Skip to comments.
Enterprise AV devices contain secret backdoor
iTnews ^
| Jan 22 2016 10:16AM (AUS)
| Juha Saarinen
Posted on 01/21/2016 7:20:10 PM PST by Utilizer
Audiovisual devices made by AMX for government, education and business users contain a secret backdoor that allows full remote access without detection, security researchers have found.
European security firm SEC Consult discovered the hidden backdoor account by analysing an operating system program for user management on the AMX Netlinx NX-1200 AV controller, which is sold in Australia.
The binary contains a function named "setUpSubtleUserAccount", which adds a hidden user with administrative privileges, SEC Consult said.
Both the account username and password are stored persistently on the AMX NX-1200, meaning if an attacker has this information, they can potentially log on remotely to multiple devices.
That secret account is named BlackWidow, after a Marvel Comics superhero.
SEC Consult contacted AMX in March last year with details of the backdoor, and a patch was issued some seven months after the disclosure.
(Excerpt) Read more at itnews.com.au ...
TOPICS: Business/Economy; Computers/Internet; Local News
KEYWORDS: businessware; malware; rootware; security
Only in Oz so far, but any security-focused individuals might wish to have a look at this to see if it translates to other business and/or POS systems.
This one seems to be just beginning, so best to take no chances I would think.
1
posted on
01/21/2016 7:20:10 PM PST
by
Utilizer
To: All
AMX, however,
did not remove the backdoor with the patch.
Instead, the company swapped the superhero user name to 1MB@tMaN, and the account with full administrative privileges, accessible via Secure Shell or a web interface, remained.
(Emphasis intentionally indicated.)
2
posted on
01/21/2016 7:24:13 PM PST
by
Utilizer
(Bacon A'kbar! - In world today are only peaceful people, and the muzrims trying to kill them)
To: Utilizer
setUpSubtleUserAccount Geeze! How stupid is it to leave a symbol name like that in the binary? Remember Windows NT and "_NSAKEY"?
3
posted on
01/21/2016 7:27:21 PM PST
by
SeeSharp
To: All
Update: It seems some US government agencies (White Hut, Military Services) might have been / are targeted by this problem. More developing...
4
posted on
01/21/2016 7:30:35 PM PST
by
Utilizer
(Bacon A'kbar! - In world today are only peaceful people, and the muzrims trying to kill them)
To: SeeSharp
Remember Windows NT and "_NSAKEY"? All too well, unfortunately.
5
posted on
01/21/2016 7:42:18 PM PST
by
Utilizer
(Bacon A'kbar! - In world today are only peaceful people, and the muzrims trying to kill them)
To: Utilizer
Makes you wonder about the vulnerability management security of our nation’s gov’t voting machines...
Democrat leftist hackers and all.
6
posted on
01/21/2016 8:01:51 PM PST
by
MarchonDC09122009
(When is our next march on DC? When have we had enough?)
To: MarchonDC09122009
Already proven to be faulty, not that anyone that counts on the erroneous tallies for their job security (*cough* most elected officials *cough*) are worried about it.
7
posted on
01/21/2016 8:04:20 PM PST
by
Utilizer
(Bacon A'kbar! - In world today are only peaceful people, and the muzrims trying to kill them)
To: Utilizer
The whole country has gone Chicago.
RE: “Already proven to be faulty, not that anyone that counts on the erroneous tallies for their job security (*cough* most elected officials *cough*) are worried about it.”
8
posted on
01/21/2016 8:07:47 PM PST
by
MarchonDC09122009
(When is our next march on DC? When have we had enough?)
To: Utilizer
9
posted on
01/21/2016 8:48:32 PM PST
by
Squeako
(Trump: The Red Kool-Aid to Obama's Blue Kool-Aid. (See home page for Rules For Trumpicals))
To: Utilizer
Update: It seems some US government agencies (White Hut, Military Services) might have been / are targeted by this problem. More developing...
Good thing the Beast didn't use a government server, eh?
10
posted on
01/22/2016 3:07:21 AM PST
by
Roccus
(Obama & Holder LLP, Procurers of fine arms to the most discerning drug lords (202) 456-1414))
Disclaimer:
Opinions posted on Free Republic are those of the individual
posters and do not necessarily represent the opinion of Free Republic or its
management. All materials posted herein are protected by copyright law and the
exemption for fair use of copyrighted works.
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson