Live data from Hacker News

Tenda firmware (multiple versions) contains hidden authentication backdoor

kb.cert.org

81–90 of 136 posts

Re: Tenda firmware (multiple versions) contains hidden authentication backdoor

#81
post #5

> Tenda is a supplier of home and business network devices such as routers, switches, wireless access points, and video surveillance equipment. I was unfamiliar with Tenda. > Shenzhen Tenda Technology Co.,Ltd. ( https://www.tendacn.com/us/profile ) Tenda may just rebrand, right? It seems like many chinese brands will either rebrand or have a 'competing' brand with the same internals but different externals. (I have n…

There's claims of it being "the first home-grown router and wireless network device manufacturer in China".

Re: Tenda firmware (multiple versions) contains hidden authentication backdoor

#82

Oh this is amazing! I have a few of their cube routers sitting around and I always hated how app-locked their firmware was when it really is just a wifi repeater with a few extras (mesh) on top. Root access will do wonders to bypassing the app now (and also disabling their ping-for-green-light mechanism which spams the network with a constant dns resolution to microsoft.com lol). Also honest take this looks less like…

why would a consumer device need a randomized password?

Re: Tenda firmware (multiple versions) contains hidden authentication backdoor

#84

Oh this is amazing! I have a few of their cube routers sitting around and I always hated how app-locked their firmware was when it really is just a wifi repeater with a few extras (mesh) on top. Root access will do wonders to bypassing the app now (and also disabling their ping-for-green-light mechanism which spams the network with a constant dns resolution to microsoft.com lol). Also honest take this looks less like…

Yes, it is randomized but due to a quirk in the universal probability waveform it always randomizes to 'rzadmin'. Scientists are baffled.

Re: Tenda firmware (multiple versions) contains hidden authentication backdoor

#86
post #47
post #25

My ifconfig is simple: if it's made in Shenzhen, throw it out

I bet more than half of components in all your electronics are made in Shenzhen

And that's something very different than a complete product designed from scratch by a Chinese team in Shenzhen.

Re: Tenda firmware (multiple versions) contains hidden authentication backdoor

#87
post #53

The consistency with which networking hardware companies produce such garbage is crazy. And it’s always amateur hour backdoors somehow. If it was something sophisticated they might get a pass on „ok some security agency made them do it probably“

They didn't produce garbage by accident. They followed a plan and made a decision.

Re: Tenda firmware (multiple versions) contains hidden authentication backdoor

#89

Earlier quoted context omitted.

I mean, it's 99% sure this was supposed to be a debug feature...

and "accidentally" they forgot to disable it when releasing

Wouldn't be the first nor the last time someone is asked to ship something and it gets rushed through for reasons XYZ...

This being said makes the situation for an attacker awfully convenient...

Re: Tenda firmware (multiple versions) contains hidden authentication backdoor

#90

Earlier quoted context omitted.

That backdoor is so up front about it. We might as well call it a frontdoor.

I mean, it's 99% sure this was supposed to be a debug feature...

Enemy of the state:

- What did you think was going on?

Jack Black: Oh, I thought it was an STO.

- STO?

Jack Black: Standard Training Op.

Post reply on HN