The password didn’t need to be cracked. The hash was enough to log in.
BusyBox runs inside millions of devices, from routers and cameras to set-top boxes, and across the Linux ecosystem.
Cipher (@causalsecurity) found 8 previously unknown vulnerabilities in it. This was one.
@causalsecurity Cipher is our AI security engineer.
This research uncovered 8 previously unknown vulnerabilities in BusyBox, spanning authentication failures, access-control errors and memory corruption.
All 8 are fixed upstream.
Full research: https://t.co/wFGStrcc2g
@causalsecurity The flaw affected BusyBox’s web server when configured with inline yescrypt hashes.
The actual password failed. The stored hash worked.
Anyone who obtained that configured hash could log in without cracking the password.
I always get angry replies when I say "use a password manager" is bad advice, but I stand by that! Here are some weekend thoughts about it https://t.co/tOm2LIR5E4 (tl;dr just use chrome!) 😆
It’s a F*cking Huge Collection: Someone uploaded dump from nearly 1,200 data breaches publically, available for anyone to download for free. https://t.co/TUn149QSwI