Windows Vista Tips

Windows Vista Tips > Newsgroups > Windows Live Messenger > Is allowing UPnP worth it?

Reply
Thread Tools Display Modes

Is allowing UPnP worth it?

 
 
thebigdintexas
Guest
Posts: n/a

 
      09-22-2006
If UPnP opens up a security risk, and Windows Live Messenger seems to operate
the same with or without it (at least to me), why is it suggested that we
allow UPnP?
 
Reply With Quote
 
 
 
 
Edward Chow [Windows Live B'fly-M'sgr]
Guest
Posts: n/a

 
      09-22-2006
UPnP will allow you to transfer files, use Sharing Folders, use webcam/voice
chat; as well as do anything that's not just text chatting.

--
Edward Chow [1067064]
Windows Live Butterfly - Messenger

"thebigdintexas" <> wrote in message
news:40B9EA0E-FA75-4943-A11D-...
> If UPnP opens up a security risk, and Windows Live Messenger seems to
> operate
> the same with or without it (at least to me), why is it suggested that we
> allow UPnP?



 
Reply With Quote
 
thebigdintexas
Guest
Posts: n/a

 
      09-22-2006
I'm not transfering any files, I don't use the sharing folders, and my
webcam/voice chat seems to work the same with or without UPnP......




"Edward Chow [Windows Live B'fly-M'sgr]" wrote:

> UPnP will allow you to transfer files, use Sharing Folders, use webcam/voice
> chat; as well as do anything that's not just text chatting.
>
> --
> Edward Chow [1067064]
> Windows Live Butterfly - Messenger
>
> "thebigdintexas" <> wrote in message
> news:40B9EA0E-FA75-4943-A11D-...
> > If UPnP opens up a security risk, and Windows Live Messenger seems to
> > operate
> > the same with or without it (at least to me), why is it suggested that we
> > allow UPnP?

>
>
>

 
Reply With Quote
 
Jonathan Kay [MVP]
Guest
Posts: n/a

 
      09-23-2006
Greetings,

The only "risk" with UPnP is that a rogue (read as worm) application opens and forwards a
port without your knowledge.

There are no known worms, viruses or trojans with exploit this. Also, if you have such an
application on your machine already, you already have a bigger security issue than UPnP.

The only other UPnP exploit wasn't in UPnP at all, it was in the SSDP service has never been
exploited in the wild and was fixed in November of 2001.

The big "security issues" surrounding UPnP are nothing but FUD created by third-parties who
benefit financially from such ideas (Symantec, Mcafee, Steve Gibson, etc.).

--
Jonathan Kay
Microsoft MVP - Windows Live Messenger/MSN Messenger/Windows Messenger
Associate Expert
http://www.microsoft.com/windowsxp/expertzone/
Messenger Resources - http://messenger.jonathankay.com
All posts unless otherwise specified are (c) 2006 Jonathan Kay.
You *must* contact me for redistribution rights.
--


"thebigdintexas" <> wrote in message
news:40B9EA0E-FA75-4943-A11D-...
> If UPnP opens up a security risk, and Windows Live Messenger seems to operate
> the same with or without it (at least to me), why is it suggested that we
> allow UPnP?



 
Reply With Quote
 
Dinko Deranja
Guest
Posts: n/a

 
      09-25-2006
I agree with you, but if that is true, then I dont understand why MS dropped
UPnP support in Windows 2003 Server (UPnP via ICS)?


"Jonathan Kay [MVP]" <> wrote in message
news:%...
> The big "security issues" surrounding UPnP are nothing but FUD created by
> third-parties who benefit financially from such ideas (Symantec, Mcafee,
> Steve Gibson, etc.).



 
Reply With Quote
 
Jonathan Kay [MVP]
Guest
Posts: n/a

 
      09-25-2006
Hi,

Unfortunately UPnP is considered a consumer-grade technology and as such was removed from the
Server platform.

For instance, if a business used Windows Server to share their Internet connection, their
users could use all this Messenger functionality and whatever other software they decided to
use that supported UPnP which may bypass any other security measures that were in place to
prevent such usage.

