<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: UPNP Extended Security in Tech Help - Software/Hardware etc</title>
    <link>https://community.plus.net/t5/Tech-Help-Software-Hardware-etc/UPNP-Extended-Security/m-p/1793363#M90662</link>
    <description>&lt;P&gt;&lt;a href="https://community.plus.net/t5/user/viewprofilepage/user-id/99397"&gt;@fydrenak&lt;/a&gt;&amp;nbsp;- You refer to UPNP as a security feature when it has more holes than a sieve!&amp;nbsp;&lt;/P&gt;</description>
    <pubDate>Tue, 16 Feb 2021 11:40:02 GMT</pubDate>
    <dc:creator>Mook</dc:creator>
    <dc:date>2021-02-16T11:40:02Z</dc:date>
    <item>
      <title>UPNP Extended Security</title>
      <link>https://community.plus.net/t5/Tech-Help-Software-Hardware-etc/UPNP-Extended-Security/m-p/1792072#M90626</link>
      <description>&lt;P&gt;Hi all, I am developing an application which uses UPNP to create peer to peer connections through NAT. I have had no issues with several routers using SSDP multicast to discover UPNP devices on the local network. However my Plusnet Hub One seems to not respond to the multicast requests. It does however respond to a unicast message sent straight to the router, but this is inadequate for my use as I want to find all devices on the network. Does anybody know on a low level what UPNP Extended Security actually does, and if it could be the source of this problem?&lt;/P&gt;&lt;P&gt;Thank you.&lt;/P&gt;</description>
      <pubDate>Tue, 09 Feb 2021 16:28:28 GMT</pubDate>
      <guid>https://community.plus.net/t5/Tech-Help-Software-Hardware-etc/UPNP-Extended-Security/m-p/1792072#M90626</guid>
      <dc:creator>fydrenak</dc:creator>
      <dc:date>2021-02-09T16:28:28Z</dc:date>
    </item>
    <item>
      <title>Re: UPNP Extended Security</title>
      <link>https://community.plus.net/t5/Tech-Help-Software-Hardware-etc/UPNP-Extended-Security/m-p/1792532#M90630</link>
      <description>&lt;P&gt;You're new here and your first post is asking for information that would help you circumvent the plusnet router security!&lt;/P&gt;
&lt;P&gt;You don't really expect help on this do you?&lt;/P&gt;</description>
      <pubDate>Fri, 12 Feb 2021 00:43:04 GMT</pubDate>
      <guid>https://community.plus.net/t5/Tech-Help-Software-Hardware-etc/UPNP-Extended-Security/m-p/1792532#M90630</guid>
      <dc:creator>7up</dc:creator>
      <dc:date>2021-02-12T00:43:04Z</dc:date>
    </item>
    <item>
      <title>Re: UPNP Extended Security</title>
      <link>https://community.plus.net/t5/Tech-Help-Software-Hardware-etc/UPNP-Extended-Security/m-p/1792533#M90631</link>
      <description>&lt;P&gt;That's quite a hostile response but I will ignore it as my intentions are not as you imply.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Quite the opposite, I would like to understand this feature so I can ensure my program functions correctly for users that have this security feature enabled. If the feature makes what I'm trying to do impossible, then I will make no efforts to circumvent it. I simply want to understand it to make sure I'm not making an error.&lt;/P&gt;</description>
      <pubDate>Fri, 12 Feb 2021 00:55:00 GMT</pubDate>
      <guid>https://community.plus.net/t5/Tech-Help-Software-Hardware-etc/UPNP-Extended-Security/m-p/1792533#M90631</guid>
      <dc:creator>fydrenak</dc:creator>
      <dc:date>2021-02-12T00:55:00Z</dc:date>
    </item>
    <item>
      <title>Re: UPNP Extended Security</title>
      <link>https://community.plus.net/t5/Tech-Help-Software-Hardware-etc/UPNP-Extended-Security/m-p/1792543#M90632</link>
      <description>I doubt you will find the answers here, perhaps try reddit.&lt;BR /&gt;Or your own ISP forums, if you're not a PN customer.</description>
      <pubDate>Fri, 12 Feb 2021 07:22:04 GMT</pubDate>
      <guid>https://community.plus.net/t5/Tech-Help-Software-Hardware-etc/UPNP-Extended-Security/m-p/1792543#M90632</guid>
      <dc:creator>dvorak</dc:creator>
      <dc:date>2021-02-12T07:22:04Z</dc:date>
    </item>
    <item>
      <title>Re: UPNP Extended Security</title>
