{"id":41775,"date":"2021-07-15T19:34:34","date_gmt":"2021-07-15T19:34:34","guid":{"rendered":"https:\/\/packetstormsecurity.com\/news\/view\/32469\/KiwiSDR-Has-Had-A-Backdoor-With-Root-Access-For-Years.html"},"modified":"2021-07-15T19:34:34","modified_gmt":"2021-07-15T19:34:34","slug":"kiwisdr-has-had-a-backdoor-with-root-access-for-years","status":"publish","type":"post","link":"https:\/\/www.threatshub.org\/blog\/kiwisdr-has-had-a-backdoor-with-root-access-for-years\/","title":{"rendered":"KiwiSDR Has Had A Backdoor With Root Access For Years"},"content":{"rendered":"<figure class=\"intro-image intro-left\"><img decoding=\"async\" src=\"https:\/\/cdn.arstechnica.net\/wp-content\/uploads\/2021\/07\/kiwisdr-800x500.jpg\" alt=\"Screenshot of Kiwi SDR.\"><figcaption class=\"caption\"><\/figcaption><\/figure>\n<aside id=\"social-left\" class=\"social-left\" aria-label=\"Read the comments or share this article\"><a title=\"31 posters participating, including story author\" class=\"comment-count icon-comment-bubble-down\" href=\"https:\/\/arstechnica.com\/gadgets\/2021\/07\/for-years-a-backdoor-in-popular-kiwisdr-product-gave-root-to-project-developer\/?comments=1\"> <\/p>\n<h4 class=\"comment-count-before\">reader comments<\/h4>\n<p> <span class=\"comment-count-number\">38<\/span> <span class=\"visually-hidden\"> with 31 posters participating, including story author<\/span> <\/a> <\/p>\n<div class=\"share-links\">\n<h4>Share this story<\/h4>\n<\/p><\/div>\n<\/aside>\n<p><!-- cache hit 690:single\/related:91628c4021a676286aff3b33d75e8395 --><!-- empty --><\/p>\n<figure class=\"image shortcode-img right medium\"><a href=\"https:\/\/cdn.arstechnica.net\/wp-content\/uploads\/2021\/07\/kiwisdr-image.jpeg\" class=\"enlarge\" data-height=\"798\" data-width=\"932\" alt=\"A spectrum painted image made using KiwiSDR.\"><img loading=\"lazy\" decoding=\"async\" alt=\"A spectrum painted image made using KiwiSDR.\" src=\"https:\/\/cdn.arstechnica.net\/wp-content\/uploads\/2021\/07\/kiwisdr-image-300x257.jpeg\" width=\"300\" height=\"257\" srcset=\"https:\/\/cdn.arstechnica.net\/wp-content\/uploads\/2021\/07\/kiwisdr-image-640x548.jpeg 2x\"><\/a><figcaption class=\"caption\">\n<div class=\"caption-text\"><a href=\"https:\/\/cdn.arstechnica.net\/wp-content\/uploads\/2021\/07\/kiwisdr-image.jpeg\" class=\"enlarge-link\" data-height=\"798\" data-width=\"932\">Enlarge<\/a> <span class=\"sep\">\/<\/span> A spectrum painted image made using KiwiSDR.<\/div>\n<\/figcaption><\/figure>\n<p>KiwiSDR is hardware that uses a <a href=\"https:\/\/en.wikipedia.org\/wiki\/Software-defined_radio\">software-defined radio<\/a> to monitor transmissions in a local area and stream them over the Internet. A largely hobbyist base of users does all kinds of cool things with the playing-card-sized devices. For instance, a user in Manhattan could connect one to the Internet so that people in Madrid, Spain, or Sydney, Australia, could listen to AM radio broadcasts, CB radio conversations, or even watch lightning storms in Manhattan.<\/p>\n<p>On Wednesday, users learned that for years, their devices had been equipped with a backdoor that allowed the KiwiSDR creator\u2014and possibly others\u2014to log in to the devices with administrative system rights. The remote admin could then make configuration changes and access data not just for the KiwiSDR but in many cases to the <a href=\"https:\/\/arstechnica.com\/tag\/raspberry-pi\/\">Raspberry Pi<\/a>, BeagleBone Black, or other computing devices the SDR hardware is connected to.<\/p>\n<h2>A big trust problem<\/h2>\n<p>Signs of the backdoor in the KiwiSDR date back to <a href=\"https:\/\/github.com\/jks-prv\/Beagle_SDR_GPS\/commit\/6bdde32e603cc6ec745c779aed7d67c855e2342b\">at least 2017<\/a>. The backdoor was <a href=\"https:\/\/github.com\/jks-prv\/Beagle_SDR_GPS\/commit\/fef90929ed8e94ff496fbce5de2fc2b1fc45b929#diff-ad090c36f5cf2b493c321e92af0edbf58f44764081e3a058a532f7b387fcc1feL833\">recently removed<\/a> with <a href=\"https:\/\/github.com\/jks-prv\/Beagle_SDR_GPS\/commit\/0edf5fcfb99fdffa2058c86f60c855a306a857ee#\">no mention<\/a> of the removal under unclear circumstances. But despite the removal, users remain rattled since the devices run as root on whatever computing device they\u2019re connected to and can often access other devices on the same network.