Hidden admin user on every HP MSA2000 G3
seclists.org
seclists.org
- A hidden admin account is perfect for debugging and support!
- What if someone guesses the password?
- Nah, who the hell is gonna guess THAT?!There's not a lot of info in that post, and I don't see any other posts in the thread. This is an issue if it can be accessed remotely, but not a big deal if it requires a console cable.
Even if it CAN be accessed remotely, it shouldn't be as big an issue as you'd think. SANs are usually not connected to the Internet and the management ports should be set on separate management VLANs. The number of SAN installs I've seen where the SAN engineer installing it left the passwords at the default and the customer never changed them is mind-boggling, anyway.
Not to take away from the importance of something like this, but it's not as severe as say, a remote-root exploit in Linux.
Doesn't help if someone has physical access to the datacenter, but that's a given.
http://h71016.www7.hp.com/dstore/ctoBases.asp?ProductLineId=...
Google has some good pictures: http://www.google.com/images?q=HP%20MSA%203000
HP's high-end 'ProLiant' kit have "Integrated Lights-out" that will allow you to do things like power cycle the device, drop on to the serial console, etc. All over a user friendly web interface.
I'm assuming this 'admin backdoor' it is for that.
(Though it looks to be a P2000 MSA G3).