      <link>https://community.plus.net/t5/Tech-Help-Software-Hardware-etc/UPNP-Extended-Security/m-p/1793356#M90659</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://community.plus.net/t5/user/viewprofilepage/user-id/99397"&gt;@fydrenak&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;
&lt;P&gt;That's quite a hostile response but I will ignore it as my intentions are not as you imply.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Quite the opposite, I would like to understand this feature so I can ensure my program functions correctly for users that have this security feature enabled. If the feature makes what I'm trying to do impossible, then I will make no efforts to circumvent it. I simply want to understand it to make sure I'm not making an error.&lt;/P&gt;
&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;
&lt;P&gt;Well consider this, you've turned up on the plusnet forum talking about a plusnet hub one and wanting to know how to get around it's upnp limitations from a security perspective.&lt;/P&gt;
&lt;P&gt;That's like turning up on a van forum saying you've locked yourself out of your van and need help getting back into it - nobody will assist you.&lt;/P&gt;
&lt;P&gt;Even if you are legit plusnet don't make any technical details about their router available to us.&lt;/P&gt;</description>
      <pubDate>Tue, 16 Feb 2021 11:06:12 GMT</pubDate>
      <guid>https://community.plus.net/t5/Tech-Help-Software-Hardware-etc/UPNP-Extended-Security/m-p/1793356#M90659</guid>
      <dc:creator>7up</dc:creator>
      <dc:date>2021-02-16T11:06:12Z</dc:date>
    </item>
    <item>
      <title>Re: UPNP Extended Security</title>
      <link>https://community.plus.net/t5/Tech-Help-Software-Hardware-etc/UPNP-Extended-Security/m-p/1793363#M90662</link>
      <description>&lt;P&gt;&lt;a href="https://community.plus.net/t5/user/viewprofilepage/user-id/99397"&gt;@fydrenak&lt;/a&gt;&amp;nbsp;- You refer to UPNP as a security feature when it has more holes than a sieve!&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 16 Feb 2021 11:40:02 GMT</pubDate>
      <guid>https://community.plus.net/t5/Tech-Help-Software-Hardware-etc/UPNP-Extended-Security/m-p/1793363#M90662</guid>
      <dc:creator>Mook</dc:creator>
      <dc:date>2021-02-16T11:40:02Z</dc:date>
    </item>
    <item>
      <title>Re: UPNP Extended Security</title>
      <link>https://community.plus.net/t5/Tech-Help-Software-Hardware-etc/UPNP-Extended-Security/m-p/1793370#M90663</link>
      <description>&lt;P&gt;&lt;a href="https://community.plus.net/t5/user/viewprofilepage/user-id/2395"&gt;@7up&lt;/a&gt; The inaccurate simile is wholly unnecessary. I have never once asked how to 'get around' any 'upnp limitations'. As I said before; I have no intention of circumventing anything, I merely want to understand what the limitations are so I know what is possible to do legitimately. I am not interested in any hacks or workarounds, I just want to know what this option on my router actually does.&lt;/P&gt;
&lt;P&gt;I would greatly appreciate it if the contents of my question were focused on instead of making baseless judgements about me personally. That makes for a pretty toxic way to welcome new members of the forum.&lt;/P&gt;
&lt;P&gt;The final line in your reply is the only constructive one, but I at least thank you for it. I assumed that all the settings users can control on the router are documented somewhere, else how are consumers expected to decide whether or not to enable/disable the feature without knowledge of what it does? That is the only level of information I am looking for.&lt;/P&gt;</description>
      <pubDate>Tue, 16 Feb 2021 12:14:12 GMT</pubDate>
      <guid>https://community.plus.net/t5/Tech-Help-Software-Hardware-etc/UPNP-Extended-Security/m-p/1793370#M90663</guid>
      <dc:creator>fydrenak</dc:creator>
      <dc:date>2021-02-16T12:14:12Z</dc:date>
    </item>
    <item>
      <title>Re: UPNP Extended Security</title>
      <link>https://community.plus.net/t5/Tech-Help-Software-Hardware-etc/UPNP-Extended-Security/m-p/1793371#M90664</link>
      <description>&lt;P&gt;&lt;a href="https://community.plus.net/t5/user/viewprofilepage/user-id/7493"&gt;@dvorak&lt;/a&gt; Thank you, I might try Reddit as well but I generally try to avoid it. For what it's worth, I am a Plusnet customer. The only reason I have access to multiple brands' routers is that I switch between multiple places of living fairly frequently, and I have asked some of those around me to test my program and send me the response.&lt;/P&gt;</description>
