{"id":286662,"date":"2021-06-29T18:29:23","date_gmt":"2021-06-29T15:29:23","guid":{"rendered":"https:\/\/en.buradabiliyorum.com\/western-digital-removed-code-that-would-have-prevented-global-my-book-wiping-review-geek\/"},"modified":"2021-06-29T18:29:23","modified_gmt":"2021-06-29T15:29:23","slug":"western-digital-removed-code-that-would-have-prevented-global-my-book-wiping-review-geek","status":"publish","type":"post","link":"https:\/\/buradabiliyorum.com\/en\/western-digital-removed-code-that-would-have-prevented-global-my-book-wiping-review-geek\/","title":{"rendered":"#Western Digital Removed Code That Would Have Prevented Global My Book Wiping \u2013 Review Geek"},"content":{"rendered":"<p><strong>&#8220;#Western Digital Removed Code That Would Have Prevented Global My Book Wiping \u2013 Review Geek&#8221;<\/strong><\/p>\n<div id=\"article-content-area\">\n<figure style=\"width: 1920px\" class=\"wp-caption alignnone\"><img loading=\"lazy\" decoding=\"async\" class=\"type:primaryImage wp-image-90180 size-full\" src=\"https:\/\/www.reviewgeek.com\/p\/uploads\/2021\/06\/0bb2a580.png?width=1200\" alt=\"\" width=\"1920\" height=\"1080\" data-credittext=\"Western Digital\" onload=\"pagespeed.lazyLoadImages.loadIfVisibleAndMaybeBeacon(this);\" onerror=\"this.onerror=null;pagespeed.lazyLoadImages.loadIfVisibleAndMaybeBeacon(this);\"\/><figcaption class=\"wp-caption-text\"><span class=\"type:primaryImage imagecredit\">Western Digital<\/span><\/figcaption><\/figure>\n<p>A Western Digital developer removed code that would have prevented last week\u2019s mass wiping of My Book Live storage drives, according to a report from <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/arstechnica.com\/gadgets\/2021\/06\/hackers-exploited-0-day-not-2018-bug-to-mass-wipe-my-book-live-devices\/\"><em>Ars Technica<\/em><\/a>. A hacker exploited this change in code, likely to disrupt <em>another<\/em> hacker who had turned some My Book Live devices into a botnet.<\/p>\n<p>Victims of last week\u2019s global wiping event complained that the factory reset tool on their My Book Live devices should be password-protected. Evidently, that was once the case. But a developer at Western Digital edited the <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/paste.debian.net\/plainh\/7630c424\">system_factory_restore PHP script<\/a> to block out all the authentication checks. To be clear, this developer did not delete the authentication checks, but simply added slash marks ahead of the code to prevent it from running.<\/p>\n<p><code>function get($urlPath, $queryParams=null, $ouputFormat=\"xml\"){<br \/>\/\/ if(!authenticateAsOwner($queryParams))<br \/>\/\/ {<br \/>\/\/ header(\"HTTP\/1.0 401 Unauthorized\");<br \/>\/\/ return;<br \/>\/\/ }\u00a0<\/code><\/p>\n<p>In a conversation with <em>Ars Technica<\/em>, security expert and CEO of Rumble HD Moore stated that \u201cthe vendor commenting out the authentication in the system restore endpoint really doesn\u2019t make things look good for them \u2026 It\u2019s like they intentionally enabled the bypass.\u201d Even more damning is the fact that this hacker triggered factory resets with an XML request, which would require prior knowledge of the My Book Live system or outstandingly good guesswork.<\/p>\n<p>But that\u2019s not all. Most of the devices hit with the factory reset exploit had already fallen victim to a hacking attempt. A recent Western Digital <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/redirect.viglink.com\/?key=204a528a336ede4177fff0d84a044482&amp;u=https%3A%2F%2Fwww.westerndigital.com%2Fsupport%2Fproductsecurity%2Fwdc-21008-recommended-security-measures-wd-mybooklive-wd-mybookliveduo\">blog post<\/a> states that hackers used CVE-2018-18472, a three-year-old exploit, to gain <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/www.wizcase.com\/blog\/hack-2018\/\">full administrative access<\/a> over My Book Live drives. This exploit lets hackers to run high-level commands on drives and view or modify files.<\/p>\n<p>Interestingly, the CVE-2018-18472 exploit was password-protected by a hacker. Western Digital says that it was used to spread .<a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/www.virustotal.com\/gui\/file\/227fe3d0435a53416cf2eeb08b197a4bb671f9395047eab2ee437ae48ff80489\/detection\">nttpd,1-ppc-be-t1-z<\/a>, a PowerPC malware that turns devices into a <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/blog.netlab.360.com\/linux-ngioweb-v2-going-after-iot-devices-en\/\">Linux.Ngioweb<\/a> botnet\u2014basically a rotating proxy service that can hide cybercriminals\u2019 identities or leverage DDoS attacks.<\/p>\n<p>Western Digital says that it doesn\u2019t know why hackers would exploit the CVE-2018-18472 <em>and<\/em> factory reset vulnerabilities back-to-back. It certainly seems counterintuitive; why would you quietly build a botnet just to create a massive scandal and push My Book Live users to buy a new NAS device?<\/p>\n<p>The conclusion made by <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/censys.io\/blog\/cve-2018-18472-western-digital-my-book-live-mass-exploitation\/\">Censys<\/a> and <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/arstechnica.com\/gadgets\/2021\/06\/hackers-exploited-0-day-not-2018-bug-to-mass-wipe-my-book-live-devices\/\"><em>Ars Technica<\/em><\/a> seems the most plausible\u2014a hacker ran the factory reset exploit to sabotage the growing botnet. Maybe the hackers are rivals, although this whole thing could have been a coincidence. Who knows, maybe someone in a Discord chat or forum announced that My Book Live devices haven\u2019t been updated since 2015, leading two hackers to run independent attacks within the same timeframe.<\/p>\n<p>If you\u2019re a My Book Live user, please disconnect your drive from the internet and never use it as a remote storage device ever again. Newer NAS devices, including those from Western Digital, have security features that are actually up to date.<\/p>\n<p><small>Source: <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/arstechnica.com\/gadgets\/2021\/06\/hackers-exploited-0-day-not-2018-bug-to-mass-wipe-my-book-live-devices\/\">Ars Technica<\/a><\/small>\n<\/div>\n<p><script>\nsetTimeout(function(){\n  !function(f,b,e,v,n,t,s)\n  {if(f.fbq)return;n=f.fbq=function(){n.callMethod?\n  n.callMethod.apply(n,arguments):n.queue.push(arguments)};\n  if(!f._fbq)f._fbq=n;n.push=n;n.loaded=!0;n.version='2.0';\n  n.queue=[];t=b.createElement(e);t.async=!0;\n  t.src=v;s=b.getElementsByTagName(e)[0];\n  s.parentNode.insertBefore(t,s)}(window, document,'script',\n  'https:\/\/connect.facebook.net\/en_US\/fbevents.js');\n  fbq('init', '1137093656460433');\n  fbq('track', 'PageView');\n  },3000);\n<\/script><\/p>\n<blockquote><p><strong><span style=\"color: #ff6600;\">If you liked the article, do not forget to share it with your friends. Follow us on\u00a0<span style=\"color: #ff0000;\"><a style=\"color: #ff0000;\" href=\"https:\/\/news.google.com\/publications\/CAAqBwgKMLG0nwswvr63Aw\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">Google News<\/a><\/span>\u00a0too, click on the star and choose us from your favorites.<\/span><\/strong><\/p><\/blockquote>\n<blockquote>\n<p style=\"text-align: center;\">For forums sites go to <span style=\"color: #ff9900;\"><a style=\"color: #ff9900;\" href=\"https:\/\/forum.buradabiliyorum.com\/\" target=\"_blank\" rel=\"noopener\">Forum.BuradaBiliyorum.Com<\/a><\/span><\/strong><\/p>\n<\/blockquote>\n<blockquote>\n<p style=\"text-align: center;\"><strong>If you want to read more like this article, you can visit our <span style=\"color: #ff9900;\"><a style=\"color: #ff9900;\" href=\"https:\/\/en.buradabiliyorum.com\/technology\/\" target=\"_blank\" rel=\"noopener\">Technology category.<\/a><\/span><\/strong><\/p>\n<\/blockquote>\n<p><span style=\"color: black;\"><a style=\"color: #ff9900;\" href=\"https:\/\/www.reviewgeek.com\/90545\/western-digital-removed-code-that-would-have-prevented-global-my-book-wiping\/\" target=\"_blank\" rel=\"noopener\">Source<\/a><\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>&#8220;#Western Digital Removed Code That Would Have Prevented Global My Book Wiping \u2013 Review Geek&#8221; Western Digital A Western Digital developer removed code that would have prevented last week\u2019s mass wiping of My Book Live storage drives, according to a report from Ars Technica. A hacker exploited this change in code, likely to disrupt another&#8230;<\/p>\n","protected":false},"author":1,"featured_media":286663,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/www.reviewgeek.com\/p\/uploads\/2021\/06\/0bb2a580.png","fifu_image_alt":"","footnotes":""},"categories":[18],"tags":[],"class_list":["post-286662","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-technology"],"_links":{"self":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/posts\/286662","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/comments?post=286662"}],"version-history":[{"count":0,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/posts\/286662\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/media\/286663"}],"wp:attachment":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/media?parent=286662"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/categories?post=286662"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/tags?post=286662"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}