3 ms·
If I was making an intentional back door I wouldn't make anything that stupid. The super-secret password is "password123". Maybe you have more faith in develop
by untog 6y ago
If I was making an intentional back door I wouldn't make anything that stupid. The super-secret password is "password123".
Maybe you have more faith in developers than I do because this sounds exactly like a dumb mistake/cutting corners to me.
- mynameisvlad 6y agoI don't think you understand, "password123!" was the password the researcher set. In the CVE, it details the call it executes to retrieve the password from nvram.
- untog 6y agoAhh I misread. Even still. Directly injecting the password in the source of a JS file for the purposes of checking authentication? That screams naive error to me.