      <pubDate>Tue, 16 Feb 2021 12:17:15 GMT</pubDate>
      <guid>https://community.plus.net/t5/Tech-Help-Software-Hardware-etc/UPNP-Extended-Security/m-p/1793371#M90664</guid>
      <dc:creator>fydrenak</dc:creator>
      <dc:date>2021-02-16T12:17:15Z</dc:date>
    </item>
    <item>
      <title>Re: UPNP Extended Security</title>
      <link>https://community.plus.net/t5/Tech-Help-Software-Hardware-etc/UPNP-Extended-Security/m-p/1793373#M90665</link>
      <description>&lt;P&gt;&lt;a href="https://community.plus.net/t5/user/viewprofilepage/user-id/99397"&gt;@fydrenak&lt;/a&gt;&amp;nbsp; I assume you've read the RFC for this:&lt;/P&gt;
&lt;P&gt;&lt;A href="https://tools.ietf.org/html/rfc6970" target="_blank"&gt;https://tools.ietf.org/html/rfc6970&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;This will explain everything you need to know.&lt;/P&gt;</description>
      <pubDate>Tue, 16 Feb 2021 12:24:00 GMT</pubDate>
      <guid>https://community.plus.net/t5/Tech-Help-Software-Hardware-etc/UPNP-Extended-Security/m-p/1793373#M90665</guid>
      <dc:creator>Mook</dc:creator>
      <dc:date>2021-02-16T12:24:00Z</dc:date>
    </item>
    <item>
      <title>Re: UPNP Extended Security</title>
      <link>https://community.plus.net/t5/Tech-Help-Software-Hardware-etc/UPNP-Extended-Security/m-p/1793374#M90666</link>
      <description>&lt;P&gt;&lt;a href="https://community.plus.net/t5/user/viewprofilepage/user-id/75682"&gt;@Mook&lt;/a&gt; I never referred to UPNP itself as a security feature, but to 'UPNP Extended Security' as it is written in the router settings, which I think can safely be called a security feature. UPNP &lt;EM&gt;could&lt;/EM&gt; be considered a security risk but the fact is sometimes people want to build peer to peer networks with a 'plug and play' client. Expecting your average consumer to find their local IP, keep it static, and manually port forward is a bit much. Also, assuming UPNP is configurable only from the LAN, if you have malicious code that would use UPNP you have far bigger problems and UPNP being enabled. And disabling it likely stops absolutely nothing. Evidently the industry agrees with me as people have been trying to call it insecure for years but it is still very widely used.&lt;/P&gt;
&lt;P&gt;If you think there is something I have not considered in my security assessment of UPNP I welcome the information.&lt;/P&gt;</description>
      <pubDate>Tue, 16 Feb 2021 12:24:15 GMT</pubDate>
      <guid>https://community.plus.net/t5/Tech-Help-Software-Hardware-etc/UPNP-Extended-Security/m-p/1793374#M90666</guid>
      <dc:creator>fydrenak</dc:creator>
      <dc:date>2021-02-16T12:24:15Z</dc:date>
    </item>
    <item>
      <title>Re: UPNP Extended Security</title>
      <link>https://community.plus.net/t5/Tech-Help-Software-Hardware-etc/UPNP-Extended-Security/m-p/1793379#M90667</link>
      <description>&lt;P&gt;I'd hardly call quoting 'UPNP Extended Security' a security assessment but each to their own I guess.&amp;nbsp;To be honest I don't use the Plusnet Router so I don't know in what context the aforementioned quote actually refers to so I will say no more but I do recommend you read the RFC, it will be time well spent.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 16 Feb 2021 12:35:19 GMT</pubDate>
      <guid>https://community.plus.net/t5/Tech-Help-Software-Hardware-etc/UPNP-Extended-Security/m-p/1793379#M90667</guid>
      <dc:creator>Mook</dc:creator>
      <dc:date>2021-02-16T12:35:19Z</dc:date>
    </item>
    <item>
      <title>Re: UPNP Extended Security</title>
      <link>https://community.plus.net/t5/Tech-Help-Software-Hardware-etc/UPNP-Extended-Security/m-p/1793380#M90668</link>
      <description>&lt;P&gt;&lt;a href="https://community.plus.net/t5/user/viewprofilepage/user-id/75682"&gt;@Mook&lt;/a&gt; Thank you for that link, I have been working from the specification of UPNP device architecture specification (&lt;A href="http://upnp.org/specs/arch/UPnP-arch-DeviceArchitecture-v1.1.pdf" target="_self"&gt;http://upnp.org/specs/arch/UPnP-arch-DeviceArchitecture-v1.1.pdf&lt;/A&gt;) when building my implementation. I admit to not being familiar with the PCP IWF. Is this what is expected to be used by modern applications?&lt;/P&gt;</description>
