Full Disclosure mailing list archives
Re: FiWin SS28S WiFi VoIP SIP/Skype Phone Hardcoded Telnet user/pass and debug access
From: "Shawn Merdinger" <shawnmer () gmail com>
Date: Fri, 22 Sep 2006 19:44:50 -0700
Hi,
Paul Schmehl wrote:The engineers who designed this should be summarily fired. The terminal stupidity of it is mind boggling!
Nick FitzGerald <nick () virus-l demon co uk> wrote:
I think _beyond_ mind-boggling.
Your spirited comments are fun to read, but I personally don't find these types of vulnerabilities all that surprising. There's a rich history of extraneous ports, services, debugging, backdoors, hardcoded credentials, etc. etc. across all types of products from all types of vendors, from the well-established "Makin' Boat Payments Big Boys" to "Fly-By-Night, Inc." Also, most all of the 802.11b/g VoIP Wireless phones released in the past year or so have these type of simplistic security issues which should've been caught way back in QA. Btw, back in 2004, Network World did a basic wired-side analysis of 15 access points and found these exact same issues, see http://www.networkworld.com/reviews/2004/1004wirelesslockside.pdf Realistically, I don't expect this situation to change, whether it's a US $50,000 "enterprise-class, best-of-breed, blah, blah, blah" or a US $50 "home network" box....or as one funny, insightful security engineer I worked with put it years ago -- "It's all the same. Nobody cares." Thanks! --scm _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/
Current thread:
- FiWin SS28S WiFi VoIP SIP/Skype Phone Hardcoded Telnet user/pass and debug access Shawn Merdinger (Sep 22)
- Re: FiWin SS28S WiFi VoIP SIP/Skype Phone Hardcoded Telnet user/pass and debug access Paul Schmehl (Sep 22)
- Re: FiWin SS28S WiFi VoIP SIP/Skype Phone Hardcoded Telnet user/pass and debug access Nick FitzGerald (Sep 22)
- Re: FiWin SS28S WiFi VoIP SIP/Skype Phone Hardcoded Telnet user/pass and debug access Shawn Merdinger (Sep 23)
- Re: FiWin SS28S WiFi VoIP SIP/Skype Phone Hardcoded Telnet user/pass and debug access pagvac (Sep 22)
- Re: FiWin SS28S WiFi VoIP SIP/Skype Phone Hardcoded Telnet user/pass and debug access Nick FitzGerald (Sep 22)
- Re: FiWin SS28S WiFi VoIP SIP/Skype Phone Hardcoded Telnet user/pass and debug access Paul Schmehl (Sep 22)