http://www.anticode.com for the latest exploits, tools and documents! Default password in Bay Networks switches. Jan B. Koum (jkb@BEST.COM) Wed, 10 Mar 1999 14:48:58 -0800 Ok.. so you would think after 3Com $%#& up last year of inserting default password into firmware vendors would learn their lesson? Hah! Welcome to the world of strings and Bay Networks firmware files. I have looked at some bay networks switches and see that the following have default password of "NetICs" BayStack 350T HW:RevC FW:V1.01 SW:V1.2.0.10 BayStack 350T HW:RevC FW:V1.01 SW:V2.0.0.15 Also works on: BayStack 350T-HD HW:RevA FW:V1.03 SW:V2.0.2.1 (24 port) BayStack 350T HW:RevC FW:V1.00 SW:V2.0.2.1 (16 port) Does not work on: BayStack 450-24T HW:RevB FW:V1.04 SW:V1.0.1.0 These however I was not able to find defaults for: BayStack 350-24T HW:RevA FW:V1.04 SW:V1.0.0.2 Bay Networks BayStack 303 Ethernet Switch BayStack 28115/ADV Fast Ethernet Switch If you have firmware images for the above, just % strings *.img | grep -B5 "Invalid Password" Something similar to this command might give you the passwd. Of course I don't have to tell you about how bad it is when someone can control your network infrastructure (switches). I don't have much experience with Bay hardware (in fact, I have none - someone at work just asked me to help them get into a switch for which they forgot the password). If someone can shed some light on this topic, it would be great. And yes, I consider this to be a backdoor - wouldn't you call it a backdoor if Solaris had default password for root logins? How can vendors in 1999 even THINK about something as stupid as inserting a default password like this into a switch!?!? Granted - I am almost sure Bay didn't have evil intentions for the use .. but still. I am speechless. -- Yan P.S. - Greetz to the inhabitants of #!adm and #!w00w00