Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

Enterprise AV devices contain secret backdoor
iTnews ^ | Jan 22 2016 10:16AM (AUS) | Juha Saarinen

Posted on 01/21/2016 7:20:10 PM PST by Utilizer

Audiovisual devices made by AMX for government, education and business users contain a secret backdoor that allows full remote access without detection, security researchers have found.

European security firm SEC Consult discovered the hidden backdoor account by analysing an operating system program for user management on the AMX Netlinx NX-1200 AV controller, which is sold in Australia.

The binary contains a function named "setUpSubtleUserAccount", which adds a hidden user with administrative privileges, SEC Consult said.

Both the account username and password are stored persistently on the AMX NX-1200, meaning if an attacker has this information, they can potentially log on remotely to multiple devices.

That secret account is named BlackWidow, after a Marvel Comics superhero.

SEC Consult contacted AMX in March last year with details of the backdoor, and a patch was issued some seven months after the disclosure.

(Excerpt) Read more at itnews.com.au ...


TOPICS: Business/Economy; Computers/Internet; Local News
KEYWORDS: businessware; malware; rootware; security
Only in Oz so far, but any security-focused individuals might wish to have a look at this to see if it translates to other business and/or POS systems.

This one seems to be just beginning, so best to take no chances I would think.

1 posted on 01/21/2016 7:20:10 PM PST by Utilizer
[ Post Reply | Private Reply | View Replies]

To: All
AMX, however, did not remove the backdoor with the patch. Instead, the company swapped the superhero user name to 1MB@tMaN, and the account with full administrative privileges, accessible via Secure Shell or a web interface, remained.

(Emphasis intentionally indicated.)

2 posted on 01/21/2016 7:24:13 PM PST by Utilizer (Bacon A'kbar! - In world today are only peaceful people, and the muzrims trying to kill them)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Utilizer
setUpSubtleUserAccount

Geeze! How stupid is it to leave a symbol name like that in the binary? Remember Windows NT and "_NSAKEY"?

3 posted on 01/21/2016 7:27:21 PM PST by SeeSharp
[ Post Reply | Private Reply | To 1 | View Replies]

To: All

Update: It seems some US government agencies (White Hut, Military Services) might have been / are targeted by this problem. More developing...


4 posted on 01/21/2016 7:30:35 PM PST by Utilizer (Bacon A'kbar! - In world today are only peaceful people, and the muzrims trying to kill them)
[ Post Reply | Private Reply | To 1 | View Replies]

To: SeeSharp
Remember Windows NT and "_NSAKEY"?

All too well, unfortunately.

5 posted on 01/21/2016 7:42:18 PM PST by Utilizer (Bacon A'kbar! - In world today are only peaceful people, and the muzrims trying to kill them)
[ Post Reply | Private Reply | To 3 | View Replies]

To: Utilizer

Makes you wonder about the vulnerability management security of our nation’s gov’t voting machines...
Democrat leftist hackers and all.


6 posted on 01/21/2016 8:01:51 PM PST by MarchonDC09122009 (When is our next march on DC? When have we had enough?)
[ Post Reply | Private Reply | To 1 | View Replies]

To: MarchonDC09122009

Already proven to be faulty, not that anyone that counts on the erroneous tallies for their job security (*cough* most elected officials *cough*) are worried about it.


7 posted on 01/21/2016 8:04:20 PM PST by Utilizer (Bacon A'kbar! - In world today are only peaceful people, and the muzrims trying to kill them)
[ Post Reply | Private Reply | To 6 | View Replies]

To: Utilizer

The whole country has gone Chicago.

RE: “Already proven to be faulty, not that anyone that counts on the erroneous tallies for their job security (*cough* most elected officials *cough*) are worried about it.”


8 posted on 01/21/2016 8:07:47 PM PST by MarchonDC09122009 (When is our next march on DC? When have we had enough?)
[ Post Reply | Private Reply | To 7 | View Replies]

To: Utilizer

Crestron 2016!!!


9 posted on 01/21/2016 8:48:32 PM PST by Squeako (Trump: The Red Kool-Aid to Obama's Blue Kool-Aid. (See home page for Rules For Trumpicals))
[ Post Reply | Private Reply | To 1 | View Replies]

To: Utilizer
Update: It seems some US government agencies (White Hut, Military Services) might have been / are targeted by this problem. More developing...

Good thing the Beast didn't use a government server, eh?
10 posted on 01/22/2016 3:07:21 AM PST by Roccus (Obama & Holder LLP, Procurers of fine arms to the most discerning drug lords (202) 456-1414))
[ Post Reply | Private Reply | To 4 | View Replies]

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson