I recently undertook a small research project while evaluating security of Thin Client devices during a Penetration Test. What I found during my assessment was that a handful of Thin Client devices were exposed to a number of security short-comings in the management and commonly deployed topology design. The project resulted in the creation of a white paper discussing security problems and observations made. It is important for me to state that the opinions and views expressed on this blog do not reflect that of NCC Group SecureTest and reflect only the opinion of their author, Hacker Fantastic. The devices and the management protocols were found to contain a number of security vulnerabilities which ranged from clear-text transmission of sensitive data (credentials), remote command injection vulnerabilities, using the devices as platforms for DDoS and local privilege escalation attacks. Marketing statements made by one vendor include “[..] with an unpublished API, Wyse Thin OS is one of the most secure operating systems on the market.” which would give an inaccurate sense of false security. You can download a copy of my paper which explains details of the attacks and weaknesses observed within the Thin Client devices here.

0 comments: