Interesting article:
http://www.cisco.com/warp/public/707/cisco-sa-20040407-username.shtml
Any of you system admins out there with Cisco hardware should give this a serious read.
Interesting article:
http://www.cisco.com/warp/public/707/cisco-sa-20040407-username.shtml
Any of you system admins out there with Cisco hardware should give this a serious read.
As noted, Cisco PSIRT published an advisory on April 7, 2004 that a hard‑coded username/password exists in all releases of the Wireless LAN Solution Engine (WLSE) and Hosting Solution Engine (HSE). The account cannot be disabled and, in affected builds, grants full administrative control. Patches were made available for the listed WLSE/HSE releases. (sec.cloudapps.cisco.com)
That kind of factory backdoor is exactly the scenario and were worried about: one undisclosed account with admin rights can be used to hide rogue access points, alter RF plans, or change hosted-site routing — effectively turning the appliance into a foothold for further attacks. The advisory spells out those impacts and stresses there was no workaround in the affected releases. (sec.cloudapps.cisco.com)
Immediate practical steps (applies to any admin who still runs WLSE/HSE or similar appliances):
This incident (April 7, 2004) is a useful reminder: treat vendor defaults as untrusted, require proof of secure development practices from suppliers, and make management‑plane hardening and account auditing part of any deployment checklist. If a patched image is not available or you cannot patch quickly, consider decommissioning or replacing the appliance with a supported, auditable solution. (sec.cloudapps.cisco.com)
Jump to Post— alc6379 120Wow.
How dumb is this? You'd think that in this day and age with all of these security fears we've got going around, Cisco of all places, which offers a FREAKING INTERNET SECURITY CERTIFICATION would have thought better than to hard-code a username/password pair into their firmware.
Ah …
Wow.
How dumb is this? You'd think that in this day and age with all of these security fears we've got going around, Cisco of all places, which offers a FREAKING INTERNET SECURITY CERTIFICATION would have thought better than to hard-code a username/password pair into their firmware.
Ah well... at least they released a patch... :rolleyes:
APC has done the same thing too. It is really disturbing that these big companies would include such backdoors. All it takes is one disgruntled employee to cause a lot of havoc. Sure, the developers of the systems would know of bugs, and other exploits as they did create the product, but setting up a straight-forward backdoor is a bit much.
Agreed. One disgruntled employee (bad apple) can spoil the lot. Why would they include it in their hardware? Sounds like leaving the key underneath the doormat if you know what I mean...and then putting up a sign with an arrow that points under the mat and says "key" (pink neon, blink blink, blinkety blink)
We're a friendly, industry-focused community of developers, IT pros, digital marketers, and technology enthusiasts meeting, networking, learning, and sharing knowledge.