The MakerBot Digitizer desktop 3D scanner is revolutionizing the design process. Learn more about you can use high quality 3D Scanning technology to have 3D models in minutes.
We are a social entrepreneurship company that partners with the top universities in the world to offer courses online for anyone to take, for free. We envision a future where the top universities are educating not only thousands of students, but millions. Our technology enables the best professors to teach tens or hundreds of thousands of students.
inding 1: Hard-Coded Bluetooth PIN
*****Credit: Daniel Crowley of Trustwave SpiderLabs
CVE: CVE-2013-4866
CWE: CWE-259
The "My Satis" Android application has a hard-coded Bluetooth PIN of "0000"
as can be seen in the following line of decompiled code from the
application:
BluetoothDevice localBluetoothDevice =
BluetoothManager.getInstance().execPairing(paramString, "0000")
As such, any person using the "My Satis" application can control any Satis
toilet. An attacker could simply download the "My Satis" application and
use it to cause the toilet to repeatedly flush, raising the water usage and
therefore utility cost to its owner.
Attackers could cause the unit to unexpectedly open/close the lid, activate
bidet or air-dry functions, causing discomfort or distress to user.