Light

Episode #969 Quiz

Minimum Viable Secure Product
Date: 2024-04-09 | Length: 1.5 hrs | Episode page at twit.tv

About this episode

The episode highlights recurring IoT and web-security failures: D-Link NAS devices exposed hardcoded backdoor credentials plus command injection in nas_sharing.cgi, enabling remote code execution on 92,589 Internet-facing units and active malware exploitation.

Your name and email are stored only in your browser local storage for convenience. They are not retained server-side.

Question 1: What was the hard-coded backdoor username used in the exposed D-Link NAS devices discussed in the episode?
Question 2: According to the episode, which CVE tracked the command-injection flaw in the D-Link NAS devices?
Question 3: What was the approximate number of exposed D-Link NAS devices found on the public Internet during the researcher’s scan?
Question 4: What did the episode identify as the current final step in the chain that lets the D-Link NAS flaw be triggered remotely?
Question 5: Which organization did the episode say had newly joined the Minimum Viable Secure Product Working Group?
Cancel