I have been Hacked

This is good generic advice as I understand it BUT, also as I understand it the UPNP issue is an old one which is rectified in newer routers and older routers with newer firmware, I thought that there were some good reasons for needing UPNP enabled?

GRC ShieldsUp now scans UPNP on your router to check if it is secure / patched. https://www.grc.com/

Unless you actually have a good reason better disable it.

If someone can tell me a good reason to have it enabled, speak now!

Iā€™d typically follow your advice re: pick a different port. I did find that it caused no end of trouble when trying to configure TTS - whereas defaulting back to 443 worked right away. Somewhere the default expected port became the only possible port. It was a few months back, might be time to see if thatā€™s updated.

My point wasā€¦hiding will not protect you if you if you donā€™t have good security practices.

Donā€™t bury money on a beach and expect it not to be found by a random kid with a shovel

1 Like

Itā€™s been said ad nauseam but ā€˜Security through obscurityā€™ is a horrible practice.

Best bet is stay up to date on software, have all patches installed, use a good password and make use of best practices.

1 Like

Yes agreed. I wasnā€™t saying just to hide. Yes, patch up, secure yourself, etc etc.

1 Like

Site list router vulnerabilities.
https://routersecurity.org/bugs.php

I am thinking router flaw that lets them into network and onto installā€¦OR just user error
anyway, The site above is worth a look.

UPNProxy is a one I been look to share for a few days
UPnP open by default on WAN by default on major consumer brand router

I should make clear, Iā€™m talking about choosing a non-standard port on top of following best practices. Obviously switching ports alone is just asking for trouble.

The case that always pops into my head is how (a couple years ago now) my SSH port had people knocking - sometimes hundreds a day - when on port 22. The moment I switched to a high number non-standard port the failed entry log dropped off to nothing. Call it personal choice but I find some satisfaction in that.

I think many understand your idea(i did at least)

Just some donā€™t read ā€œdo all 5 of these network best practices togetherā€ā€¦they read ā€œdo this one thing and your secureā€ Unfortunately

best discourse ever. so glad i started all this and sort of glad i got hacked to be honest