TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Secret backdoor found in networking gear perfect for government espionage

4 点作者 kushti大约 6 年前

2 条评论

theamk大约 6 年前
&gt; .. allow an unauthenticated, remote attacker to connect to the affected system with the privileges of the root user.<p>&gt; The vulnerability is due to the presence of a default SSH key pair that is present in all devices.<p>That&#x27;s quite a bug -- I expected to see obscure exploit deep in the networking code which masterfully bypasses all code hardening, but found a default credentials instead. This is the kind of mistake that a random IoT company would do, I would not expect this from Cisco.
java-man大约 6 年前
I don&#x27;t understand how this could happen in 2019. There were multiple people involved who coded, reviewed, tested the code, signed off on the release.<p>The other possible explanation is that it&#x27;s intentional.