View Single Post
Cpp Cpp's Avatar

JCF Member

Joined: Mar 2001

Posts: 1,557

Cpp is doing well so far

May 19, 2009, 09:47 PM
Cpp is offline
Reply With Quote
It does not matter what the default upnp setting is for jj2+. As long as upnp is enabled by the router, port forwarding can be manipulated by any application inside your local network (this includes jj2+ and the flash hack described in the article I linked). The only way to prevent this is to turn off upnp on your router completely. This, however, defeats the purpose of easy port forwarding.

I think that jj2+ can safely have the upnp enabled by default since jj2+ isn't a malicious application and doesn't affect the security in any way. Besides I don't think that many people will even bother to turn off their router upnp as a result.
__________________
<a href="http://nmap.org/"><img border="0" alt="Nmap Security Scanner" src="http://images.insecure.org/nmap/images/prop/nmap_bnr_matrix_pfos.gif"/></a>