Over 60% of domestic electronic display billboards have vulnerabilities

Source: Internet
Author: User

Over 60% of domestic electronic display billboards have vulnerabilities

Vulnerabilities in over 60% of electronic billboard Control Software in China
Attackers or hackers can remotely control the large screen. Undermine social harmony and threaten public security until it reaches national security!

Name: xingyu large screen authorization bypass

Exception or Problem description: the user name and password are not stored in an encrypted location. This kind of measure prevents unauthorized local logins. Attackers or malicious users can obtain the username and password to perform network attacks.

Hit scope: more than half of the Large Screen

Exception solution: official patch

Exception verification test record: Pass

Verify attack code: complete code (or no code required)

Attack path: Local attack

Complexity: high

Authentication: Required

Confidentiality: complete

Integrity: complete

Name: the large screen account of Ling xingyu can be remotely Enumerated

Exception or Problem description: The user authentication system is not strictly controlled and the password can be guessed remotely.

Hit scope: more than half of the Large Screen

Exception solution: official patch

Exception verification test record: Pass

Verify attack code: complete code (or no code required)

Attack path: remote attack

Complexity: Medium

Authentication: Required

Confidentiality: complete

Integrity: complete

Availability: completely



This system has a market share of more than 60% and is almost monopolized in many regions. Its Control Software has vulnerabilities and may leak user authentication information locally. This information can be remotely exploited. The control shows that the screen is like a mobile phone. If it is used by several hostile forces, even national security!

Due to technical restrictions on the remote access to this authentication information, the local database can be 100% successfully. Therefore, the RANK value is reduced to 18. the user name and password are used to defend against illegal local operations on the large screen. However, the password is basically the same as that in this example. The password is not encrypted for storage, and the storage location is actually the Registry (Dahan ). A very simple system is widely used. In addition, after attackers obtain information about a local account, attackers can control the server as if they were on their own computers. In addition, remote brute-force cracking still exists. The addresses that fail authentication are not effectively recorded and blocked, the account may be cracked remotely .,

Because the system is really simple and has many problems, it is no longer a problem of columns. We hope that the manufacturers can take the mass line and accept suggestions from the masses to self-check, correct, and check as many vulnerabilities as possible.

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

 

Solution:

Encrypted storage of user information
 

Contact Us

The content source of this page is from Internet, which doesn't represent Alibaba Cloud's opinion; products and services mentioned on that page don't have any relationship with Alibaba Cloud. If the content of the page makes you feel confusing, please write us an email, we will handle the problem within 5 days after receiving your email.

If you find any instances of plagiarism from the community, please send an email to: info-contact@alibabacloud.com and provide relevant evidence. A staff member will contact you within 5 working days.

A Free Trial That Lets You Build Big!

Start building with 50+ products and up to 12 months usage for Elastic Compute Service

  • Sales Support

    1 on 1 presale consultation

  • After-Sales Support

    24/7 Technical Support 6 Free Tickets per Quarter Faster Response

  • Alibaba Cloud offers highly flexible support services tailored to meet your exact needs.