Core Engine

Misconfiguration Analysis

Introduction

Misconfiguration analysis finds insecure default settings, weak cryptography and poor architectural choices in an application or device.

Why it's needed

An application with no known CVEs is still a target if it ships with default administrative credentials, exposed debug ports (UART or JTAG) or unencrypted communication channels.

How TrustDyne works

TrustDyne runs static analysis on the unpacked firmware. It checks for default, empty and weakly hashed (MD5-crypt or DES) account passwords, telnet and FTP started at boot, insecure UPnP, open Wi-Fi, SSH root login, default SNMP community strings, SUID binaries and backdoor daemons. For iOS apps it also flags settings that allow TLS 1.0 or 1.1.