Updated:07:56 AM EST Jan 19


this is ggmania.com subsite Western Digital My Cloud drives have a built-in backdoor - TechAmok

TOP STORIES

HEADLINES

2018 Was the Year of VR Headsets - Except it Wasn't :-)
20 Things Proving That Japan Lives In 3018
10 funny moments in Granny The Horror Game
The best pics on the Internet #263
Emira Kowalska aka EmiraFoods Huge Booty & More Spicy Pics
23 BRILLIANT PHONE HACKS
Ashtanga Yoga - core strength for back bends
Beautiful Taekwondo Girls
FASTEST WORKERS 2018 - God Level Experts
The Prodigy - Baby's Got A Temper (Hit Me Remix 2k19)
3 Awesome Life Hacks
Ambushed - New Chinese Action Film - Best Kungfu Martial
Emily Ratajkowski's Body Perfection
GeForce RTX 2080 Ti Now De-listed on NVIDIA's Online Store
Researchers Discover Seven New Meltdown and Spectre Attacks
This Guy Seems To Have Broken The Matrix
How A Hacker Obtained Motorola Source Code with a Few Phone Calls
Eiza Gonzalez Is An Amazing Talent!

30 MONEY-SAVING LIFE HACKS FOR GIRLS
25 BEST HACKS FOR YOUR SMARTPHONE
Best Sport Vines 2019 - January
Windows 10 Mobile Is Officially Dead
Ford Is Developing a Powerful All-Electric F-Series Truck
John Wick: Chapter 3 - Parabellum (2019 Movie) Official Trailer
Project Stream Official Gameplay Capture
Next RAZR Might be a $1,500 Foldable Smartphone
Alexis Ren Could Be The Next Queen Of Instagram
How Well Do FreeSync Monitors Work with NVIDIA GPUs?
Game of Thrones - Season 8 - Official Tease
HoloLens news incoming
YouTube Bans Dangerous Challenges and Pranks Videos
New Bluetooth Sticker Tags Powered by Ambient Radio Waves
AMD's Initial Production Run of Radeon VII Just 5,000 Pieces?
Spider-Man: Far From Home - Teaser Trailer
Apple Allegedly Replaced 11 Million Batteries
NVIDIA Releases GeForce 417.71 WHQL Drivers

Western Digital My Cloud drives have a built-in backdoor - [security]
12:11 PM EST - Jan,05 2018 - post a comment

Western Digital's network attached storage solutions have a newfound vulnerability allowing for unrestricted root access. James Bercegay disclosed the vulnerability to Western Digital in mid-2017. After allowing six months to pass, the full details and proof-of-concept exploit have been published. No fix has been issued to date.>

More troubling is the existence of a hard coded backdoor with credentials that cannot be changed. Logging in to Western Digital My Cloud services can be done by anybody using "mydlinkBRionyg" as the administrator username and "abc12345cba" as the password. Once logged in, shell access is readily available followed with plenty of opportunity for injection of commands. Owners of Western Digital NAS drives are not safe on local area networks, either. Specially crafted HTML image and iFrame tags can be used on websites to make requests to devices on a local network using predictable host names. No user interaction is required other than visiting a malicious webpage.

Affected models include My Cloud Gen 2, My Cloud EX2, My Cloud EX2 Ultra, My Cloud PR2100, My Cloud PR4100, My Cloud EX4, My Cloud EX2100, My Cloud EX4100, My Cloud DL2100 and My Cloud DL4100. A Metasploit module has also been publicly released, making is very easy for almost anyone to take advantage of Western Digital drives. It is advised to disconnected any affected drives from your local area network and block it from having Internet access until a patch can be issued.

Reportedly, anyone can log in with "mydlinkBRionyg" as the username and "abc12345cba" as the password.


Add your comment (free registrationrequired)

Short overview of recent news articles

Jan,19 2019 30 MONEY-SAVING LIFE HACKS FOR GIRLS
Jan,19 2019 25 BEST HACKS FOR YOUR SMARTPHONE
Jan,19 2019 Best Sport Vines 2019 - January
Jan,19 2019 Windows 10 Mobile Is Officially Dead
Jan,19 2019 Ford Is Developing a Powerful All-Electric F-Series Truck
Jan,18 2019 John Wick: Chapter 3 - Parabellum (2019 Movie) Official Trailer
Jan,18 2019 Project Stream Official Gameplay Capture
Jan,17 2019 Next RAZR Might be a $1,500 Foldable Smartphone
Jan,17 2019 Alexis Ren Could Be The Next Queen Of Instagram
Jan,17 2019 How Well Do FreeSync Monitors Work with NVIDIA GPUs?
Jan,16 2019 Game of Thrones - Season 8 - Official Tease
Jan,16 2019 HoloLens news incoming
Jan,16 2019 YouTube Bans Dangerous Challenges and Pranks Videos
Jan,16 2019 New Bluetooth Sticker Tags Powered by Ambient Radio Waves
Jan,16 2019 AMD's Initial Production Run of Radeon VII Just 5,000 Pieces?
Jan,15 2019 Spider-Man: Far From Home - Teaser Trailer
Jan,15 2019 Apple Allegedly Replaced 11 Million Batteries
Jan,15 2019 NVIDIA Releases GeForce 417.71 WHQL Drivers
>> News Archive <<

TechAmok - Privacy Policy        loading time:0.03secs