<\/p>\n<p>\u201cIt\u2019s a big trust problem,\u201d a user with the handle <a href=\"https:\/\/twitter.com\/xssfox\">xssfox<\/a> told me. \u201cI was completely unaware that there was a backdoor, and it\u2019s hugely disappointing to see the developer adding backdoors in and actively using them without consent.\u201d<\/p>\n<aside class=\"ad_wrapper\" aria-label=\"In Content advertisement\"> <span class=\"ad_notice\">Advertisement <\/span> <\/aside>\n<p>Xssfox said she runs two KiwiSDR devices, one on a <a href=\"https:\/\/beagleboard.org\/black\/\">BeagleBone Black<\/a> that uses a custom <a href=\"https:\/\/en.wikipedia.org\/wiki\/Field-programmable_gate_array\">FPGA<\/a> to run the <a href=\"https:\/\/prideradio.group\/news\/kiwisdr-and-vi2021pride-schedule\">Pride Radio Group<\/a>, which lets people listen to radio transmissions in and around Gladstone, Australia. A <a href=\"http:\/\/kiwisdr.com\/public\/\">page<\/a> of public broadcasts shows that roughly 600 other devices are also connected to the Internet.<\/p>\n<p>Xssfox added:<\/p>\n<blockquote>\n<p>In my case, the KiwiSDRs are hosted on a remote site that has other radio experiments running. They could have gained access to those. Other KiwiSDR users sometimes have them set up in remote locations using other people\u2019s\/companies\u2019 networks, or on their home network. It\u2019s sort of like the security camera backdoors\/exploits, but smaller-scale [and] just amateur radio people.<\/p>\n<\/blockquote>\n<p>Software-defined radios use software\u2014rather than the standard hardware found in traditional radio equipment\u2014to process radio signals. The KiwiSDR attaches to an embedded computer, which in turn shares local signals with a much wider base of people.<\/p>\n<p>The backdoor is simple enough. A few lines of code allow the developer to remotely access any device by entering its URL in a browser and appending a password to the end of the address. From there, the person using the backdoor can make configuration changes not only to the radio device but, by default, also to the underlying computing device it runs on. Here\u2019s a <a href=\"https:\/\/twitter.com\/xssfox\/status\/1415606351464595459\">video<\/a> of xssfox using the backdoor on her device and getting root access to her BeagleBone.<\/p>\n<div class=\"twitter-tweet\">\n<blockquote class=\"twitter-tweet\" data-lang=\"en\">\n<p lang=\"en\" dir=\"ltr\">Quick video showing how the backdoor on the kiwisdr works.<\/p>\n<p>I&#8217;ve also tested that touch \/root\/kiwi.config\/opt.no_console mitigates the issue<\/p>\n<p>Thanks <a href=\"https:\/\/twitter.com\/the6p4c?ref_src=twsrc%5Etfw\">@the6p4c<\/a> for helping me test \ud83d\ude42 <a href=\"https:\/\/t.co\/0xKD1NfvwL\">pic.twitter.com\/0xKD1NfvwL<\/a><\/p>\n<p>\u2014 xssfox (@xssfox) <a href=\"https:\/\/twitter.com\/xssfox\/status\/1415606351464595459?ref_src=twsrc%5Etfw\">July 15, 2021<\/a><\/p><\/blockquote>\n<\/div>\n<p>Here\u2019s an image in higher resolution:<\/p>\n<figure class=\"image shortcode-img center large\"><a href=\"https:\/\/cdn.arstechnica.net\/wp-content\/uploads\/2021\/07\/kiwisdr-admin-interface.jpg\" class=\"enlarge\" data-height=\"1349\" data-width=\"2048\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/cdn.arstechnica.net\/wp-content\/uploads\/2021\/07\/kiwisdr-admin-interface-640x422.jpg\" width=\"640\" height=\"422\" srcset=\"https:\/\/cdn.arstechnica.net\/wp-content\/uploads\/2021\/07\/kiwisdr-admin-interface-1280x843.jpg 2x\"><\/a><figcaption class=\"caption\"><\/figcaption><\/figure>\n<p>\u201cIt looks like the SDR&#8230; plugs into a BeagleBone Arm Linux board,\u201d HD Moore, a security expert and CEO of network discovery platform Rumble, told me. \u201cThis shell is on that Linux board. Compromising it may get you into the user\u2019s network.\u201d<\/p>\n<aside class=\"ad_wrapper\" aria-label=\"In Content advertisement\"> <span class=\"ad_notice\">Advertisement <\/span> <\/aside>\n<h2>The backdoor lives on<\/h2>\n<p>Xssfox said that access to the underlying computing device\u2014and possibly other devices on the same network\u2014happens as long as a setting called &#8220;console access&#8221; is turned on, as it is by default. Turning the access off requires a change to either the admin interface or a configuration file, which many users are unlikely to have made. Additionally, many devices are updated rarely, if ever. So even though the KiwiSDR developer has removed the offending code, the backdoor will live on in devices, making them vulnerable to takeover.<\/p>\n<p>Software submissions and technical documents like <a href=\"http:\/\/kiwisdr.com\/docs\/KiwiSDR\/KiwiSDR.design.review.pdf\">this one<\/a> name the developer of KiwiSDR as John Seamons. Seamons didn\u2019t respond to an email seeking comment for this post.<\/p>\n<p>The user forums were unavailable at the time of publication. Screenshots <a href=\"https:\/\/twitter.com\/vk5qi\/status\/1415429408312098819\">here<\/a> and <a href=\"https:\/\/twitter.com\/vk5qi\/status\/1415434355757916160\">here<\/a>, however, appear to show Seamons admitting to the backdoor as long ago as 2017.<\/p>\n<figure class=\"image shortcode-img center large\"><a href=\"https:\/\/cdn.arstechnica.net\/wp-content\/uploads\/2021\/07\/jks-post-02.jpeg\" class=\"enlarge\" data-height=\"355\" data-width=\"1200\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/cdn.arstechnica.net\/wp-content\/uploads\/2021\/07\/jks-post-02-640x189.jpeg\" width=\"640\" height=\"189\" srcset=\"https:\/\/cdn.arstechnica.net\/wp-content\/uploads\/2021\/07\/jks-post-02.jpeg 2x\"><\/a><figcaption class=\"caption\"><\/figcaption><\/figure>\n<figure class=\"image shortcode-img center large\"><a href=\"https:\/\/cdn.arstechnica.net\/wp-content\/uploads\/2021\/07\/jks-post-01.jpeg\" class=\"enlarge\" data-height=\"437\" data-width=\"1199\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/cdn.arstechnica.net\/wp-content\/uploads\/2021\/07\/jks-post-01-640x233.jpeg\" width=\"640\" height=\"233\" srcset=\"https:\/\/cdn.arstechnica.net\/wp-content\/uploads\/2021\/07\/jks-post-01.jpeg 2x\"><\/a><figcaption class=\"caption\"><\/figcaption><\/figure>\n<p>Another troubling aspect to the backdoor is that, as <a href=\"https:\/\/twitter.com\/vk5qi\/status\/1415440183982391298\">noted<\/a> by engineer user <a href=\"https:\/\/twitter.com\/vk5qi\">Mark Jessop<\/a>, it communicated over an HTTP connection, exposing the plaintext password and data over the backdoored network to anyone who could monitor the traffic coming into or out of the device.<\/p>\n<div class=\"twitter-tweet\">\n<blockquote class=\"twitter-tweet\" data-lang=\"en\">\n<p lang=\"en\" dir=\"ltr\">However, given the KiwiSDR is HTTP only, sending what is essentially a &#8216;master&#8217; password in the clear is a little worrying. KiwiSDR does not support HTTPS, and it&#8217;s been stated that it will never support it. (Dealing with certs on it would be a PITA too)<\/p>\n<p>\u2014 Mark Jessop (@vk5qi) <a href=\"https:\/\/twitter.com\/vk5qi\/status\/1415440183982391298?ref_src=twsrc%5Etfw\">July 14, 2021<\/a><\/p><\/blockquote>\n<\/div>\n<p>KiwiSDR users who want to check if their devices have been remotely accessed can do so by running the command<\/p>\n<pre>zgrep -- \"PWD admin\" \/var\/log\/messages*<\/pre>\n<p>There\u2019s no indication that anyone has used the backdoor to do malicious things, but the very existence of this code and its apparent use over the years to access user devices without permission is itself a security breach\u2014and a disturbing one at that. At a minimum, users should inspect their devices and networks for signs of compromise and upgrade to <a href=\"https:\/\/github.com\/jks-prv\/Beagle_SDR_GPS\/commit\/0edf5fcfb99fdffa2058c86f60c855a306a857ee#diff-0f9dd0b75ca4dd0210c8be84066de570e59c0713d22688ac5b26422af8b05021R5\">v1.461<\/a>. The truly paranoid should consider unplugging their devices until more details become available.<\/p>\n<p><em>Listing image by <a href=\"http:\/\/kiwisdr.com\/\">KiwiSDR<\/a><\/em><\/p>\n<p> READ MORE <a href=\"https:\/\/packetstormsecurity.com\/news\/view\/32469\/KiwiSDR-Has-Had-A-Backdoor-With-Root-Access-For-Years.html\">HERE<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>READ MORE HERE&#8230;<\/p>\n","protected":false},"author":2,"featured_media":41776,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"colormag_page_layout":"default_layout","footnotes":""},"categories":[277],"tags":[4207],"class_list":["post-41775","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cybersecurity-blogs","tag-headlinehackerbackdoor"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.1 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>KiwiSDR Has Had A Backdoor With Root Access For Years 2026 | ThreatsHub Cybersecurity News<\/title>\n<meta name=\"description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.threatshub.org\/blog\/kiwisdr-has-had-a-backdoor-with-root-access-for-years\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"KiwiSDR Has Had A Backdoor With Root Access For Years 2026 | ThreatsHub Cybersecurity News\" \/>\n<meta property=\"og:description\" content=\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security &amp; Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.threatshub.org\/blog\/kiwisdr-has-had-a-backdoor-with-root-access-for-years\/\" \/>\n<meta property=\"og:site_name\" content=\"ThreatsHub Cybersecurity News\" \/>\n<meta property=\"article:published_time\" content=\"2021-07-15T19:34:34+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/07\/kiwisdr-has-had-a-backdoor-with-root-access-for-years.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"800\" \/>\n\t<meta property=\"og:image:height\" content=\"500\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"TH Author\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@threatshub\" \/>\n<meta name=\"twitter:site\" content=\"@threatshub\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"TH Author\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"5 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/kiwisdr-has-had-a-backdoor-with-root-access-for-years\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/kiwisdr-has-had-a-backdoor-with-root-access-for-years\\\/\"},\"author\":{\"name\":\"TH Author\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\"},\"headline\":\"KiwiSDR Has Had A Backdoor With Root Access For Years\",\"datePublished\":\"2021-07-15T19:34:34+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/kiwisdr-has-had-a-backdoor-with-root-access-for-years\\\/\"},\"wordCount\":952,\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/kiwisdr-has-had-a-backdoor-with-root-access-for-years\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/07\\\/kiwisdr-has-had-a-backdoor-with-root-access-for-years.jpg\",\"keywords\":[\"headline,hacker,backdoor\"],\"articleSection\":[\"CyberSecurity Blogs\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/kiwisdr-has-had-a-backdoor-with-root-access-for-years\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/kiwisdr-has-had-a-backdoor-with-root-access-for-years\\\/\",\"name\":\"KiwiSDR Has Had A Backdoor With Root Access For Years 2026 | ThreatsHub Cybersecurity News\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/kiwisdr-has-had-a-backdoor-with-root-access-for-years\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/kiwisdr-has-had-a-backdoor-with-root-access-for-years\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/07\\\/kiwisdr-has-had-a-backdoor-with-root-access-for-years.jpg\",\"datePublished\":\"2021-07-15T19:34:34+00:00\",\"description\":\"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/kiwisdr-has-had-a-backdoor-with-root-access-for-years\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/kiwisdr-has-had-a-backdoor-with-root-access-for-years\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/kiwisdr-has-had-a-backdoor-with-root-access-for-years\\\/#primaryimage\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/07\\\/kiwisdr-has-had-a-backdoor-with-root-access-for-years.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2021\\\/07\\\/kiwisdr-has-had-a-backdoor-with-root-access-for-years.jpg\",\"width\":800,\"height\":500},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/kiwisdr-has-had-a-backdoor-with-root-access-for-years\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"headline,hacker,backdoor\",\"item\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/tag\\\/headlinehackerbackdoor\\\/\"},{\"@type\":\"ListItem\",\"position\":3,\"name\":\"KiwiSDR Has Had A Backdoor With Root Access For Years\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"name\":\"ThreatsHub Cybersecurity News\",\"description\":\"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform\",\"publisher\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\"},\"alternateName\":\"Threatshub.org\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#organization\",\"name\":\"ThreatsHub.org\",\"alternateName\":\"Threatshub.org\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\",\"url\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"contentUrl\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/wp-content\\\/uploads\\\/2025\\\/05\\\/Threatshub_Favicon1.jpg\",\"width\":432,\"height\":435,\"caption\":\"ThreatsHub.org\"},\"image\":{\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/logo\\\/image\\\/\"},\"sameAs\":[\"https:\\\/\\\/x.com\\\/threatshub\"]},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/www.threatshub.org\\\/blog\\\/#\\\/schema\\\/person\\\/12e0a8671ff89a863584f193e7062476\",\"name\":\"TH Author\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g\",\"caption\":\"TH Author\"}}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"KiwiSDR Has Had A Backdoor With Root Access For Years 2026 | ThreatsHub Cybersecurity News","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.threatshub.org\/blog\/kiwisdr-has-had-a-backdoor-with-root-access-for-years\/","og_locale":"en_US","og_type":"article","og_title":"KiwiSDR Has Had A Backdoor With Root Access For Years 2026 | ThreatsHub Cybersecurity News","og_description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","og_url":"https:\/\/www.threatshub.org\/blog\/kiwisdr-has-had-a-backdoor-with-root-access-for-years\/","og_site_name":"ThreatsHub Cybersecurity News","article_published_time":"2021-07-15T19:34:34+00:00","og_image":[{"width":800,"height":500,"url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/07\/kiwisdr-has-had-a-backdoor-with-root-access-for-years.jpg","type":"image\/jpeg"}],"author":"TH Author","twitter_card":"summary_large_image","twitter_creator":"@threatshub","twitter_site":"@threatshub","twitter_misc":{"Written by":"TH Author","Est. reading time":"5 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.threatshub.org\/blog\/kiwisdr-has-had-a-backdoor-with-root-access-for-years\/#article","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/kiwisdr-has-had-a-backdoor-with-root-access-for-years\/"},"author":{"name":"TH Author","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476"},"headline":"KiwiSDR Has Had A Backdoor With Root Access For Years","datePublished":"2021-07-15T19:34:34+00:00","mainEntityOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/kiwisdr-has-had-a-backdoor-with-root-access-for-years\/"},"wordCount":952,"publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/kiwisdr-has-had-a-backdoor-with-root-access-for-years\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/07\/kiwisdr-has-had-a-backdoor-with-root-access-for-years.jpg","keywords":["headline,hacker,backdoor"],"articleSection":["CyberSecurity Blogs"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/www.threatshub.org\/blog\/kiwisdr-has-had-a-backdoor-with-root-access-for-years\/","url":"https:\/\/www.threatshub.org\/blog\/kiwisdr-has-had-a-backdoor-with-root-access-for-years\/","name":"KiwiSDR Has Had A Backdoor With Root Access For Years 2026 | ThreatsHub Cybersecurity News","isPartOf":{"@id":"https:\/\/www.threatshub.org\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.threatshub.org\/blog\/kiwisdr-has-had-a-backdoor-with-root-access-for-years\/#primaryimage"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/kiwisdr-has-had-a-backdoor-with-root-access-for-years\/#primaryimage"},"thumbnailUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/07\/kiwisdr-has-had-a-backdoor-with-root-access-for-years.jpg","datePublished":"2021-07-15T19:34:34+00:00","description":"ThreatsHub Cybersecurity News | ThreatsHub.org | Cloud Security & Cyber Threats Analysis Hub. 100% Free OSINT Threat Intelligent and Cybersecurity News.","breadcrumb":{"@id":"https:\/\/www.threatshub.org\/blog\/kiwisdr-has-had-a-backdoor-with-root-access-for-years\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.threatshub.org\/blog\/kiwisdr-has-had-a-backdoor-with-root-access-for-years\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/kiwisdr-has-had-a-backdoor-with-root-access-for-years\/#primaryimage","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/07\/kiwisdr-has-had-a-backdoor-with-root-access-for-years.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2021\/07\/kiwisdr-has-had-a-backdoor-with-root-access-for-years.jpg","width":800,"height":500},{"@type":"BreadcrumbList","@id":"https:\/\/www.threatshub.org\/blog\/kiwisdr-has-had-a-backdoor-with-root-access-for-years\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.threatshub.org\/blog\/"},{"@type":"ListItem","position":2,"name":"headline,hacker,backdoor","item":"https:\/\/www.threatshub.org\/blog\/tag\/headlinehackerbackdoor\/"},{"@type":"ListItem","position":3,"name":"KiwiSDR Has Had A Backdoor With Root Access For Years"}]},{"@type":"WebSite","@id":"https:\/\/www.threatshub.org\/blog\/#website","url":"https:\/\/www.threatshub.org\/blog\/","name":"ThreatsHub Cybersecurity News","description":"%%focuskw%% Threat Intel \u2013 Threat Intel Services \u2013 CyberIntelligence \u2013 Cyber Threat Intelligence - Threat Intelligence Feeds - Threat Intelligence Reports - CyberSecurity Report \u2013 Cyber Security PDF \u2013 Cybersecurity Trends - Cloud Sandbox \u2013- Threat IntelligencePortal \u2013 Incident Response \u2013 Threat Hunting \u2013 IOC - Yara - Security Operations Center \u2013 SecurityOperation Center \u2013 Security SOC \u2013 SOC Services - Advanced Threat - Threat Detection - TargetedAttack \u2013 APT \u2013 Anti-APT \u2013 Advanced Protection \u2013 Cyber Security Services \u2013 Cybersecurity Services -Threat Intelligence Platform","publisher":{"@id":"https:\/\/www.threatshub.org\/blog\/#organization"},"alternateName":"Threatshub.org","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.threatshub.org\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.threatshub.org\/blog\/#organization","name":"ThreatsHub.org","alternateName":"Threatshub.org","url":"https:\/\/www.threatshub.org\/blog\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/","url":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","contentUrl":"https:\/\/www.threatshub.org\/blog\/coredata\/uploads\/2025\/05\/Threatshub_Favicon1.jpg","width":432,"height":435,"caption":"ThreatsHub.org"},"image":{"@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/logo\/image\/"},"sameAs":["https:\/\/x.com\/threatshub"]},{"@type":"Person","@id":"https:\/\/www.threatshub.org\/blog\/#\/schema\/person\/12e0a8671ff89a863584f193e7062476","name":"TH Author","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/066276f086d5155df79c850206a779ad368418a844da0182ce43f9cd5b506c3d?s=96&d=mm&r=g","caption":"TH Author"}}]}},"_links":{"self":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/41775","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/comments?post=41775"}],"version-history":[{"count":0,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/posts\/41775\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media\/41776"}],"wp:attachment":[{"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/media?parent=41775"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/categories?post=41775"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.threatshub.org\/blog\/wp-json\/wp\/v2\/tags?post=41775"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}