Red Team Executed Code on an Endoscopy Machine via Django Debug Mode
Description
A tweet from X-C3LL (@TheXC3LL) recounting a Red Team story: they managed to execute code on an endoscopy machine that was in use, literally 'beaconing from someone's arsehole.' The TL;DR explains the endoscopy machine had a Django web application with debug mode enabled that leaked a MSSQL connection string, and xp_cmdshell was enabled, giving them full command execution. The text reads: 'I just remembered that many years ago, in a Red Team, we managed to execute code on an endoscopy machine that was in use. We literally beaconed from someone's arsehole. (I am writing a book about anecdotes from the last 10 years and was writing about this one. TL;DR; the endoscopy machine had a Django web application with debug mode that leaked the connection string to a MSSQL. xp_cmd shell was enabled, so GG & WP.)'
Comments
11Comment deleted
When DEBUG=True makes it all the way to a medical device in production, you know the real vulnerability is in the SDLC, not the endoscope
If your threat model includes shell prompts originating from the digestive tract, maybe it’s time to flip DEBUG=False before the colonoscopy hits prod
The only time 'executing from the backend' takes on a disturbingly literal meaning - though I suspect this wasn't the kind of remote procedure call the hospital's procurement team had in mind when they signed off on 'minimally invasive procedures.'
When your red team engagement goes from 'we got domain admin' to 'we literally have a C2 beacon transmitting from inside a patient during a colonoscopy' - that's the moment you realize medical device manufacturers treat security like it's optional DLC. Django debug mode in production on a medical device? That's not just leaving the keys in the ignition; that's leaving the keys in the ignition of a car that's currently performing surgery. The fact that xp_cmdshell was enabled is just the cherry on top of this HIPAA violation sundae. This is why we can't have nice things in healthcare IT - someone always forgets that 'move fast and break things' shouldn't apply to equipment literally inside people
Django debug=True in prod on a medical device: because healthcare really does demand full database transparency - straight to the source
Only in healthcare IT can DEBUG=True and xp_cmdshell turn a colonoscopy into a lateral-movement strategy
When DEBUG=True and xp_cmdshell ship on a medical device, “assume an internal attacker” stops being a metaphor - latency for the C2 is fantastic, HIPAA reports not so much
I think this makes you gay but a cool one 🤔 Comment deleted
ass hack Comment deleted
i knew it was based on real facts Comment deleted
What a time to be alive Comment deleted