{"id":288359,"date":"2021-06-30T17:28:36","date_gmt":"2021-06-30T14:28:36","guid":{"rendered":"https:\/\/en.buradabiliyorum.com\/western-digital-says-it-meant-to-add-code-to-prevent-my-book-live-hack-but-forgot-review-geek\/"},"modified":"2021-06-30T17:28:36","modified_gmt":"2021-06-30T14:28:36","slug":"western-digital-says-it-meant-to-add-code-to-prevent-my-book-live-hack-but-forgot-review-geek","status":"publish","type":"post","link":"https:\/\/buradabiliyorum.com\/en\/western-digital-says-it-meant-to-add-code-to-prevent-my-book-live-hack-but-forgot-review-geek\/","title":{"rendered":"#Western Digital Says It Meant to Add Code to Prevent My Book Live Hack, But Forgot \u2013 Review Geek"},"content":{"rendered":"<p><strong>&#8220;#Western Digital Says It Meant to Add Code to Prevent My Book Live Hack, But Forgot \u2013 Review Geek&#8221;<\/strong><\/p>\n<div id=\"article-content-area\">\n<figure style=\"width: 1920px\" class=\"wp-caption alignnone\"><img loading=\"lazy\" decoding=\"async\" class=\"type:primaryImage  wp-image-90180 size-full\" src=\"https:\/\/www.reviewgeek.com\/p\/uploads\/2021\/06\/0bb2a580.png?width=1200\" alt=\"Western Digital's My Book\" width=\"1920\" height=\"1080\" data-credittext=\"Western Digital\" onload=\"pagespeed.lazyLoadImages.loadIfVisibleAndMaybeBeacon(this);\" onerror=\"this.onerror=null;pagespeed.lazyLoadImages.loadIfVisibleAndMaybeBeacon(this);\"\/><figcaption class=\"wp-caption-text\"><span class=\"type:primaryImage imagecredit\">Western Digital<\/span><\/figcaption><\/figure>\n<p>You\u2019re not going to believe this. Western Digital now <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/redirect.viglink.com\/?key=204a528a336ede4177fff0d84a044482&amp;u=https%3A%2F%2Fwww.westerndigital.com%2Fsupport%2Fproductsecurity%2Fwdc-21008-recommended-security-measures-wd-mybooklive-wd-mybookliveduo\">confirms<\/a> that it disabled authentication code that should have prevented last week\u2019s My Book Live factory reset exploit. What\u2019s worse, this code was disabled in 2011 with the intent of replacing it with something better\u2014Western Digital simply forgot to paste in the new code.<\/p>\n<p>Let\u2019s backtrack a bit. Last week, My Book Live users found that their internet-connected storage drives had lost all of their data. A factory reset, triggered remotely, caused this data loss.<\/p>\n<p>Analysis by security experts has since shown that hackers were exploiting two separate My Book Live vulnerabilities at the same time; one exploit (called CVE-2018-18472) left the drives open to full remote control and was used to build a botnet, while another exploit allowed hackers to execute remote factory resets without the need for any login credentials.<\/p>\n<p>These security experts found that Western Digital had intentionally disabled factory reset authentication code, which would have forced hackers to enter login information for each My Book Live device they tried to format. A new <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/redirect.viglink.com\/?key=204a528a336ede4177fff0d84a044482&amp;u=https%3A%2F%2Fwww.westerndigital.com%2Fsupport%2Fproductsecurity%2Fwdc-21008-recommended-security-measures-wd-mybooklive-wd-mybookliveduo\">support post<\/a> from Western Digital confirms that this code was disabled in 2011 as part of a refactor\u2014basically a wide-scale upgrade to underlying code. While this refactor was correctly performed in other parts of the My Book Live system, it failed to replace the factory reset authentication code.<\/p>\n<blockquote><p>We have determined that the unauthenticated factory reset vulnerability was introduced to the My Book Live in April of 2011 as part of a refactor of authentication logic in the device firmware. The refactor centralized the authentication logic into a single file, which is present on the device as includes\/component_config.php and contains the authentication type required by each endpoint. In this refactor, the authentication logic in system_factory_restore.php was correctly disabled, but the <a href=\"https:\/\/buradabiliyorum.com\/en\/category\/download-scripts-themes-apps\/\" data-internallinksmanager029f6b8e52c=\"9\" title=\"Download Scripts &amp; Themes &amp; Apps\" target=\"_blank\" rel=\"noopener\">app<\/a>ropriate authentication type of ADMIN_AUTH_LAN_ALL was not added to component_config.php, resulting in the vulnerability. The same refactor removed authentication logic from other files and correctly added the appropriate authentication type to the component_config.php file.<\/p>\n<\/blockquote>\n<p>Western Digital goes on to clarify a few details of this attack. While security analysts suggest that a hacker exploited the factory reset vulnerability to sabotage the growing My Book Live botnet (which was enabled by the separate CVE-2018-18472 \u201cremote control\u201d exploit), Western Digital says that both attacks were often executed from a single IP address. This suggests that one hacker took advantage of both vulnerabilities, for some reason.<\/p>\n<p>Throughout this whole mess, many people have blamed My Book Live users for leaving themselves open to attack. After all, My Book Live devices haven\u2019t been updated since 2015, so, of course, they\u2019re unsafe! But in reality, My Book Live drives were vulnerable to the factory reset <em>and<\/em>\u00a0CVE-2018-18472 \u201cremote control\u201d exploits long before Western Digital ended software support.<\/p>\n<p>Western Digital says that it will offer free data recovery services and a free My Cloud device to My Book Live owners starting this July. If you\u2019re still using a My Book Live device, please unplug it and never use it again.<\/p>\n<p><small>Source: <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/redirect.viglink.com\/?key=204a528a336ede4177fff0d84a044482&amp;u=https%3A%2F%2Fwww.westerndigital.com%2Fsupport%2Fproductsecurity%2Fwdc-21008-recommended-security-measures-wd-mybooklive-wd-mybookliveduo\">Western Digital<\/a><\/small>\n<\/div>\n<p><script>\nsetTimeout(function(){\n  !function(f,b,e,v,n,t,s)\n  {if(f.fbq)return;n=f.fbq=function(){n.callMethod?\n  n.callMethod.apply(n,arguments):n.queue.push(arguments)};\n  if(!f._fbq)f._fbq=n;n.push=n;n.loaded=!0;n.version='2.0';\n  n.queue=[];t=b.createElement(e);t.async=!0;\n  t.src=v;s=b.getElementsByTagName(e)[0];\n  s.parentNode.insertBefore(t,s)}(window, document,'script',\n  'https:\/\/connect.facebook.net\/en_US\/fbevents.js');\n  fbq('init', '1137093656460433');\n  fbq('track', 'PageView');\n  },3000);\n<\/script><\/p>\n<blockquote><p><strong><span style=\"color: #ff6600;\">If you liked the article, do not forget to share it with your friends. Follow us on\u00a0<span style=\"color: #ff0000;\"><a style=\"color: #ff0000;\" href=\"https:\/\/news.google.com\/publications\/CAAqBwgKMLG0nwswvr63Aw\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">Google News<\/a><\/span>\u00a0too, click on the star and choose us from your favorites.<\/span><\/strong><\/p><\/blockquote>\n<blockquote>\n<p style=\"text-align: center;\">For forums sites go to <span style=\"color: #ff9900;\"><a style=\"color: #ff9900;\" href=\"https:\/\/forum.buradabiliyorum.com\/\" target=\"_blank\" rel=\"noopener\">Forum.BuradaBiliyorum.Com<\/a><\/span><\/strong>\n<\/p><\/blockquote>\n<blockquote>\n<p style=\"text-align: center;\"><strong>If you want to read more like this article, you can visit our <span style=\"color: #ff9900;\"><a style=\"color: #ff9900;\" href=\"https:\/\/en.buradabiliyorum.com\/technology\/\" target=\"_blank\" rel=\"noopener\">Technology category.<\/a><\/span><\/strong><\/p>\n<\/blockquote>\n<p><span style=\"color: black;\"><a style=\"color: #ff9900;\" href=\"https:\/\/www.reviewgeek.com\/90716\/wd-my-book-live-devices-have-been-vulnerable-to-factory-reset-exploit-since-2011\/\" target=\"_blank\" rel=\"noopener\">Source<\/a><\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>&#8220;#Western Digital Says It Meant to Add Code to Prevent My Book Live Hack, But Forgot \u2013 Review Geek&#8221; Western Digital You\u2019re not going to believe this. Western Digital now confirms that it disabled authentication code that should have prevented last week\u2019s My Book Live factory reset exploit. What\u2019s worse, this code was disabled in&#8230;<\/p>\n","protected":false},"author":1,"featured_media":288360,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/www.reviewgeek.com\/p\/uploads\/2021\/06\/0bb2a580.png","fifu_image_alt":"","footnotes":""},"categories":[18],"tags":[],"class_list":["post-288359","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-technology"],"_links":{"self":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/posts\/288359","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/comments?post=288359"}],"version-history":[{"count":0,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/posts\/288359\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/media\/288360"}],"wp:attachment":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/media?parent=288359"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/categories?post=288359"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/tags?post=288359"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}