Logic vulnerability exists in the safe in the guest room of the binan Hotel. You can change the super administrator password with common permissions.

Source: Internet
Author: User

Logic vulnerability exists in the safe in the guest room of the binan Hotel. You can change the super administrator password with common permissions.

Shanghai binan Industrial Co., Ltd. is located in Shanghai Zhabei District Changan Road No. 1138 Center East China building 20 H, main safe and so on. The company adheres to the business philosophy of "customer first, climb the peak" and adheres to the principle of "honesty and trustworthiness" to provide quality services to our customers.
K-BE100 hotel room safe has logic vulnerability, can be exploited by criminals, its properties are as follows
1. use international ADA buttons, wear resistance 2. portable computer storage 3. large LCD display, battery can be used for one year. master and customer-level password Classification Management 5. configure CEU to forcibly open the box and query switch box records and connect to the computer to print data. You can query and print the most recent 100 ON and OFF Box Information, with a mechanical key to forcibly open the box

The safe operation process allows hackers to change the super administrator password as a guest and then enable the safe after the waiter resets the safe with the key to steal the financial or confidential files of the next tenant.

What do we need a super administrator password that can be modified by a low-privilege user ?!

There is no archive in the manual, and the waiter can check whether the super password has a probability of being modified no more than 50% (who will use the complex password if there is a key ?), Therefore, the probability of successful attacks to steal property secrets is greater than 50% in this safe.

Safe Operation Procedure
 



Hacker (thief) Committing a crime



Video
 

http://**.**.**.**/ptv/vplay/23775203.html#0-qzone-1-30480-d020d2d2a4e8d1a374a433f596ad1440


The key is used to reset the password and the super password. This is reasonable. Otherwise, the service will be rejected.


 

 

 

 

 

 

 

 

 

 

 

 

 

 

http://**.**.**.**/ptv/vplay/23775203.html#0-qzone-1-30480-d020d2d2a4e8d1a374a433f596ad1440

 

Related Article

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.