{"id":84662,"date":"2020-06-10T01:42:15","date_gmt":"2020-06-09T23:42:15","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/uyazvimost-v-upnp-podhodyashhaya-dlya-usileniya-ddos-atak-i-skanirovaniya-vnutrennej-seti"},"modified":"2020-06-10T01:42:15","modified_gmt":"2020-06-09T23:42:15","slug":"uyazvimost-v-upnp-podhodyashhaya-dlya-usileniya-ddos-atak-i-skanirovaniya-vnutrennej-seti","status":"publish","type":"post","link":"https:\/\/prohoster.info\/nl\/blog\/news\/uyazvimost-v-upnp-podhodyashhaya-dlya-usileniya-ddos-atak-i-skanirovaniya-vnutrennej-seti","title":{"rendered":"Kwetsbaarheid in UPnP, geschikt voor het versterken van DDoS-aanvallen en het scannen van interne netwerken","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p><noindex><a rel=\"nofollow\" href=\"https:\/\/www.tenable.com\/blog\/cve-2020-12695-callstranger-vulnerability-in-universal-plug-and-play-upnp-puts-billions-of\">Onthuld<\/a><\/noindex> informatie over <noindex><a rel=\"nofollow\" href=\"https:\/\/kb.cert.org\/vuls\/id\/339275\">kwetsbaarheden<\/a><\/noindex> (<noindex><a rel=\"nofollow\" href=\"https:\/\/security-tracker.debian.org\/tracker\/CVE-2020-12695\">CVE-2020-12695<\/a><\/noindex>) in het UPnP-protocol, waarmee het mogelijk is om verkeer naar een willekeurige ontvanger te sturen, gebruikmakend van de in de standaard voorziene operatie &#171;SUBSCRIBE&#187;. De kwetsbaarheid heeft de codenaam gekregen <noindex><a rel=\"nofollow\" href=\"https:\/\/callstranger.com\/\">CallStranger<\/a><\/noindex>. De kwetsbaarheid kan worden gebruikt voor het extraheren van gegevens uit netwerken die worden beschermd door datalekpreventiesystemen (DLP), het scannen van poorten op computers in een intern netwerk, en om DDoS-aanvallen te versterken met behulp van miljoenen UPnP-apparaten die wereldwijd zijn verbonden, zoals kabelmodems, thuisrouters, spelconsoles, IP-camera's, TV-ontvangers, mediacentra en printers.<\/p>\n<p>Probleem <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/yunuscadirci\/CallStranger\/blob\/master\/CallStranger%20-%20Technical%20Report.pdf\">is caused by<\/a><\/noindex> dat de in de specificatie voorziene functie &#171;SUBSCRIBE&#187; elke externe aanvaller in staat stelt om HTTP-pakketten met een Callback-header te verzenden en het UPnP-apparaat als een proxy te gebruiken om verzoeken naar andere hosts te sturen. De functie &#171;SUBSCRIBE&#187; is gedefinieerd in de UPnP-specificatie en wordt gebruikt om wijzigingen in andere apparaten en diensten te volgen. Met de HTTP-header Callback kan een willekeurige URL worden opgegeven waar het apparaat een verbindingspoging naartoe zal maken. <\/p>\n<p><center><noindex><a rel=\"nofollow\" href=\"https:\/\/www.tenable.com\/sites\/drupal.dmz.tenablesecurity.com\/files\/images\/blog\/CVE-2020-12695%20-%20CallStranger%20Vulnerability.png\"><img decoding=\"async\" alt=\"Kwetsbaarheid in UPnP, geschikt voor het versterken van DDoS-aanvallen en het scannen van interne netwerken\" src=\"\/wp-content\/uploads\/2020\/06\/dcee8b0bfd93ce0ce40d1104963a024c.png\" style=\"display:block;margin: 0 auto;\" \/><\/a><\/noindex><\/center><\/p>\n<p>Bijna alle UPnP-implementaties zijn kwetsbaar, gebaseerd op <noindex><a rel=\"nofollow\" href=\"https:\/\/openconnectivity.org\/upnp-specs\/UPnP-arch-DeviceArchitecture-v2.0-20200417.pdf\">de specificatie<\/a><\/noindex>, uitgebracht voor 17 april. Ook is de kwetsbaarheid <noindex><a rel=\"nofollow\" href=\"https:\/\/w1.fi\/security\/2020-1\/upnp-subscribe-misbehavior-wps-ap.txt\">bevestigd<\/a><\/noindex> in een open pakket <noindex><a rel=\"nofollow\" href=\"http:\/\/w1.fi\/hostapd\/\">hostapd<\/a><\/noindex> met de implementatie van een draadloze toegangspunt (WPS AP). De patch is voorlopig beschikbaar als <noindex><a rel=\"nofollow\" href=\"https:\/\/w1.fi\/security\/2020-1\/\">patches<\/a><\/noindex>. In de distributies zijn er voorlopig geen updates vrijgegeven (<noindex><a rel=\"nofollow\" href=\"https:\/\/security-tracker.debian.org\/tracker\/CVE-2020-12695\">Debian<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/openwrt.org\/advisory\/start\">OpenWRT<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/people.canonical.com\/~ubuntu-security\/cve\/CVE-2020-12695\">Ubuntu<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/bugzilla.redhat.com\/show_bug.cgi?id=CVE-2020-12695\">RHEL<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/bugzilla.suse.com\/show_bug.cgi?id=CVE-2020-12695\">SUSE<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/bodhi.fedoraproject.org\/updates\/?releases=F32&#038;type=security\">Fedora<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/security.archlinux.org\/\">Arch<\/a><\/noindex>). Het probleem betreft ook <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/pupnp\/pupnp\/issues\/180\">aan<\/a><\/noindex> oplossingen op basis van de open UPnP-stack <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/pupnp\/pupnp\/\">pupnp<\/a><\/noindex>, waarvoor nog geen informatie over patches beschikbaar is.<\/p>\n<p>Het UPnP-protocol definieert een mechanisme voor automatische detectie van apparaten in een lokaal netwerk en interactie met deze apparaten. Het protocol is oorspronkelijk ontworpen voor gebruik in interne lokale netwerken en voorziet niet in enige vorm van authenticatie of verificatie. Desondanks schakelen miljoenen apparaten de ondersteuning voor UPnP op externe netwerkinterfaces niet uit en <noindex><a rel=\"nofollow\" href=\"https:\/\/www.shodan.io\/search?query=upnp\">blijven toegankelijk<\/a><\/noindex> voor verzoeken uit het wereldwijde netwerk. Een aanval kan worden uitgevoerd via elk dergelijk UPnP-apparaat.<br \/>\nBijvoorbeeld, Xbox One-consoles kunnen worden aangevallen via poort 2869, omdat ze het mogelijk maken om dergelijke veranderingen als het delen van content te volgen via het SUBSCRIBE-commando.<\/p>\n<p> De organisatie Open Connectivity Foundation (OCF) werd eind vorig jaar op de kwestie gewezen, maar weigerde aanvankelijk dit als een kwetsbaarheid in de specificatie te beschouwen. Na een herhaalde, meer gedetailleerde rapportage werd het bestaan van het probleem erkend en werd er een voorschrift aan de specificatie toegevoegd om UPnP alleen op LAN-interfaces te gebruiken. Aangezien het probleem voortkomt uit een tekortkoming in de standaard, kan het lang duren om de kwetsbaarheid in afzonderlijke apparaten te verhelpen, en voor oudere apparaten kunnen er mogelijk geen firmware-updates beschikbaar komen.<\/p>\n<p>Als alternatieve beschermingsmaatregelen wordt aanbevolen om UPnP-apparaten te isoleren van externe aanvragen via een firewall, externe HTTP-aanvragen &#171;SUBSCRIBE&#187; en &#171;NOTIFY&#187; op aanvallendetectiesystemen te blokkeren of het UPnP-protocol op externe netwerkinterfaces uit te schakelen. Fabrikanten wordt aangeraden om de functie SUBSCRIBE in de standaardinstellingen uit te schakelen en bij inschakeling alleen verzoeken uit het interne netwerk toe te staan.<br \/>\nOm de kwetsbaarheid van uw apparaten te testen,  <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/yunuscadirci\/CallStranger\">gepubliceerd<\/a><\/noindex> een speciale toolkit, geschreven in Python en verspreid onder de MIT-licentie. <\/p>\n<p><noindex><a rel=\"nofollow\" name=\"link\"><\/a><\/noindex><\/p>\n<p>Bron: <a \ncontent=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=53123\">opennet.ru<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0420\u0430\u0441\u043a\u0440\u044b\u0442\u044b \u0441\u0432\u0435\u0434\u0435\u043d\u0438\u044f \u043e\u0431 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 (CVE-2020-12695) \u0432 \u043f\u0440\u043e\u0442\u043e\u043a\u043e\u043b\u0435 UPnP, \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u044e\u0449\u0435\u0439 \u043e\u0440\u0433\u0430\u043d\u0438\u0437\u043e\u0432\u0430\u0442\u044c \u043e\u0442\u043f\u0440\u0430\u0432\u043a\u0443 \u0442\u0440\u0430\u0444\u0438\u043a\u0430 \u043f\u0440\u043e\u0438\u0437\u0432\u043e\u043b\u044c\u043d\u043e\u043c\u0443 \u043f\u043e\u043b\u0443\u0447\u0430\u0442\u0435\u043b\u044e, \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u044f \u043f\u0440\u0435\u0434\u0443\u0441\u043c\u043e\u0442\u0440\u0435\u043d\u043d\u0443\u044e \u0432 \u0441\u0442\u0430\u043d\u0434\u0430\u0440\u0442\u0435 \u043e\u043f\u0435\u0440\u0430\u0446\u0438\u044e &#171;SUBSCRIBE&#187;. \u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u043f\u0440\u0438\u0441\u0432\u043e\u0435\u043d\u043e \u043a\u043e\u0434\u043e\u0432\u043e\u0435 \u0438\u043c\u044f CallStranger. \u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u043c\u043e\u0436\u0435\u0442 \u043f\u0440\u0438\u043c\u0435\u043d\u044f\u0442\u044c\u0441\u044f \u0438\u0437\u0432\u043b\u0435\u0447\u0435\u043d\u0438\u044f \u0434\u0430\u043d\u043d\u044b\u0445 \u0438\u0437 \u0441\u0435\u0442\u0435\u0439, \u0437\u0430\u0449\u0438\u0449\u0451\u043d\u043d\u044b\u0445 \u0441\u0438\u0441\u0442\u0435\u043c\u0430\u043c\u0438 \u043f\u0440\u0435\u0434\u043e\u0442\u0432\u0440\u0430\u0449\u0435\u043d\u0438\u044f \u0443\u0442\u0435\u0447\u0435\u043a \u0434\u0430\u043d\u043d\u044b\u0445 (DLP), \u043e\u0440\u0433\u0430\u043d\u0438\u0437\u0430\u0446\u0438\u0438 \u0441\u043a\u0430\u043d\u0438\u0440\u043e\u0432\u0430\u043d\u0438\u044f \u043f\u043e\u0440\u0442\u043e\u0432 \u043a\u043e\u043c\u043f\u044c\u044e\u0442\u0435\u0440\u043e\u0432 \u0432\u043e \u0432\u043d\u0443\u0442\u0440\u0435\u043d\u043d\u0435\u0439 \u0441\u0435\u0442\u0438, \u0430 \u0442\u0430\u043a\u0436\u0435 \u0434\u043b\u044f \u0443\u0441\u0438\u043b\u0435\u043d\u0438\u044f DDoS-\u0430\u0442\u0430\u043a \u043f\u0440\u0438 \u043f\u043e\u043c\u043e\u0449\u0438 \u043c\u0438\u043b\u043b\u0438\u043e\u043d\u043e\u0432 \u043f\u043e\u0434\u043a\u043b\u044e\u0447\u0451\u043d\u043d\u044b\u0445 \u043a [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":84663,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-84662","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.3 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0420\u0430\u0441\u043a\u0440\u044b\u0442\u044b \u0441\u0432\u0435\u0434\u0435\u043d\u0438\u044f \u043e\u0431\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/nl\/blog\/news\/uyazvimost-v-upnp-podhodyashhaya-dlya-usileniya-ddos-atak-i-skanirovaniya-vnutrennej-seti\" \/>\n\t\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.3\" \/>\n\t\t<meta property=\"og:locale\" content=\"nl_NL\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 UPnP, \u043f\u043e\u0434\u0445\u043e\u0434\u044f\u0449\u0430\u044f \u0434\u043b\u044f \u0443\u0441\u0438\u043b\u0435\u043d\u0438\u044f DDoS-\u0430\u0442\u0430\u043a \u0438 \u0441\u043a\u0430\u043d\u0438\u0440\u043e\u0432\u0430\u043d\u0438\u044f \u0432\u043d\u0443\u0442\u0440\u0435\u043d\u043d\u0435\u0439 \u0441\u0435\u0442\u0438 | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0420\u0430\u0441\u043a\u0440\u044b\u0442\u044b \u0441\u0432\u0435\u0434\u0435\u043d\u0438\u044f \u043e\u0431\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/nl\/blog\/news\/uyazvimost-v-upnp-podhodyashhaya-dlya-usileniya-ddos-atak-i-skanirovaniya-vnutrennej-seti\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2020-06-09T23:42:15+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2020-06-09T23:42:15+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47Kwetsbaarheid in UPnP, geschikt voor het versterken van DDoS-aanvallen en het scannen van interne netwerken | ProHoster","description":"Informatie onthuld over","canonical_url":"https:\/\/prohoster.info\/nl\/blog\/news\/uyazvimost-v-upnp-podhodyashhaya-dlya-usileniya-ddos-atak-i-skanirovaniya-vnutrennej-seti","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"nl_NL","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432 UPnP, \u043f\u043e\u0434\u0445\u043e\u0434\u044f\u0449\u0430\u044f \u0434\u043b\u044f \u0443\u0441\u0438\u043b\u0435\u043d\u0438\u044f DDoS-\u0430\u0442\u0430\u043a \u0438 \u0441\u043a\u0430\u043d\u0438\u0440\u043e\u0432\u0430\u043d\u0438\u044f \u0432\u043d\u0443\u0442\u0440\u0435\u043d\u043d\u0435\u0439 \u0441\u0435\u0442\u0438 | ProHoster","og:description":"\u0420\u0430\u0441\u043a\u0440\u044b\u0442\u044b \u0441\u0432\u0435\u0434\u0435\u043d\u0438\u044f \u043e\u0431","og:url":"https:\/\/prohoster.info\/nl\/blog\/news\/uyazvimost-v-upnp-podhodyashhaya-dlya-usileniya-ddos-atak-i-skanirovaniya-vnutrennej-seti","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2020-06-09T23:42:15+00:00","article:modified_time":"2020-06-09T23:42:15+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"84662","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":null,"breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-02-28 14:53:24","updated":"2022-09-27 14:10:17","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/nl\/wp-json\/wp\/v2\/posts\/84662","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/nl\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/nl\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/nl\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/nl\/wp-json\/wp\/v2\/comments?post=84662"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/nl\/wp-json\/wp\/v2\/posts\/84662\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/prohoster.info\/nl\/wp-json\/wp\/v2\/media\/84663"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/nl\/wp-json\/wp\/v2\/media?parent=84662"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/nl\/wp-json\/wp\/v2\/categories?post=84662"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/nl\/wp-json\/wp\/v2\/tags?post=84662"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}