Become a Patron!

Hidden backdoor discovered in Chinese IoT devices

VUBot

Staff member
Diamond Contributor
ECF Refugee
Vape Media
Researchers at Trustwave have uncovered a backdoor in IoT devices from a Chinese manufacturer that could leave them open to exploitation. The backdoor is present in almost all devices produced by VoIP specialist DBLTek, and appears to have been purposely built in for use by the vendor. It uses a simple challenge and response mechanism to allow remote access. However, Trustwave's investigation has shown this scheme to be fundamentally flawed in that it is not necessary for a remote user to possess knowledge of any secret or password, besides the challenge itself and knowledge of the protocol/computation used. The issue… [Continue Reading]

yYlvzfrL9iA


Continue reading...
 

VU Sponsors

Top