Re: Future plans after 1.3?

Chris Buechler <[email protected]>
Newsgroups gmane.comp.security.firewalls.m0n0wall
Message-ID <[email protected]>
On Sun, Dec 13, 2009 at 6:34 PM, Quark Group - Hilton Travis
<[email protected]> wrote:
>
> So, what happens when some malware gets installed on a PC which is allowed to open ports on the UPnP device and
> then starts communicating over those?
>

It would have to pick one of your already authorized ports, then have
to open the ports. In your "secure" scenario, those ports would have
always been wide open already, so it would have been even easier.
Sure, you would never use it in a business network, but with many home
networks, your options are either to leave a bunch of ports wide open
all the time, or have a properly restricted upnp service that lets the
apps on your machine open ports when needed. The latter is obviously
preferable.
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.