      <pubDate>Tue, 16 Feb 2021 12:36:49 GMT</pubDate>
      <guid>https://community.plus.net/t5/Tech-Help-Software-Hardware-etc/UPNP-Extended-Security/m-p/1793380#M90668</guid>
      <dc:creator>fydrenak</dc:creator>
      <dc:date>2021-02-16T12:36:49Z</dc:date>
    </item>
    <item>
      <title>Re: UPNP Extended Security</title>
      <link>https://community.plus.net/t5/Tech-Help-Software-Hardware-etc/UPNP-Extended-Security/m-p/1793383#M90669</link>
      <description>&lt;P&gt;&lt;a href="https://community.plus.net/t5/user/viewprofilepage/user-id/75682"&gt;@Mook&lt;/a&gt; My assessment is what I outlined in why I think UPNP is not too insecure for use in modern applications. I reviewed what it enables and I don't think it allows an attacker to do much more than they would be able to do anyway given that they're inside the network. The quote of the name was my response to the comment that i called UPNP itself a security feature.&lt;/P&gt;</description>
      <pubDate>Tue, 16 Feb 2021 12:39:50 GMT</pubDate>
      <guid>https://community.plus.net/t5/Tech-Help-Software-Hardware-etc/UPNP-Extended-Security/m-p/1793383#M90669</guid>
      <dc:creator>fydrenak</dc:creator>
      <dc:date>2021-02-16T12:39:50Z</dc:date>
    </item>
    <item>
      <title>Re: UPNP Extended Security</title>
      <link>https://community.plus.net/t5/Tech-Help-Software-Hardware-etc/UPNP-Extended-Security/m-p/1793387#M90670</link>
      <description>&lt;P&gt;It's always been my understanding that an RFC is the defacto standard for this kind of thing and when I've had to deal with protocols this is my first port of call.&lt;/P&gt;
&lt;P&gt;But UPnP is bad news, do a search of the &lt;A title="CVE Site" href="https://cve.mitre.org/index.html" target="_self"&gt;CVE&lt;/A&gt; site using UPNP and you'll get an idea.&lt;/P&gt;</description>
      <pubDate>Tue, 16 Feb 2021 12:52:18 GMT</pubDate>
      <guid>https://community.plus.net/t5/Tech-Help-Software-Hardware-etc/UPNP-Extended-Security/m-p/1793387#M90670</guid>
      <dc:creator>Mook</dc:creator>
      <dc:date>2021-02-16T12:52:18Z</dc:date>
    </item>
    <item>
      <title>Re: UPNP Extended Security</title>
      <link>https://community.plus.net/t5/Tech-Help-Software-Hardware-etc/UPNP-Extended-Security/m-p/1817338#M91534</link>
      <description>&lt;P&gt;&lt;a href="https://community.plus.net/t5/user/viewprofilepage/user-id/2395"&gt;@7up&lt;/a&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;EM&gt;"You don't really expect help on this do you?"&lt;/EM&gt;&lt;/P&gt;
&lt;P&gt;What a ridiculous response !&lt;/P&gt;
&lt;P&gt;15,000 posts and this is how you behave in response to a new person asking a perfectly natural question.&lt;/P&gt;
&lt;P&gt;Perhaps you have come to think that you are so important that it's your job to be rude to anyone who doesn't spend all their time here ?&lt;/P&gt;
&lt;P&gt;Maybe that's why your fixes to posts ratio is so low.&lt;/P&gt;
&lt;P&gt;Of course the OP should be able to know how his router works.&lt;/P&gt;
&lt;P&gt;I also want to know, as I'm investigating whether this router is vulnerable to NAT slipstreaming.&lt;/P&gt;
&lt;P&gt;Is that ok with you ?&amp;nbsp; -&amp;nbsp; It probably &lt;EM&gt;isn't&lt;/EM&gt; relevant, but how can I tell unless I know what this bland unhelpful label "Advanced Security" actually means.&lt;/P&gt;
&lt;P&gt;Security Through Obscurity is a discredited approach.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;In any case the OP is already logged in to the router advanced settings - how much worse can it get.&amp;nbsp; Apparently he already pwned his network.&lt;/P&gt;</description>
      <pubDate>Thu, 08 Jul 2021 15:57:00 GMT</pubDate>
      <guid>https://community.plus.net/t5/Tech-Help-Software-Hardware-etc/UPNP-Extended-Security/m-p/1817338#M91534</guid>
      <dc:creator>topgallant</dc:creator>
      <dc:date>2021-07-08T15:57:00Z</dc:date>
    </item>
  </channel>
</rss>

