Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Wow. Back door accounts are just totally inexcusable these days - manufacturers should be held to account if their back doors end up getting exploited by threat actors. (Granted, you could argue it’s hard to distinguish between a really terrible bug and a back door, sometimes, but “intent” should cover this difference…)

Would you happen to have a write up/article about this series of events that isn’t a sanitized series of security bulletins? Sounds like it’d make for good reading.




Reading further along in the forum, the `walter` thing sounds like it's only present in test code and comments.

The actual backdoor looks like the `jisoosocoolhbsmgnt` session ID [1] that was removed in the update [2]. It looks like a hardcoded session ID used for tests [3]. Leaving something like that hardcoded and active in the production code is inexcusable.

[1] https://forum.qnap.com/viewtopic.php?f=45&t=160849&start=495...

[2] https://forum.qnap.com/viewtopic.php?f=45&t=160849&start=555...

[3] https://forum.qnap.com/viewtopic.php?f=45&t=160849&start=495...


Wow !




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: