ParityNews.com: ...Because Technology Matters

Switch to desktop Register Login

Researcher Details Samsung SNMP Backdoor Flaw

Earlier today we reported about a flaw in Samsung printers that would enable attackers to remotely control the vulnerable device and carry out attacks on the network after a vulnerability note was published on US-CERT.

Neil Smith, the researcher who reported his discovery to US-CERT has since then detailed of the Samsung SNMP backdoor on this Tumblr post. Smith tweeted today that working with Samsung was a frustrating experience and that because US-CERT published it, he went ahead with the disclosure.

 

In his post Smith has coded few starting bits of what he calls the NetWorkManager.class and has put down a custom MIB file that other security enthusiasts [read hackers] could use to further their research. One startling thing that Smith notes is that the community string has been found in firmware that was used way back in 2004. “Also, that community string has been found in firmware dating back to 2004,” notes Smith.

US-CERT has warned that users to follow good security practice and that they should only allow connections from trusted hosts. “As a general good security practice, only allow connections from trusted hosts and networks”, notes US-CERT in the vulnerability note. Printers from Dell that are manufactured by Samsung are also vulnerable.

Parity Media Private Limited. All rights reserved. 2013

Top Desktop version