Results 1 to 2 of 2

Thread: [News] Chinese Internet of things gear has a backdoor

  1. #1
    Join XS BOINC Team StyM's Avatar
    Join Date
    Mar 2006
    Location
    Tropics
    Posts
    9,468

    [News] Chinese Internet of things gear has a backdoor

    http://www.fudzilla.com/news/43034-c...has-a-backdoor

    A Chinese tech firm which specialises in VoIP products has been shipping products with a backdoor which could mean that data hungry spooks can control your light switches.

    Security outfit Trustwave made the discovery of a hidden backdoor in DblTek?s devices which was apparently put there to allow the manufacturer access its hardware. Of course it is also available for any hacker who can crack it, and any government spooks who know about it.

    The backdoor is in the Telnet admin interface of DblTek-branded devices, and potentially allows an attacker to remotely open a shell with root privileges on the target device.

    When asked about the backdoor DblTek issued a patch which rather than removing the flaw, the vendor simply made it more difficult to access and exploit.

    Trustwave said that the firmware with the hole in the middle is present on almost every GSM-to-VoIP device which DblTek makes (hardware which is mainly used by SMBs). Trustwave has found hundreds of these devices on the net, and many other brands which use the same firmware.

    The security company also said that it has been able to successfully exploit both the old backdoor, and the new (better hidden) modified version which was patched in at the end of last year.

  2. #2
    Xtreme Enthusiast
    Join Date
    Feb 2010
    Posts
    578
    No surprises there.

Bookmarks

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •