Showing posts with label hp. Show all posts
Showing posts with label hp. Show all posts

New backdoor in HP server products

Computer manufacturer HP has admitted that its StoreVirtual servers also contain an undocumented backdoor. The security vulnerability risks allowing attackers to gain unauthorised access to the storage systems. The backdoor provides users with direct access to the holy of holies, "LeftHand" (the operating system for the StoreVirtual server). HP has previously marketed its StoreVirtual systems as LeftHand Storage and P4000 SAN. LeftHand OS was originally called SAN/iQ.

http://www.h-online.com/security/news/item/New-backdoor-in-HP-server-products-1916506.html
New backdoor in HP server products
In a security advisory, HP stresses that, although the backdoor provides root access to the server, it does not provide access to the user data stored on the server system. HP is planning to provide a patch to permanently deactivate the backdoor by 17 July.




HP D2D/StoreOnce Storage unit backdoors

HP D2D Storage unit backdoor
HP D2D Storage unit
HP was exposed back in 2010 with a horrendously embarassing backdoor in their SAN technologies. I'm not sure where someone in management had that "oh shit" moment, but the seem to have forgotten it quickly by implementing the same exact problem in their D2D hardware.
In this case, we're pretty much talking about history repeating, with noone at HP being any the wiser. The difference is, this time, nothing is public (yet), so HP are working on their "close your eyes and it might go away" approach.