A backdoor giving root access has lurked for years in popular KiwiSDR
arstechnica.com
arstechnica.com
It hints at somebody who has never worked in a modern dev agency. Fair enough, I don't mean that as an insult. But, definitely old-school style. Like someone learned to code in a time before the age of internet hacking.” A great comment in the article
The code in question was removed yesterday [1] with the commit message "v1.461: bug fixes". The password sha256 hash was df05611250593c4299da8b3216751552b5a690e44b7e1b63f419e64b5e14ed9c.
There's been at least 5 different values, though some are short-lived:
* First added Jul 6, 2017 [2] commit message "for cases when src ip address is not preserved" and hash cc9b1457655eecfcb5f1beb6986bb9d27adfca2377ed32a4120014852fa415e6
* Changed later that day [3] with commit message "proper way to cleanup" to hash 7cdd62b9f85bb7a8f9d85595c4e488d8090c435cf71f8dd41ff7177ea6735189
* Nov 6, 2017 [4] commit message "first cut at GPS_ONLY_BUILD support" added a second hash: 974706effe52b397714f8ee22bf137e7cbfb46f3e88c7972defa3bbc55883048
* ..which was then removed on Nov 7, 2017 [5] with commit message "remove admin console bypass hack"
* Changed Oct 24, 2018 [6] with commit message "v1.243: security improvements" to hash 34ac320e522bdd9c8e5f8b9e5aa264e732473b0621a8b899ddf2c708d80b442c
* Changed Feb 13, 2020 [7] with commit message "lint" to hash df05611250593c4299da8b3216751552b5a690e44b7e1b63f419e64b5e14ed9c
[1]: https://github.com/jks-prv/Beagle_SDR_GPS/commit/fef90929ed8...
[2] https://github.com/jks-prv/Beagle_SDR_GPS/commit/6bdde32e603...
[3] https://github.com/jks-prv/Beagle_SDR_GPS/commit/c0178bd2206...
[4] https://github.com/jks-prv/Beagle_SDR_GPS/commit/d6ea8061c8f...
[5] https://github.com/jks-prv/Beagle_SDR_GPS/commit/e66e67a20bc...
[6] https://github.com/jks-prv/Beagle_SDR_GPS/commit/30024d542f3...
[7] https://github.com/jks-prv/Beagle_SDR_GPS/commit/20b3859bbbc...