Suitable for Amplifying DDoS Attacks and Scanning Internal Network | ProHoster","description":"Details have been disclosed about","canonical_url":"https:\/\/prohoster.info\/en\/blog\/news\/uyazvimost-v-upnp-podhodyashhaya-dlya-usileniya-ddos-atak-i-skanirovaniya-vnutrennej-seti","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"en_US","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 UPnP, \u043f\u043e\u0434\u0445\u043e\u0434\u044f\u0449\u0430\u044f \u0434\u043b\u044f \u0443\u0441\u0438\u043b\u0435\u043d\u0438\u044f DDoS-\u0430\u0442\u0430\u043a \u0438 \u0441\u043a\u0430\u043d\u0438\u0440\u043e\u0432\u0430\u043d\u0438\u044f \u0432\u043d\u0443\u0442\u0440\u0435\u043d\u043d\u0435\u0439 \u0441\u0435\u0442\u0438 | ProHoster","og:description":"\u0420\u0430\u0441\u043a\u0440\u044b\u0442\u044b \u0441\u0432\u0435\u0434\u0435\u043d\u0438\u044f \u043e\u0431","og:url":"https:\/\/prohoster.info\/en\/blog\/news\/uyazvimost-v-upnp-podhodyashhaya-dlya-usileniya-ddos-atak-i-skanirovaniya-vnutrennej-seti","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2020-06-09T23:42:15+00:00","article:modified_time":"2020-06-09T23:42:15+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"84662","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":null,"breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-02-28 14:53:24","updated":"2022-09-27 14:10:17","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/84662","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/comments?post=84662"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/84662\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/media\/84663"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/media?parent=84662"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/categories?post=84662"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/tags?post=84662"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}