Gonjeshke Darand claims cyberattack against Bank Sepah (Iran)
xcancel.com2 pointsby dhx1 comments
An adjoining substation to BAH53 had one of it's two main buildings damaged/destroyed about 2026-07-16 per https://soaratlas.com/maps/asia-damage-to-data-center-power-substation-bahrain-jul-16th-2026-142024
Then about 2026-07-22 BAH53 itself was damaged/destroyed per https://soaratlas.com/maps/asia-damage-to-amazon-web-services-bahrain-jul-22nd-2026-142112
Possibly the least defended of the three sites as there is no air/missile defence battery in between this site and Iran.
BAH54 (Zallaq): https://www.openstreetmap.org/way/1359931661 No media reports about this data centre being attacked previously. Possibly the safest of the three as there are at least two (probably three) air/missile defence batteries in between this site and Iran.
BAH55 (Hamala): https://www.openstreetmap.org/way/956069872 Apparently the Batelco DC.1 data centre adjoining (and apparently critical to) BAH55 was damaged/destroyed about 2026-04-01 per https://www.bbc.com/news/articles/cgk28nj0lrjo _or_ the adjoining substation to these two facilities was damaged/destroyed -- news articles are hard to follow as to what exactly might have been damaged and the extent of damage caused.
Middle ground for defence with one or two (maybe three) air/missile defence batteries between this site and Iran, depending on where drones/missiles are launched from.
If these data centres are rebuilt, you'd maybe expect them to be rebuilt in new locations behind existing _permanent_ (and seemingly quite expensive) air/missile defence batteries in Bahrain (https://www.openstreetmap.org/way/1492281507 and https://www.openstreetmap.org/way/1492953902). Based on the permanency of those air/missile defence batteries it doesn't look like the government of Bahrain are expecting things to get safer for data centre hosting in Bahrain any time soon. US: 1.62
Japan: 1.23
China: 1.02
ROC: 0.86
ROK: 0.75 (where an increase to 0.8 in 2025 was cause for celebration, as is a predicted increase to 0.85 by mid 2026)[2]
Alternatively (and perhaps accounting for migration etc), UN 2024 forecasts population differences in these countries between 2024-2050 as:[3] US: +10%
Japan: -16%
China: -8%
ROC: -6%
ROK: -12%
[1] https://en.wikipedia.org/wiki/List_of_countries_by_total_fer... DECIMAL HEXADECIMAL DESCRIPTION
--------------------------------------------------------------------------------
516 0x204 OpenSSL encryption, salted, salt: 0x436999A39FECA649
binwalk US_BE12ProV1.0mt_V16.03.66.23_TD01.bin DECIMAL HEXADECIMAL DESCRIPTION
--------------------------------------------------------------------------------
516 0x204 OpenSSL encryption, salted, salt: 0x81235B7D4130B6AB
The third attempt I tried was unencrypted, and possibly reveals the problem exists on another model this CVE doesn't list as affected: DECIMAL HEXADECIMAL DESCRIPTION
--------------------------------------------------------------------------------
64 0x40 uImage header, header size: 64 bytes, header CRC: 0x95335734, created: 2026-06-16 09:09:35, image size: 2159135 bytes, Data Address: 0x80100000, Entry Point: 0x805F41C0, data CRC: 0x5ABEDB00, OS: Linux, CPU: MIPS, image type: OS Kernel Image, compression type: lzma, image name: "MIPS Tenda Linux-4.14.90"
128 0x80 LZMA compressed data, properties: 0x6D, dictionary size: 8388608 bytes, uncompressed size: 6947248 bytes
2159263 0x20F29F Squashfs filesystem, little endian, version 4.0, compression:xz, size: 8971644 bytes, 847 inodes, blocksize: 1048576 bytes, created: 2026-06-16 08:53:20
Inside is /squashfs-root/webroot_ro/default_ac.cfg which offers: sys.rzadmin.username=rzadmin
sys.rzadmin.password=cnphZG1pbg== (ed: base64 decoded: rzadmin)
sys.guest.username=guest
sys.guest.password=Z3Vlc3Q= (ed: base64 decoded: guest)
And /squashfs-root/webroot_ro/default_router.cfg which offers: sys.rzadmin.username=rzadmin
sys.rzadmin.password=cnphZG1pbg== (ed: base64 decoded: rzadmin)
From what I can see quickly (I haven't looked hard), "sys.rzadmin.password" is only referenced from the login() function of /bin/httpd in the context of retrieving a value. This value is retrieved and compared before the error message "login err: password is wrong." is emitted. I can't find any other reference to code in any part of the firmware that may allow a user to change the default value of "sys.rzadmin.password".
David Hicks (dhx)
Web (IPv6 and IPv4): https://david.hicks.id.au
E-mail (IPv6 and IPv4): [email protected]
PGP: Public Key: https://david.hicks.id.au/pgp/728F3435.asc Key ID: 728F3435 Fingerprint: 2442 14B5 2E51 CB0F CA3B 9DB8 59E0 E7B7 728F 3435
Hacker News: https://news.ycombinator.com/user?id=dhx
Last updated: 2012-03-05
-----BEGIN PGP SIGNATURE-----
iQIzBAEBCgAdFiEEJEIUtS5Ryw/KO524WeDnt3KPNDUFAlqcjdcACgkQWeDnt3KP NDUoJQ//TTN8pul74acpaVWImkdxEzqU1xOtAn/JyrZtYLjO2XnMDJSF9fTYKD7o AT19lV6kZnMo0p0lsNg5tnk5QMJ96rqPhpelAiXBYkdfz3VfVVj3X3AOdkg5XRbm 6Uy1sa8Omp6Jo21wtUOE+jtSYWwEiUFn9NPl3B1aNZSUo/LuMTJve1IidJuW705m OCenqn/Ro8eZ6kUOUByWoDBbGlobAkZpBZEyzHCpczZ1nGj50mn4cssXxDG4St62 S+o9009ZMgjFtfIDTwI7gwaNCgn6ldBbwYwfMaPL2cs2Kxl05iqbM/KcsU/CLZE5 Dmh/0aPaYNJdg8PDjpItupxryNwwROB/lCigGsp+msiXtOJTENdCfojFF6ffiFTl Lxqfmbe+bn3JcqTOXzExPD0NXstx7sdetQZSwVnuCQGH4JjcUpyzKmrEw4ATvpXb VXWf00jXAMWhGHSQJLzecTXw8/iWWh0swIpLrokq3ISrMBwK2oAavZzPh4TpH5ao Y+VL0LkqAaiEpLyBAJDUFFdrJbDv9P82fZ8NFEiK3plgm5xfv62UOzFVIG+ezdDY PvfodliBtu/mLMc9YIjo5H59NtnmT4fXb8/LW5rNP7xSxWjMbCGiG3/pVSUx+FBN v74Ykn2ioBPNM3ApFC3kBrlS1K8jIcNgCfMQcH0oc7y6+e84NwY= =sBF3 -----END PGP SIGNATURE-----