Slashdot Mirror


Cisco Products Have Backdoors

Cbs228 writes "A Cisco Security Advisory released yesterday admits that "A default username/password pair is present in all releases of the Wireless LAN Solution Engine (WLSE) and Hosting Solution Engine (HSE) software. A user who logs in using this username has complete control of the device. This username cannot be disabled." Can we really trust closed-source vendors, such as Cisco, to develop secure products that are free of backdoors?"

31 of 555 comments (clear)

  1. And the username/password pair is... by momerath2003 · · Score: 5, Funny

    admin/password.

    --
    I had but a simple dream, to destroy all humans.
    1. Re:And the username/password pair is... by orrigami · · Score: 5, Funny

      That is my root password.

    2. Re:And the username/password pair is... by mitchell_pgh · · Score: 2, Funny

      Sorry, the real password is...

      1... 2... 3... 4... 5... 6...

    3. Re:And the username/password pair is... by MacOS_Rules · · Score: 5, Funny

      I found it! The little bugger is at 127.0.0.1, and confirmed, the l/p work! OMG, tons of pr0n! ;)

      --
      If a man's character is to be abused there's nobody like a relative to do the business. -Thackeray, William
    4. Re:And the username/password pair is... by okvol · · Score: 2, Funny

      My favorite password is ******

      --
      cabg x3 is a life changing event...
    5. Re:And the username/password pair is... by swordboy · · Score: 2, Funny

      That's the same login that I use on my luggage!

      --

      Life is the leading cause of death in America.
    6. Re:And the username/password pair is... by orthogonal · · Score: 5, Funny
      My favorite password is ******

      I quote from bash.org:
      #244321 +(2664)- [X]

      <Cthon98> hey, if you type in your pw, it will show as stars
      <Cthon98> ********* see!
      <AzureDiamond> hunter2
      <AzureDiamond> doesnt look like stars to me
      <Cthon98> <AzureDiamond> *******
      <Cthon98> thats what I see
      <AzureDiamond> oh, really?
      <Cthon98> Absolutely
      <AzureDiamond> you can go hunter2 my hunter2-ing hunter2
      <AzureDiamond> haha, does that look funny to you?
      <Cthon98> lol, yes. See, when YOU type hunter2, it shows to us as *******
      <AzureDiamond> thats neat, I didnt know IRC did that
      <Cthon98> yep, no matter how many times you type hunter2, it will show to us as *******
      <AzureDiamond> awesome!
      <AzureDiamond> wait, how do you know my pw?
      <Cthon98> er, I just copy pasted YOUR ******'s and it appears to YOU as hunter2 cause its your pw
      <AzureDiamond> oh, ok.
    7. Re:And the username/password pair is... by Anonymous Coward · · Score: 5, Funny

      >I found it! The little bugger is at 127.0.0.1, and confirmed, the l/p work! OMG, tons of pr0n! ;)

      No pr0n when I connect there, but I'll be damned, THAT BUGGER HAS A COPY OF ALL MY FILES!

    8. Re:And the username/password pair is... by RussDavisDotCom · · Score: 5, Funny

      Correction: That WAS your root password.

      --
      My favorite phrase: You have 5 Moderator Points! Use 'em or lose 'em!
    9. Re:And the username/password pair is... by Anonymous Coward · · Score: 1, Funny

      I tried that too, but all of the porn I saw, I have seen already...

    10. Re:And the username/password pair is... by Anonymous Coward · · Score: 3, Funny

      Delete them all from his drive! Quick!

  2. Your giving away all our secrets! by General+Newcomb · · Score: 5, Funny

    "Mr. Potato Head! Back doors are not secrets!"

  3. Your answer by ls-lta · · Score: 4, Funny

    " Can we really trust closed-source venders, such as Cisco, to develop secure products that are free of backdoors?"

    Yes. Lord, next you'll be asking about patents.

  4. And that username/password is by Neil+Blender · · Score: 2, Funny

    3COMengineers/Areweenies

  5. USER/PASS by Allen+Zadr · · Score: 4, Funny
    Don't some of us have some serious hacking to do? I guess I know what you are planning on doing this weekend.

    What do you bet the id set is joshua/pencil?

    --
    Kinetic stupidity has a new brand leader: Allen Zadr.
  6. Re:No Refund - firmware fix by thpdg · · Score: 5, Funny

    Can't Cisco just download it to the devices themselves? They do have the password to every box, after all.

    --

    -Patrick

    "They never stop thinking about new ways to harm our country and our people, and neither do we."

  7. and when you log in, you get... by funny-jack · · Score: 4, Funny

    Greetings, Professor Falken.
    Shall we play a game?

    --
    You probably shouldn't click this.
  8. Re:Cisco's Life Lesson - Maybe not. by Anonymous Coward · · Score: 5, Funny


    Cisco has an evil backdoor that works (initially) at the ethernet level. You send several specially crafted frames to a MAC on the local segment or special packets to the outside interface and the unit will open up a back connection to Cisco. The PIX and ACLs in their router products will not log these or otherwise alert you to their existence. Once the connection is made, Cisco can mirror selected bits of your LAN traffic. Being that most of the internet's traffic flows over Cisco products...

    Some history:
    In 1928 an American inventor (Henry P. Acket) was working on a method to send extremely low voltage electrical impulses over wires as a covert means of communications. He succeeded in that he was able to use the telephone companies' wires to speak to friends without paying a telephone tax. Early on, his friend Charles Isco was able to put a backdoor in the vacuum tubes with nothing more than a few drops of solder, some tin and flux. Charles showed Acket this and provided some wax cylinders of Acket's supposedly private conversation.

    The FBI heard of this and took all their patent-pending information. Acket and Isco were paid the then huge sums of $1M and $500K respectively to shut up.

    Fast forward to the 60's.
    Early in 1963, J. Edgar Hoover was perusing the FBI archives when he spotted these plans from 35 years prior. He didn't believe it but one of his technical people played Hoover a tape recording made with a successor of the equipment. The tape was of Hoover making dinner reservations at Le Grande Fiste, a homosexual dinner club. Hoover went through the roof. He destroyed all the paperwork and equipment. After months of extreme drug therapy which rendered the technician nearly incoherent, Hoover had him framed for a crime we are all familiar with. The technician's name? Lee Harvey Oswald.

    Ahh.. the technology survived
    In the 1980s some people from Stanford University were going through recordings of Oswalds. Playing them backwards they could hear the terms "Black Helicopters", "Area 51" and "Backdoor Device". The truly learned already know about black helicopters and Area 51.. but what was this "Backdoor Device" Oswalds was rambling about? Those investigators, Len Bosack and Sandy Lerner, went on to form Cisco.

    If you look inside any Cisco product you'll find a small vacuum tube with hacked in piece of tin, some solder and flux.

    I present this information at grave risk to myself.

  9. Re:Can we really trust closed-source vendors? by ReallyNiceGuy · · Score: 2, Funny

    Happy Easter! This is not a backdoor, this is an easter egg...

  10. Re:Cisco's Life Lesson - Maybe not. by strictnein · · Score: 4, Funny

    Holy f@ck I'm an idiot.

    I got to this point:

    The technician's name? Lee Harvey Oswald.

    Before realizing something was wrong with this post.

  11. Taliban Master-Plan to Destroy America by Progman3K · · Score: 4, Funny

    >Just like we can't trust closed-source e-voting software [when] it comes to our republic (the U.S.:), we can't trust close-source vendors whose systems power our infrastructure...that, without, the world would cease to function as it does today.

    Taliban leader speaking:

    OK troops, here's what we'll do; we will sub-contract from the Pakistanis that are sub-contracting from the Indians that are sub-contracting from the Americans that are outsourcing their I.T. operations, and when WE are the ones coding everything for the Americans, we slip in trojans, viruses and everything else we can think of to screw with their heads!

    Once they are all helpless because they've outsourced all the jobs that require an education, we show up and sell them all Edsel automobiles and when they've all killed themselves on the road, we simply take over the country.

    Simple.

    --
    I don't know the meaning of the word 'don't' - J
  12. I must be a slow reader.. by Altrag · · Score: 2, Funny

    I only made it to (Score:3, Funny) before I decided it was likely bogus...

  13. Re:Cisco's Life Lesson - Maybe not. by Anonymous Coward · · Score: 3, Funny
    I highly doubt that they will be embarassed enough to have learned a powerful life-lesson.

    Cisco doesn't make mistakes, they define new industry de-facto standards. Expect Juniper to issue a press-release shortly about some of their products having a backdoor as well. They're always followers.

  14. Re:Cisco's Life Lesson - Maybe not. by txviking · · Score: 2, Funny

    That fix, be-it an actual removal of the userid/password, or a paranoid password change, is just as installable, either way.

    no. it just changes the user/password pair to another one, only know to Cisco until somebody hacks it.... ;-)

  15. Re:Cisco is not alone. It's industry wide practice by Anonymous Coward · · Score: 1, Funny

    :level 3 tech casts silver modem at level 2 bug.

    :level 2 bug takes damage.

  16. Re:Well, that depends. by re-Verse · · Score: 3, Funny

    Whoever modded this offtopic has the sense of humour of a brick.

    See, what he is explaining is that due to Ciscos inherent stupidity at adding an override all password, their track record, that was once the shit, is now just shit. Get it???

  17. Re:Cisco's Life Lesson - Maybe not. by scubacuda · · Score: 2, Funny
    Funny, I was thinking the same thing.

    Too much Art Bell, I guess....

  18. Re:Cisco's Life Lesson - Maybe not. by mcowger · · Score: 2, Funny

    Wow...You missed Henry P. Acket??? Henry Packet.....

  19. Re:Cisco's Life Lesson - Maybe not. by drinkypoo · · Score: 3, Funny

    Wally: You are the wind beneath my wings.
    Dilbert: Next week I'll tell him the packet must be lost in the "ether" net.

    A.C., I could fly higher than an eagle...

    --
    "You're right," Fisheye says. "I should have set it on 'whip' or 'chop.'"
  20. Re:Cisco's Life Lesson - Maybe not. by elecbrick · · Score: 2, Funny
    It must be a bad day. I got to

    If you look inside any Cisco product you'll find a small vacuum tube

    before cluing in that I have not see a vacuum tube in years.

  21. Re:true dat? by 0x0d0a · · Score: 2, Funny

    I'd be impressed if you were posting to Slashdot from a Cisco router...