Nmap Security Scanner
*Intro
*Ref Guide
*Install Guide
*Download
*Changelog
*Book
*Docs
Security Lists
*Nmap Hackers
*Nmap Dev
*Bugtraq
*Full Disclosure
*Pen Test
*Basics
*More
Security Tools
*Pass crackers
*Sniffers
*Vuln Scanners
*Web scanners
*Wireless
*Exploitation
*Packet crafters
*More
Site News
Site Search:
Exploit World
Advertising
About/Contact
Credits
Sponsors:
edgeos



Full Disclosure: Re: FiWin SS28S WiFi VoIP SIP/Skype Phone Hardcoded Telnet user/pass and debug access

Re: FiWin SS28S WiFi VoIP SIP/Skype Phone Hardcoded Telnet user/pass and debug access

From: Nick FitzGerald <nick_at_virus-l.demon.co.uk>
Date: Sat, 23 Sep 2006 13:22:05 +1200

Paul Schmehl wrote:

> The engineers who designed this should be summarily fired. The terminal
> stupidity of it is mind boggling!

I think _beyond_ mind-boggling.

It's mind-boggling that no-one else involved in the development/
testing noticed EITHER that this "unintended" backdoor existed OR
implementing that design was stupefyingly moronic.

Either way, marginally sentient beings should have prevented this
stupidity making it to production.

That it was not stopped raises a bunch of questions about the fitness
to purpose and other quality issues for all other Fi Win products.
Having now read the review, I see that such concerns clearly already
apply to other design features of the SS28S...

Regards,

Nick FitzGerald

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/
Received on Sep 22 2006

[ Nmap | Sec Tools | Mailing Lists | Site News | About/Contact | Advertising | Privacy ]