5 ms·
The article doesn't disclose the value of "sys.rzadmin.password", but this writeup from 2022 does: https://boschko.ca/tenda_ac1200_router/ https://boschko.ca/t
by greyface- 3mo ago
The article doesn't disclose the value of "sys.rzadmin.password", but this writeup from 2022 does:
https://boschko.ca/tenda_ac1200_router/ https://boschko.ca/tenda_ac1200_router/
Spoiler: it's "rzadmin". And it looks like there are a bunch of other goodies in the firmware, too.
- lemagedurage 3mo agoSounds like a convenience feature for a dev that they forgot to remove before distribution, since it's this poorly hidden.
- sph 3mo agoIn computer security, never attribute to ignorance that which is adequately explained by malice.
- hnlmorg 3mo agoYou’ve got the saying backwards: “Never attribute to malice that which is adequately explained by stupidity.” https://en.wikipedia.org/wiki/Hanlon%27s_razor https://en.wikipedia.org/wiki/Hanlon%27s_razor
- jchw 3mo agoPretty sure the point was to invert it. :)
- hnlmorg 3mo agoYes, I got their point. My point is that’s the opposite of reality.
- naruhodo 3mo agoHis point is that in security, the opposite applies. The supposed "incompetence" is just plausible deniability for a malicious act.
- hnlmorg 3mo agoYes, and my point is that hasn’t been the case in my experience.
- natebc 3mo agoIt's because you (like me) aren't quite as paranoid as security people are. Personally I couldn't sleep at night if I was security people. It's really a matter of context. Security people tend to only be involved when things are already nefarious where as boring old normal people like us see get to see the mundane everyday mistakes so not just the nefarious bits.
- deleted 3mo ago[deleted]
- coldpie 3mo agoI'm a security people. I can say with confidence that a tiny, tiny, tiny, tiny fraction of these security issues are deliberate. Almost all of them are just dumb mistakes because making good software is really hard and really, really expensive and there is no market incentive to make good software. You don't need to get hired at the safe factory to build an elaborate back door into the production line if safes are actually just cardboard boxes, you know? It's possible the backdoor is deliberate, I have no idea in this particular case, but the more likely situation, absent more information, is that someone who is earning a middling wage just added the "feature" and didn't think about the security implications because no one cares about computer security.
- hnlmorg 3mo ago> It's because you (like me) aren't quite as paranoid as security people are. I work heavily with security-conscious clients where vulnerabilities would be catastrophic. And we are talking high profile clients that are juicy target for attacks. My experience is still that the vast majority of vulnerabilities are accidental rather than due to malice. And when I say “vast”, I mean the so heavily slanted in favour of “unintended” that it’s not even comparable. > It's really a matter of context. Security people tend to only be involved when things are already nefarious I’m guessing you’ve not worked with many “security people”? You’d be surprised how much of their day-to-day is mundane.
- UweSchmidt 3mo agoMaybe it's time to take a closer look at reality and correct this meme, which might casually blur the issue and deflect responsibility? Looking at the IT security landscape we see every layer, every product category if not every product itself riddled with issues at one point or another. At the same time the incentives to put those security issues in are huge, and we know attackers work systematic, creative and persistent to introduce those weak points. Security is hard and many bugs certainly happen due to mistakes, but I wouldn't assume that all of those security mishaps stem from an endless series of blunders from "stupid" programmers. So I would go with “Never attribute to ignorance that which is adequately explained by malice.”
- hnlmorg 3mo ago> I wouldn't assume that all of those security mishaps stem from an endless series of blunders from "stupid" programmers. The saying doesn’t mean that all vulnerabilities are blunders. It means we shouldn’t automatically assume vulnerabilities are nefarious. If closer inspection proves beyond reasonable doubt that it was placed there deliberately and maliciously then that’s different. But the point is most vulnerabilities are blunders so it’s better to assume that until proven otherwise.
- UweSchmidt 3mo agoIt's usually not possible to prove that something was put in deliberately and maliciously, so that puts the bar very high. We know it for sure in some of the supply chain attacks, and should assume that other kinds of bugs are being introduced by malicious actors across the board, rather than to risk downplaying the issues to "just blunders".
- hnlmorg 3mo agoIt’s actually quite easy in most cases: 1. You can generally get a feel for the intent by the developers reputation. 2. Look at the code that changed as part of the same commits. Eg was the vulnerable code included as part of the same commits as an unrelated change elsewhere in the codebase? If the latter then that’s hugely suspicious. 3. How is that vulnerability encoded? Eg is a bug parsing logic that was discovered via fuzzing? Or is it obfuscated code? Clearly the latter demonstrates intent. 4. What’s the nature of the vulnerability? Is it simply a dumb unhandled bounds or allocation error in C? Or is there an entire path of code that opens network ports? The latter also demonstrates intent. 5. How did the authors behind the vulnerable code react to the big report? Did they rush a patch out? Write more robust tests? Work with the community? Was there any transparency? Or was the issue quietly brushed over? This is least reliable indicator but it does demonstrate trustworthiness. With these and other indicators you can build a body of evidence that can make an argument for or against a particular vulnerability being malicious. And while I do agree that in some cases it isn’t going to be clear cut, in most cases the evidence, or lack of, will be enough to justify an opinion. The key part of my earlier statement being “beyond reasonable doubt”. Ie I’m not talking about a mathematical proof here.
