Skype Logo
Buy Skype Credit · Help ·
  • Download
  • Use Skype
  • Business
  • Shop
  • Account
  • Home
  • Get Connected
  • Features
  • Mobile
  • Prices
  • Share
  • All

Skype Community

  • Skype Community
  • English
  • Development, Betas...
  • Archive
  • Skype 4.1 Beta for...


Skype UPNP

Not closing ports

funkydude
Regular member
Posts: 5

**


I've not tested it with 4.1 yet, but in 4.x my router shows that ports opened by skype via UPNP are never closed when skype is closed.

Ports opened by other applications via UPNP close fine on exit, such as torrent applications, if you could please look into it.
Tue Jun 9 2009, 01:37 · Reply · Quote and reply · Permalink · Top ·

Raul Liive
Advanced Member
Posts: 2,697

Group Icon


Skype deletes old uPnP mappings on new start of the Skype client, if your router supports it.


--------------------
For support go to:
http://support.skype.com

I may not reply to Private Messages which have easy to find answer or should go to Customer Support.
Tue Jun 9 2009, 09:10 · Reply · Quote and reply · Permalink · Top ·
funkydude
Regular member
Posts: 5

**


Can you explain to me how that makes any logical sense whatsoever? You're saying that Skype removes the mapped ports when it starts... at which point it will re-open them again..?

They SHOULD be closed on Skype close, closing them manually is not appreciated, considering nearly every other app manages to do this fine, I don't see why Skype can't.
Tue Jun 9 2009, 12:59 · Reply · Quote and reply · Permalink · Top ·

Neil
Advanced Member
Posts: 5,314

Group Icon


opening ports via UPnP is great for Skype because it makes NAT traversal easy, but the UPnP function itself is NOT secure (there are known exploits in the wild too) and MANY security experts recommend turning this function OFF in the router


--------------------
Regards,
Neil


(GMT - 8)
AMD 3800+ Athlon 64 (HP), 1GB RAM
Upload: 500Kbps | Download: 5Mbps
Thu Jun 11 2009, 04:51 · Reply · Quote and reply · Permalink · Top ·
funkydude
Regular member
Posts: 5

**


I don't know what experts you consult, but that debate isn't for this thread. Yes it has security concerns, but you make it sound like the spawn of the devil. A NAT&SPI router with UPnP is perfectly secure.

I can't think of a worse security threat than a program not closing it's ports after it's finished with them, a.k.a. Skype.
Fri Jun 12 2009, 18:50 · Reply · Quote and reply · Permalink · Top ·

Neil
Advanced Member
Posts: 5,314

Group Icon


QUOTE (funkydude @ Fri Jun 12 2009, 09:50)
Go to the original post
I don't know what experts you consult, but that debate isn't for this thread. Yes it has security concerns, but you make it sound like the spawn of the devil. A NAT&SPI router with UPnP is perfectly secure.


the fact of the matter is that as currently implemented there is NO authentication associated with the app that uses UPnP so that makes it a BIG security threat -- and if you think that this is not necessary for apps that are already running on your system, think again (no need to help a trojan get set up to receive instructions after calling home)

if you disable UPnP like in the router like you should, then this thread becomes irrelevant, so I think it is perfectly valid to bring it up

QUOTE
I can't think of a worse security threat than a program not closing it's ports after it's finished with them, a.k.a. Skype.


although I agree on general principle, for there to be a security threat two things have to exist:

1) an app has to be listening to the open port (wouldn't be the case if Skype is closed at the time)

2) the app that is listening to the open port must have a known vulnerability that can be leveraged (assuming you can even tell from the outside what app this might even be)


--------------------
Regards,
Neil


(GMT - 8)
AMD 3800+ Athlon 64 (HP), 1GB RAM
Upload: 500Kbps | Download: 5Mbps
Fri Jun 12 2009, 19:57 · Reply · Quote and reply · Permalink · Top ·
funkydude
Regular member
Posts: 5

**


Well my point is it's obviously a problem that shouldn't be dismissed.
Mon Jun 15 2009, 13:20 · Reply · Quote and reply · Permalink · Top ·
funkydude
Regular member
Posts: 5

**


Bump.
Wed Jul 1 2009, 02:12 · Reply · Quote and reply · Permalink · Top ·

Raul Liive
Advanced Member
Posts: 2,697

Group Icon


This issue has not been dismissed.

