In the dark ages of personal computers (1980s and '90s), you either needed to be a computer geek or have access to one if you wanted any device to work with your computer. You had to go through a complicated driver installation process and possibly replace system files. If someone who was used to the process of adding a network card to a system today looked at the process of how to do it in 1989, they would swear that the early computer user was practicing witchcraft. Today, when you plug something into your computer it lets you know that it detected something and can either use the default driver (assuming one exists), or you can choose your own. My how the world has changed.
The technology that allows this type of communication between devices is known as Universal Plug and Play (UPnP). It was designed to allow devices on the same network to communicate with one another without complicating the process. It makes adding devices to a network more convenient, but convenience and security are always diametrically opposed. In other words, unlimited (and poorly patched) UPnP devices are ripe feeding grounds for computer hackers who want into you system.
In a recent report releaded by Rapid 7, an Internet security firm, there are approximately 40-50 million devices exposed to the Internet with a host of UPnP vulnerabilities. The real issue is that UPnP was never designed to be exposed to the Internet and security was never a consideration in its design. On top of that, early versions of it were easy to infiltrate and force the affected devices to run malicious code. Several current devices are still running the vulnerable version of UPnP because their manufacturers did not update the code on their hardware.
Since this blog focuses on the security of retailers, why am I including this report? The simple answer is that if you are running a switch, printer, router or another device that is UPnP enabled, you are potentially exposing your network to computer hackers. If you take credit cards, and have to comply with PCI, then section 6 (which asks about applying security patches), and section 11 (which includes internal vulnerability scans and penetration testing) become much more critical if you have UPnP devices on your network.
The first vulnerability I personally ever read about on UPnP was exposed in 2001; 12 years later, not much has changed on this front. UPnP should not be enabled if you are concerned about security. If you must use it because of how your network is put together or managed, than at least know that you are running the latest versions of the technology that are less vulnerable to attacks. If you are unsure of where you stand, find a modern-day geek (or at least your technology provider) and ask.
567
http://global.networldalliance.com/new/images/slideshows/show567_thumb8653.jpg
NRA's 2013 Kitchen Innovation winners
NRA's 2013 Kitchen Innovation winners
562
http://global.networldalliance.com/new/images/slideshows/show562_thumb8595.jpg
Order up: EMN8's self-order tech at Domino's, KFC India
Order up: EMN8's self-order tech at Domino's, KFC India
559
http://global.networldalliance.com/new/images/slideshows/show559_thumb8515.jpg
Naked Pizza thrives in Dubai
Naked Pizza thrives in Dubai
542
http://global.networldalliance.com/new/images/slideshows/show542_thumb8207.gif
Minsky's Pizza turns 37
Minsky's Pizza turns 37
537
http://global.networldalliance.com/new/images/slideshows/show537_thumb8119.gif
NAFEM 2013
NAFEM 2013
531
http://global.networldalliance.com/new/images/slideshows/show531_thumb8031.gif
Pizza chains' LTOs kick off 2013
Pizza chains' LTOs kick off 2013
512
http://global.networldalliance.com/new/images/slideshows/show512_thumb7713.gif
The Loop Pizza Grill new restaurant prototype
The Loop Pizza Grill new restaurant prototype
506
http://global.networldalliance.com/new/images/slideshows/show506_thumb7615.gif
Patxi's Pizza's new menu items
Patxi's Pizza's new menu items
505
http://global.networldalliance.com/new/images/slideshows/show505_thumb7583.jpg
4 technologies gaining ground in restaurant industry
4 technologies gaining ground in restaurant industry
495
http://global.networldalliance.com/new/images/slideshows/show495_thumb7351.gif
Boston Pizza's new menu
Boston Pizza's new menu
Low Cost ATM
http://global.networldalliance.com/new/images/products/RL2000_100.gif
1019/Low-Cost-ATM
Mexican Style Meats and Taco Filling | Burke Corporation |
http://global.networldalliance.com/new/images/products/Chorizo100.jpg
1298/Mexican-Style-Meats-and-Taco-Filling-Burke-Corporation
Recipes
http://global.networldalliance.com/new/images/products/cubanmedianochepizza_100.jpg
1917/Recipes
Pizza POS Software
http://global.networldalliance.com/new/images/products/5937.png
5937/Pizza-POS-Software
Nationwide Criminal Records
http://global.networldalliance.com/new/images/products/Criminal_Search_iix.gif
1427/Nationwide-Criminal-Records
Pizza Toppings | Sausage Toppings | Beef Toppings | Burke …
http://global.networldalliance.com/new/images/products/BeefPorkToppings100.jpg
1296/Pizza-Toppings-Sausage-Toppings-Beef-Toppings-Burke-Corporation
POS health test: do a quick check
http://global.networldalliance.com/new/images/products/1288.png
1288/POS-health-test-do-a-quick-check
PeopleMatter HIRE™
http://global.networldalliance.com/new/images/products/4625.png
4625/PeopleMatter-HIRE
MVR Reports
http://global.networldalliance.com/new/images/products/MVR_Report_iix.gif
1252/MVR-Reports
Call Center Ordering
http://global.networldalliance.com/new/images/products/5939.png
5939/Call-Center-Ordering
|
Inside Networld Media Group Network QSRWeb
|
Popular on Networld Media Group | Other Networld Media Group Sites | Global Partners |
User Comments