Re: [FD] Grandstream VoIP phone: SSH key backdoor and multiple vulnerabilities leading to RCE as root (David Jorm

2015-07-13 Thread Jeffrey Walton
> A final issue I've reported to them in the past that's not resolved is the > SSH host key being shared across all phones of the same firmware version. > > The authenticity of host '10.150.117.57 (10.150.117.57)' can't be established. > RSA key fingerprint is 7f:83:e8:5c:0b:fb:d1:47:c7:f1:33:60:b

Re: [FD] Grandstream VoIP phone: SSH key backdoor and multiple vulnerabilities leading to RCE as root (David Jorm

2015-07-11 Thread Seamus Caveney
There is another similar issue affecting GXP color phones (GXP2130, 2140, 2160) reported to Grandstream that was fixed in 1.0.4.22. From the main shell there is a bluetooth test mode you can enter by typing 'bttest'. From inside this subshell there is no shell sanitization and you can escape usi