Zyxel Backdoor & A Known Plaintext Attack

Опубликовано: 03 Ноябрь 2024
на канале: cybercdh
6,353
255

In this video I discuss a recent finding where an undocumented admin-user account was found in Zyxel security products, accessible over SSH and via the web. As such, I showcase a simple technique called a 'Known Plaintext Attack' which can help enable you to analyse this Zyxel device firmware.

LINKS / BLOGS
============
https://www.zdnet.com/article/backdoo...
https://www.zyxel.com/support/CVE-202...
https://www.eyecontrol.nl/blog/undocu...
https://math.ucr.edu/~mike/zipattacks...
https://portal.myzyxel.com/my/firmwares

TOOLS
======
https://formulae.brew.sh/formula/pkcrack
https://formulae.brew.sh/formula/squa...
https://github.com/cybercdh/hacks/blo...

FOLLOW
======
You can join in the conversation by following me at   / cybercdh  

THANKS
=======
If you LIKED this video, please hit the THUMBS UP. If you LOVED it, please SUBSCRIBE!

Many thanks for watching, it means a lot.

Peace out. ✌️
@cybercdh