Posted on 01/21/2016 7:20:10 PM PST by Utilizer
Audiovisual devices made by AMX for government, education and business users contain a secret backdoor that allows full remote access without detection, security researchers have found.
European security firm SEC Consult discovered the hidden backdoor account by analysing an operating system program for user management on the AMX Netlinx NX-1200 AV controller, which is sold in Australia.
The binary contains a function named "setUpSubtleUserAccount", which adds a hidden user with administrative privileges, SEC Consult said.
Both the account username and password are stored persistently on the AMX NX-1200, meaning if an attacker has this information, they can potentially log on remotely to multiple devices.
That secret account is named BlackWidow, after a Marvel Comics superhero.
SEC Consult contacted AMX in March last year with details of the backdoor, and a patch was issued some seven months after the disclosure.
(Excerpt) Read more at itnews.com.au ...
This one seems to be just beginning, so best to take no chances I would think.
(Emphasis intentionally indicated.)
Geeze! How stupid is it to leave a symbol name like that in the binary? Remember Windows NT and "_NSAKEY"?
Update: It seems some US government agencies (White Hut, Military Services) might have been / are targeted by this problem. More developing...
All too well, unfortunately.
Makes you wonder about the vulnerability management security of our nation’s gov’t voting machines...
Democrat leftist hackers and all.
Already proven to be faulty, not that anyone that counts on the erroneous tallies for their job security (*cough* most elected officials *cough*) are worried about it.
The whole country has gone Chicago.
RE: “Already proven to be faulty, not that anyone that counts on the erroneous tallies for their job security (*cough* most elected officials *cough*) are worried about it.”
Crestron 2016!!!
Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.