Daffodil International University

Faculty of Science and Information Technology => Recent Technologies and Trends in Software Engineering => Software Engineering => Cyber and Software Security => Topic started by: maruf.swe on March 25, 2019, 06:39:39 PM

Title: IDenticard Zero-Days Allow Corporate Building Access, Location Recon
Post by: maruf.swe on March 25, 2019, 06:39:39 PM
(https://media.threatpost.com/wp-content/uploads/sites/103/2019/01/15173207/building-tag.jpeg)
Multiple hardcoded passwords allow attackers to create badges to gain building entry, access video surveillance feeds, manipulate databases and more.

UPDATE

Most denizens of corporate America are pretty familiar with building security, and the requirement to swipe a badge to enter a building or an office suite; and as a result, most workers likely go about their day feeling secure that their stuff is physically secure from outsiders. Unfortunately, it turns out that multiple zero-day vulnerabilities in the PremiSys access control system mean that any sense of security may be a false one.

For More Details : https://threatpost.com/identicard-zero-days-allow-corporate-building-access-location-recon/140891/ (https://threatpost.com/identicard-zero-days-allow-corporate-building-access-location-recon/140891/)