Skip to main content

For years, a backdoor in popular KiwiSDR product gave root to project developer


Jasper_The_Rasper
Moderator
Forum|alt.badge.img+54

Users are rattled after learning their devices and networks were exposed.

 

DAN GOODIN - 7/15/2021

 

KiwiSDR is hardware that uses a software-defined radio to monitor transmissions in a local area and stream them over the Internet. A largely hobbyist base of users do all kinds of cool things with the playing-card-sized devices. A user in, say, Manhattan can connect one to the Internet so that people in, say, Madrid, Spain, or Sydney, Australia, can listen to AM radio broadcasts, CB radio conversations, or even watch lightning storms in Manhattan.

 

On Wednesday, users learned that for years their devices had been equipped with a backdoor that allowed the KiwiSDR creator—and possibly others—to log in to their devices with administrative system rights. The remote admin could then make configuration changes and access data not just for the KiwiSDR, but in many cases to the Raspberry Pi, BeagleBone Black, or other computing device the SDR hardware is connected to.

 

Full Article.

0 replies

Be the first to reply!

Reply