Saturday, October 19, 2013

Supply chain anyone?

Backdoors are not an option, they're a standard feature!


From Craig's blog, that was tweeted by HD Moore

Lest anyone think that D-Link is the only vendor who puts backdoors in their products, here’s one that can be exploited with a single UDP packet, courtesy of Tenda.
After extracting the latest firmware for Tenda’s W302R wireless router, I started looking at /bin/httpd, which turned out to be the GoAhead webserver:



No comments: