5 ms·
Aaaaaand: https://twitter.com/hackerfantastic/status/1103087869063704576 https://twitter.com/hackerfantastic/status/11030878690637045...
by stargazing 8y ago
Aaaaaand: https://twitter.com/hackerfantastic/status/1103087869063704576 https://twitter.com/hackerfantastic/status/11030878690637045...
- meowface 8y agoThough the obvious explanation for that is that it was an intentional backdoor, that honestly looks more to me like a legitimate oversight than a backdoor. I think an actual backdoor would be a lot more subtle and clever than that. Especially since this way, absolutely anyone could exploit it (it's just Java Debug Wire Protocol). Also, you have to explicitly run it in debug mode for this to happen, which probably only a small percentage of end users will do. Kind of seems like the equivalent of running Flask apps in debug mode, which by default will handle exceptions by showing a traceback with an interactive debugger that can be used to execute arbitrary code. There could be some backdoors in it, but I'm leaning towards that not being an intentional one. (But I definitely could be totally wrong; you never know when it comes to intelligence agencies.)
- earenndil 8y agoI also don't think it's a backdoor, but the best way to hide a backdoor is to make it look like a mistake.
- meowface 8y ago>but the best way to hide a backdoor is to make it look like a mistake It is, but usually the best way to do is to make it look like a mistake that's very subtle and difficult to notice without careful testing and analysis, kind of like Apple's infamous SSL "goto fail". That's a classic example of a vulnerability that really could be either an honest mistake or a very insidious backdoor. This is more like leaving the house's sliding glass door to the backyard wide open for everyone to see.
- hiccuphippo 8y agoThen again, maybe the best way to hide a backdoor is to have another very obvious one so people look the other way.
- WrtCdEvrydy 8y agoI wonder if they run Ghidra on a remote machine and run it with some sort of command and control center to automate tasks (IE, run regular some basic automated stuff). This makes the whole release even more interesting, I wonder if we'll get a statement on why they have that debug mode.
- merlincorey 8y ago> Kind of seems like the equivalent of running Flask apps in debug mode, which by default will handle exceptions by showing a traceback with an interactive debugger that can be used to execute arbitrary code. As an aside, this is no longer precisely the case, though it was for quite some time. With modern Flask (> 1.0.0), the debug server will start with a randomly generated PIN output to STDOUT when the server starts. In turn this PIN must be entered on the web interface to execute commands.
- strictnein 8y agoAn overhyped tweet. You have to enable debug mode on it. It's not something that runs by default.
- zip1234 8y agoYes this doesn't really seem like a big deal
- paxys 8y agoIf you have every port on your machine exposed to the internet you deserve to get hacked.
- curiousgal 8y agoIt really sucks that an agency funded by your tax dollars is out to get you.
- aarong11 8y agoCtrl-F + Backdoor