The US/Israel would never do such a thing, buy UniFi/Fortinet/Palo Alto!
Tenda firmware (multiple versions) contains hidden authentication backdoor
31–40 of 136 posts
Re: Tenda firmware (multiple versions) contains hidden authentication backdoor
#32The article doesn't disclose the value of "sys.rzadmin.password", but this writeup from 2022 does: https://boschko.ca/tenda_ac1200_router/ Spoiler: it's "rzadmin". And it looks like there are a bunch of other goodies in the firmware, too.
Re: Tenda firmware (multiple versions) contains hidden authentication backdoor
#33Earlier quoted context omitted.
I’m working on a hotel right now. And I’ve gone to great lengths to make the wifi more secure. Everyone on their own VLAN. Separate PPSK for each room. Credentials are randomly generated and not some ridiculous pattern of last name and room number or similar. We built our own custom access control system, with what at the time was the strongest keycards we could find (mifare desfire ev3), I’m really trying to make a…
How do you distribute credentials to residents? My Macbook is permanently locked out of Cox's hotspot system (used in some U.S. hotels) because the password was given to me on a tiny label which I couldn't read as a blind person except through OCR, and the OCR was wrong a few too many times.
Re: Tenda firmware (multiple versions) contains hidden authentication backdoor
#34My ifconfig is simple: if it's made in Shenzhen, throw it out
Re: Tenda firmware (multiple versions) contains hidden authentication backdoor
#35Re: Tenda firmware (multiple versions) contains hidden authentication backdoor
#36> Tenda is a supplier of home and business network devices such as routers, switches, wireless access points, and video surveillance equipment. I was unfamiliar with Tenda. > Shenzhen Tenda Technology Co.,Ltd. ( https://www.tendacn.com/us/profile ) Tenda may just rebrand, right? It seems like many chinese brands will either rebrand or have a 'competing' brand with the same internals but different externals. (I have n…
I have a small Tenda 5-port gigabit dumb switch. It uses the same switch chip as this TP-Link, just with different branding; even the "SG105" model number is the same:
https://goughlui.com/2022/02/27/unbox-teardown-tp-link-tl-sg...
Re: Tenda firmware (multiple versions) contains hidden authentication backdoor
#37Earlier quoted context omitted.
How do you distribute credentials to residents? My Macbook is permanently locked out of Cox's hotspot system (used in some U.S. hotels) because the password was given to me on a tiny label which I couldn't read as a blind person except through OCR, and the OCR was wrong a few too many times.
Do macs not spoof their macid (heh) everytime they join a network? I thought android (and windows?) did that already?
Re: Tenda firmware (multiple versions) contains hidden authentication backdoor
#38> Tenda is a supplier of home and business network devices such as routers, switches, wireless access points, and video surveillance equipment. I was unfamiliar with Tenda. > Shenzhen Tenda Technology Co.,Ltd. ( https://www.tendacn.com/us/profile ) Tenda may just rebrand, right? It seems like many chinese brands will either rebrand or have a 'competing' brand with the same internals but different externals. (I have n…
I have an ethernet over power adapter somewhere in a cupboard from perhaps 10 years ago.
Back then it was standard for the admin password to be 'admin'. They'd often even print it on the device itself.
Re: Tenda firmware (multiple versions) contains hidden authentication backdoor
#39The article doesn't disclose the value of "sys.rzadmin.password", but this writeup from 2022 does: https://boschko.ca/tenda_ac1200_router/ Spoiler: it's "rzadmin". And it looks like there are a bunch of other goodies in the firmware, too.
Sounds like a convenience feature for a dev that they forgot to remove before distribution, since it's this poorly hidden.