HP admits to backdoors in storage products
theregister.co.uk
theregister.co.uk
2. Username: hpsupport
3. Password (from SHA1 lookup): badg3r5
Yes that shit.
We have some of this kit in and I've tested it and it works absolutely spot on. Fortunately it's all firewalled off but it's not the sort of crap you want on your doorstep.
Nothing to do with the NSA this - just a crappy decision somewhere which is designed to make HP support's life easier. As someone else said: this bug is as old as time.
uname -a
cat /proc/cpuinfo
cat /proc/meminfo
cat /etc/passwd
If I can get a firmware image I'll take a look early next week and do an analysis follow-up.
~sigh~
That said, it's still a backdoor, whether it was left there intentionally or not. I'd have a hard time trusting HP products after this.
Which, cynically, could easily be read as "with the storage device on a network, and with a company policy requiring support staff to request permission before using it".
Maybe these things aren't _intended_ to be directly internet connected - but there's a _lot_ of gear that ebds up that way without ever having been designed too. Even HP admit: "This vulnerability could be remotely exploited to gain unauthorized access to the device."
And from the end of the article - it seems at most: "And, of course, there's the "reset factory defaults" option, which would nuke all a user's data." - still not a "backdoor", but somewhat worse than just "a reboot".