NUUO 3.0.8 strong_user.php Backdoor Remote Shell Access

Discussion in 'News Aggregator' started by Packet Storm, 7 Aug 2016.

  1. Packet Storm

    Packet Storm Guest

    NUUO NVRmini, NVRmini2, Crystal and NVRSolo devices have a hidden PHP script that when called, a backdoor user is created with poweruser privileges that is able to read and write files on the affected device. The backdoor user 'bbb' when created with the password '111111' by visiting 'strong_user.php' script is able to initiate a secure shell session and further steal and/or destroy sensitive information.

    Continue reading...
     

Share This Page

Loading...