- jchw 3mo agoThe main reason I assumed you didn't is because you linked to Hanlon's Razor and explained it in a way that made it seem like you didn't think the other person knew. I think it's true to some extent that a lot of the backdoors really are just stupidity, like debugging tools put into prod for convenience. Rather than suggesting that it is genuine malice, maybe the right thing to say is that for security, it doesn't matter whether or not it is malice for most purposes. If it did, it would give more incentive to do as much as possible to disguise malicious backdoors as mistakes.
- psychoslave 3mo agoLooks like this time you interpreted the message in a malicious way.
- hnlmorg 3mo agoHow? Neither their comment nor mine have anything malicious in their tone nor content.
- psychoslave 3mo agoUnfortunately, explaining a joke won’t make it funny afterward I guess.
- hnlmorg 3mo agoAs someone who really doesn’t take themselves even the slightest bit seriously, if there was ever a chance that your comment was funny then I would have realised it was a joke. ;)
- deleted 3mo ago[deleted]
- torginus 3mo agoDunno, if I were to backdoor a piece of my code, I would definitely put in an exploit instead of a deliberate bypass. Plausible deniability is important. A lot of the stuff I worked on already had glaring issues like that without me having to add it..
- thibaut_barrere 3mo agoThat backdoor is so up front about it. We might as well call it a frontdoor.
- Wololooo 3mo agoI mean, it's 99% sure this was supposed to be a debug feature...
- rootatixww3 3mo agoand "accidentally" they forgot to disable it when releasing
- Wololooo 3mo agoWouldn't be the first nor the last time someone is asked to ship something and it gets rushed through for reasons XYZ... This being said makes the situation for an attacker awfully convenient...
- amarant 3mo agoBelieve it or not, shit happens in the software business. I know this from personal experience.
- rasz 3mo agoEnemy of the state: - What did you think was going on? Jack Black: Oh, I thought it was an STO. - STO? Jack Black: Standard Training Op.
- torginus 3mo agoI have done this accidentally at least once - we shipped a full-stack app, and telemetry started lighting up that on certain older phones and browsers (no points for guessing which brand and browser), the release version didn't load. The minifier did something in the release build that it didn't like. So after a quick test, it was decided to deploy the debug version of just the frontend as a bandaid. Next day we saw we managed to deploy the debug version of the backend with admin stuff like this as well..
- BloondAndDoom 3mo agoAt that point it’s not even a back door it’s just stupid default root password kind of design which used to be standard in this kind of hardware. Backdoor would at least try to be subtle :)
- Asraelite 3mo agoBackdoors are often (almost always?) designed to look like incompetence so that there's plausible deniability.
- ktm5j 3mo agoThat sounds like a fun thing to wonder about, but how could anyone possibly know that for sure?
- eth0up 3mo ago[flagged]
- gunapologist99 3mo agoThat's what makes it plausible deniability.
- eth0up 3mo agoIt's refreshing to see someone around here addressing the compulsively overlooked elephant in the room; plausible deniability. I am not implying it applies directly here, but notice the trend -- it's taboo to even speculate on and often gets rebuke for even hinting at it. The social convention around it is perfect cover. And I am not the only one that knows this. If we were to wake suddenly and realize the scale of relevance here, we'd probably all go full luddite. Call me paranoid though.
- Grombobulous 3mo agoIf this wasn’t Tenda maybe I would be more inclined to agree with you. We are talking about an extremely shitty bargain basement vendor. The three stars on Amazon kind of router company. I think sufficiently explained by incompetence over malice applies here. Some nefarious three letter agency having a backdoor like this is pretty pointless anyway. Unless you’ve enabled remote management you can’t even get to this backdoor from a physical network perspective. And then you change some router settings which really aren’t a magical access point into your devices in your home. My PC isn’t just going to magically allow you to browse the file system just because a malicious actor got on my local network. They can’t intercept anything moving over TLS. Not saying it’s good to have that kind of access, but I think at the scale of “typical home network of consumer devices” the utility and blast radius is pretty limited. Go ahead and launch a DDOS attack on my printer and use up my ink cartridges, I guess.
- LargoLasskhyfv 3mo agoSomehow this reads like German to me. Because "rz" is a common abbreviation of RechenZentrum, meaning DataCenter. So in English it would be like "dcadmin". Maybe they outsourced it to someone doing "gute Deutsche Wertarbeit", or it's a leftover from some agency having had their fun, or smoke&mirrors from whomever for whichever reasons.
- petee 3mo agoNearly 4 years from last notification and the password is the same; either thats real incompetence, or a hilarious power move