--
Jonathan Kay
Microsoft MVP - Windows Live Messenger/MSN Messenger/Windows Messenger
Associate Expert
http://www.microsoft.com/windowsxp/expertzone/
Messenger Resources - http://messenger.jonathankay.com
All posts unless otherwise specified are (c) 2006 Jonathan Kay.
You *must* contact me for redistribution rights.
--

"Dinko Deranja" <> wrote in message news:...
>I agree with you, but if that is true, then I dont understand why MS dropped UPnP support in
>Windows 2003 Server (UPnP via ICS)?
>
>
> "Jonathan Kay [MVP]" <> wrote in message
> news:%...
>> The big "security issues" surrounding UPnP are nothing but FUD created by third-parties
>> who benefit financially from such ideas (Symantec, Mcafee, Steve Gibson, etc.).

>
>



 
Reply With Quote
 
duoc
Guest
Posts: n/a

 
      09-26-2006
To be clear, UPnP is not entirely necessary to make these features work. It
helps in some cases (for example, if in the connection settings, you are
detected behind a Symmetric NAT).

"Edward Chow [Windows Live B'fly-M'sgr]" wrote:

> UPnP will allow you to transfer files, use Sharing Folders, use webcam/voice
> chat; as well as do anything that's not just text chatting.
>
> --
> Edward Chow [1067064]
> Windows Live Butterfly - Messenger
>
> "thebigdintexas" <> wrote in message
> news:40B9EA0E-FA75-4943-A11D-...
> > If UPnP opens up a security risk, and Windows Live Messenger seems to
> > operate
> > the same with or without it (at least to me), why is it suggested that we
> > allow UPnP?

>
>
>

 
Reply With Quote
 
Dinko Deranja
Guest
Posts: n/a

 
      09-26-2006
Well, about bypassing - a single checkbox named "Allow UPnP" would be
enough.


"Jonathan Kay [MVP]" <> wrote in message
news:...
> Hi,
>
> Unfortunately UPnP is considered a consumer-grade technology and as such
> was removed from the Server platform.
>
> For instance, if a business used Windows Server to share their Internet
> connection, their users could use all this Messenger functionality and
> whatever other software they decided to use that supported UPnP which may
> bypass any other security measures that were in place to prevent such
> usage.



 
Reply With Quote
 
Jonathan Kay [MVP]
Guest
Posts: n/a

 
      09-28-2006
Hi,

I don't disagree but getting such things added in can be, difficult. I'm not quite sure what
the story is for Longhorn server.

--
Jonathan Kay
Microsoft MVP - Windows Live Messenger/MSN Messenger/Windows Messenger
Associate Expert
http://www.microsoft.com/windowsxp/expertzone/
Messenger Resources - http://messenger.jonathankay.com
All posts unless otherwise specified are (c) 2006 Jonathan Kay.
You *must* contact me for redistribution rights.
--

"Dinko Deranja" <> wrote in message news:...
> Well, about bypassing - a single checkbox named "Allow UPnP" would be enough.
>
>
> "Jonathan Kay [MVP]" <> wrote in message
> news:...
>> Hi,
>>
>> Unfortunately UPnP is considered a consumer-grade technology and as such was removed from
>> the Server platform.
>>
>> For instance, if a business used Windows Server to share their Internet connection, their
>> users could use all this Messenger functionality and whatever other software they decided
>> to use that supported UPnP which may bypass any other security measures that were in place
>> to prevent such usage.

>
>



 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Is it worth it from XP Brian Taylor Windows Vista General Discussion 5 05-16-2008 01:26 AM
Is SP1 REALLY worth it? Gary Goldblum Windows Vista General Discussion 12 03-21-2008 09:46 PM
Re: UPNP works for everything but Messenger - even though it makes entries in the UPNP settings fine... and it worked before... Jonathan Kay [MVP] Windows MSN Messenger 3 04-29-2007 03:19 AM
IE 7 - is it worth it? Meg Internet Explorer 18 11-22-2006 09:04 PM
I'm curious about the UPnP functionality in MSN Messenger.– How can one tell what UPnP actions are automatically transpiring behind the scenes? Stan Shankman Windows MSN Messenger 1 08-20-2005 06:59 PM



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59