I have raised it as a feedback point for considerations.


--------------------
For support go to:
http://support.skype.com

I may not reply to Private Messages which have easy to find answer or should go to Customer Support.
Wed Jul 1 2009, 12:08 · Reply · Quote and reply · Permalink · Top ·
hrdubwd
New member
Posts: 3

*


When I found the "enable uPnP" option in 4.1, I was somewhat surprised to find no help whatsoever anywhere - no explanation, nothing.

I was under the impression that uPnP was a problem anyway - but has anything changed since this: http://www.grc.com/UnPnP/UnPnP.htm ? I have always disabled it since then (2001).

The question, what is it there for in terms that anyone can understand? If it is a risk (and its behaviour now seems to be even odder), why is this not explained?
Sun Jul 12 2009, 08:22 · Reply · Quote and reply · Permalink · Top ·

Neil
Advanced Member
Posts: 5,314

Group Icon


if you disable this feature in your router, it does not matter whether the option to use it is set in the Skype client or not

apparently Skype only considers two types of users:

a) those that know already, and who therefore don't need an explanation

b) those that don't need to know

speechless.png


--------------------
Regards,
Neil


(GMT - 8)
AMD 3800+ Athlon 64 (HP), 1GB RAM
Upload: 500Kbps | Download: 5Mbps
Tue Jul 14 2009, 00:37 · Reply · Quote and reply · Permalink · Top ·
hrdubwd
New member
Posts: 3

*


Thanks, Neil, noted.
Actually, disabled on the laptop, but your types assessment seems all too common, unfortunately.
Tue Jul 14 2009, 01:24 · Reply · Quote and reply · Permalink · Top ·

Neil
Advanced Member
Posts: 5,314

Group Icon


the best place to disable UPnP is always in the router itself

...my previous post was not my assessment, by the way . . . I was being sarcastic . . . of course there should be some sort of explanation


--------------------
Regards,
Neil


(GMT - 8)
AMD 3800+ Athlon 64 (HP), 1GB RAM
Upload: 500Kbps | Download: 5Mbps
Tue Jul 14 2009, 01:56 · Reply · Quote and reply · Permalink · Top ·
hrdubwd
New member
Posts: 3

*


Router: not using one at the moment. But when I was, I saw no such setting.
Sarky: I realized that, of course! ;-) But I have still encountered this kind of opacity many times.
Explanation: And I am hoping still that we get one.

Put it this way, there are those who are suspicious of Skype as it is. This will not help my comfort.



Tue Jul 14 2009, 09:05 · Reply · Quote and reply · Permalink · Top ·

Neil
Advanced Member
Posts: 5,314

Group Icon


Skype and security experts like Steve Gibson apparently disagree on whether the risk associated with the current implementation of UPnP (no authentication of process using the feature) outweighs the benefit (easy NAT traversal)

I side with Steve on this, especially as there are already some known exploits associated with UPnP

Skype just wants it to work, and UPnP is often/usually ON in the router by default

iirc, Skype's use of UPnP is also ON by default


--------------------
Regards,
Neil


(GMT - 8)
AMD 3800+ Athlon 64 (HP), 1GB RAM
Upload: 500Kbps | Download: 5Mbps
Tue Jul 14 2009, 10:36 · Reply · Quote and reply · Permalink · Top ·
 
2 User(s) are reading this topic (2 Guests and 0 Anonymous Users)
0 Members:

Display Mode: Standard · Switch to: Linear+ · Switch to: Outline

Track this topic · Email this topic · Print this topic · Subscribe to this forum

Welcome guest Read a quick guide to using these community forums.

  • My area
  • Sign in
  • Related
  • Search
  • Community guidelines
  • User guides
  • Knowledgebase

Heartbeat Heartbeat See how our products are performing on the Heartbeat blog.

About us · News · Jobs · Prices · Security · Site map
Privacy policy · Legal · © 2009 Skype Limited