Something is punching holes in my WAG54G

Discussion in 'Other Linksys Equipment' started by komUnec8, Nov 25, 2004.

  1. komUnec8

    komUnec8 Network Guru Member

    I've noticed (twice now) that something is accessing my WAG54G configuration without my permission (running v.1.02.7). (no one but me has access to the box).

    The end result is that unwanted entries are appearing in my Single Port Forwarding table.

    These are referenced as follows:-

    Application External Port Internal port Protocol IP address Enabled
    msmsgs xxxxx 12129 TCP 192.168.2.x Yes
    msmsgs xxxxx 12307 TCP 192.168.2.x Yes

    I understand that msmsgs.exe is MS Messenger, but I am really surprised that something (maybe an App on my PC?) is able to insert itself into the Firewall settings without me doing it manually!?

    Either something has learned my Linksys Admin login, or access is being gained via SNMP (or UPNP ?) to insert these settings into the Port Forwarding table.

    Anybody come across this before :?:
  2. 4Access

    4Access Network Guru Member

    MSN Messenger is UPNP aware. If you don't want programs to be able to adjust your firewall rules simply disable UPNP in the router and this won't be an issue.
  3. komUnec8

    komUnec8 Network Guru Member

    Thanks for the confirmation, thought it may be that so have been running with UPnP off for the last few days, with seemingly no more holes!
