Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

Lenovo used '12345678' as filesharing tool password
iTnews ^ | Jan 27 2016 11:59AM (AUS) | Juha Saarinen

Posted on 01/26/2016 7:56:56 PM PST by Utilizer

A filesharing utility for Android devices and Windows computers shipped by hardware vendor Lenovo has been found by security researchers to contain multiple, easily exploitable vulnerabilities

CoreSecurity discovered that the free Lenovo SHAREit tool for Windows creates a wi-fi hotspot with the password 12345678, allowing anyone to connect to the system running SHAREit.

On Android devices, SHAREit sets up an open wi-fi hotspot without any password at all, in order to receive files. This could allow attackers to connect to the Android device without authentication and capture information transferred, CoreSecurity said.

The researchers also noted that files were transferred using plain-text hyper text transport protocol (HTTP) with no encryption; this could allow attackers to intercept and modify data in man-in-the-middle scenarios on the same network.

It was also possible to browse - but not download - the file systems on Windows computers with SHAREit active, using a simple request to a webserver and by connecting with the default 12345678 password.

Core Security alerted Lenovo to the vulnerabilities in SHAREit on October 29 last year. Lenovo issued patched versions of SHAREit yesterday.

(Excerpt) Read more at itnews.com.au ...


TOPICS: Business/Economy; Computers/Internet
KEYWORDS: filesharing; lenovo; passwords; security; software
You would think people would have leaned by now. *sigh*

Links to a bit more info at site.

1 posted on 01/26/2016 7:56:56 PM PST by Utilizer
[ Post Reply | Private Reply | View Replies]

To: Utilizer

Computer made in China. Should we expect it *not* to spy in some manner?


2 posted on 01/26/2016 7:59:32 PM PST by Fester Chugabrew (Diversity is Hillary Clinton and Barack Obama sharing the same jail cell.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Utilizer

3 posted on 01/26/2016 8:00:50 PM PST by CtBigPat (Free Republic - The grown-ups table of the internet.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Utilizer
What's wrong with that?

That's the password I always use for everything!

</sarcasm>

4 posted on 01/26/2016 8:00:53 PM PST by E. Pluribus Unum ("The goal of socialism is communism... Hatred is the basis of communism" --Vladimir Lenin)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Utilizer

don’t use the software, but what would be helpful for passwords is the use of different alphabets (Russian, German, Greek, etc.)in English passwords.

Is such a thing possible?


5 posted on 01/26/2016 8:02:58 PM PST by txnativegop (Tired of liberals, even a few in my own family.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: CtBigPat

GMTA


6 posted on 01/26/2016 8:03:00 PM PST by Army Air Corps (Four Fried Chickens and a Coke)
[ Post Reply | Private Reply | To 3 | View Replies]

To: Utilizer

It was a secret until you posted this!


7 posted on 01/26/2016 8:03:44 PM PST by PGR88
[ Post Reply | Private Reply | To 1 | View Replies]

To: Utilizer

If it’s good enough for Hillary, it’s good enough for anyone!


8 posted on 01/26/2016 8:04:41 PM PST by kaehurowing
[ Post Reply | Private Reply | To 1 | View Replies]

To: txnativegop

If you know the ASCII code, yes. However, then the problem becomes one of retention. The more convoluted the password created, the more difficult it is to remember it later on.

Nothing more embarrassing than forgetting your own password for a file or project you worked on back in your past.


9 posted on 01/26/2016 8:11:28 PM PST by Utilizer (Bacon A'kbar! - In world today are only peaceful people, and the muzrims trying to kill them)
[ Post Reply | Private Reply | To 5 | View Replies]

To: Utilizer

A couple of years back, NASA IT personnel were preparing some new computers (out of the box new) to deploy at Marshall Space Flight Center. The computers were plugged into the network for configuration. A couple of minutes later a security guy burst into the room and started yanking network cables.

A brand new, “out-of-the-box” Lenovo started uploading to an IP in mainland China.

The moron who approved the deployment of Lenovo Computers at a government installation should be in prison.


10 posted on 01/26/2016 8:20:55 PM PST by Bryan24 (When in doubt, move to the right..........)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Utilizer

that is not something I have too much trouble with.

Thanks for the info.


11 posted on 01/26/2016 8:43:13 PM PST by txnativegop (Tired of liberals, even a few in my own family.)
[ Post Reply | Private Reply | To 9 | View Replies]

To: Utilizer

How is this any different than bunches of companies using administration for user name and password for password when they ship their products?


12 posted on 01/26/2016 9:01:28 PM PST by gunsequalfreedom
[ Post Reply | Private Reply | To 1 | View Replies]

To: PGR88

Not so much. It’s more a problem that a major (*cough*) manufacturer uses it on a Ready-To-Implement mainstream device with no idea (one would hope, giving them the benefit of a doubt) that such an unthinking default immediately leaves the device vulnerable to compromises.


13 posted on 01/26/2016 9:28:25 PM PST by Utilizer (Bacon A'kbar! - In world today are only peaceful people, and the muzrims trying to kill them)
[ Post Reply | Private Reply | To 7 | View Replies]

To: Bryan24

Do you have a reference for that one? I would dearly love to read about it and save it for future usage later on in security consultations.


14 posted on 01/26/2016 9:29:33 PM PST by Utilizer (Bacon A'kbar! - In world today are only peaceful people, and the muzrims trying to kill them)
[ Post Reply | Private Reply | To 10 | View Replies]

To: Utilizer
Core Security alerted Lenovo to the vulnerabilities in SHAREit on October 29 last year. Lenovo issued patched versions of SHAREit yesterday.

Lenovo will release no patch before its time.

15 posted on 01/26/2016 11:26:29 PM PST by TChad (The left's accusations are usually self-descriptions.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: Utilizer

Nothing written. I talked to one of the IT guys when he was working on a problem in my office. The new contract to supply computers to NASA was an epic disaster. I work at MSFC in Huntsville. NASA should have cancelled the contract and started over.


16 posted on 01/27/2016 7:34:50 AM PST by Bryan24 (When in doubt, move to the right..........)
[ Post Reply | Private Reply | To 14 | View Replies]

To: PGR88

I just checked Utilizer bank account. He only has $24.96 left in his savings.


17 posted on 01/27/2016 1:15:00 PM PST by minnesota_bound
[ Post Reply | Private Reply | To 7 | View Replies]

To: minnesota_bound

Too late. It’s already been donated to the FR support drive. :)

Cheers!


18 posted on 01/27/2016 6:18:01 PM PST by Utilizer (Bacon A'kbar! - In world today are only peaceful people, and the muzrims trying to kill them)
[ Post Reply | Private Reply | To 17 | View Replies]

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson