No Code No Crime: UPnP as an Off-the-Shelf Attacker's Toolkit

No ratings

Presented at BlueHatIL 2019 by

Given the rise of exposed IoT and home routers, UPnP is quite an interesting attack vector on those devices, enabling the often misconfigured service.Indeed in March 2018, Symantec found evidence of attacks from the «Inception Framework» hiding behind an increasingly complex network of proxies and cloud services since 2014. It is said that the protocol can be abused to «hop» through a victim to masquerade your true IP address: "It's not a bug, it's a feature".There are hundreds of thousands of vulnerable devices across 80 countries, most of them simply accept SOAP requests from the WAN as if they were from a “trusted” LAN. This exposure can lead to a messy situation. Indeed, the same bug has been used by multiple threat actors to exploit Windows computers behind NAT.In this session, we’ll dig in to, explore the potential ways to abuse UPnP, and explain how to create a "malware-less" botnet.