Skip to content
DevMeme
6625 of 7590
Security Post #7259 · source on Telegram

Red Team Executed Code on an Endoscopy Machine via Django Debug Mode

Description

A tweet from X-C3LL (@TheXC3LL) recounting a Red Team story: they managed to execute code on an endoscopy machine that was in use, literally 'beaconing from someone's arsehole.' The TL;DR explains the endoscopy machine had a Django web application with debug mode enabled that leaked a MSSQL connection string, and xp_cmdshell was enabled, giving them full command execution. The text reads: 'I just remembered that many years ago, in a Red Team, we managed to execute code on an endoscopy machine that was in use. We literally beaconed from someone's arsehole. (I am writing a book about anecdotes from the last 10 years and was writing about this one. TL;DR; the endoscopy machine had a Django web application with debug mode that leaked the connection string to a MSSQL. xp_cmd shell was enabled, so GG & WP.)'

Comments

11
Anonymous ★ Top Pick When DEBUG=True makes it all the way to a medical device in production, you know the real vulnerability is in the SDLC, not the endoscope
  1. Anonymous ★ Top Pick

    When DEBUG=True makes it all the way to a medical device in production, you know the real vulnerability is in the SDLC, not the endoscope

  2. Anonymous

    If your threat model includes shell prompts originating from the digestive tract, maybe it’s time to flip DEBUG=False before the colonoscopy hits prod

  3. Anonymous

    The only time 'executing from the backend' takes on a disturbingly literal meaning - though I suspect this wasn't the kind of remote procedure call the hospital's procurement team had in mind when they signed off on 'minimally invasive procedures.'

  4. Anonymous

    When your red team engagement goes from 'we got domain admin' to 'we literally have a C2 beacon transmitting from inside a patient during a colonoscopy' - that's the moment you realize medical device manufacturers treat security like it's optional DLC. Django debug mode in production on a medical device? That's not just leaving the keys in the ignition; that's leaving the keys in the ignition of a car that's currently performing surgery. The fact that xp_cmdshell was enabled is just the cherry on top of this HIPAA violation sundae. This is why we can't have nice things in healthcare IT - someone always forgets that 'move fast and break things' shouldn't apply to equipment literally inside people

  5. Anonymous

    Django debug=True in prod on a medical device: because healthcare really does demand full database transparency - straight to the source

  6. Anonymous

    Only in healthcare IT can DEBUG=True and xp_cmdshell turn a colonoscopy into a lateral-movement strategy

  7. Anonymous

    When DEBUG=True and xp_cmdshell ship on a medical device, “assume an internal attacker” stops being a metaphor - latency for the C2 is fantastic, HIPAA reports not so much

  8. @dwtexe 10mo

    I think this makes you gay but a cool one 🤔

  9. @hur7m3 10mo

    ass hack

  10. @a_646_man 10mo

    i knew it was based on real facts

  11. @Chris_FJ 10mo

    What a time to be alive

Use J and K for navigation