MyBook Users Urged to Unplug Devices from Internet
krebsonsecurity.com
krebsonsecurity.com
Bridges have very long useful lifespans wih massive up front cost, after which they're just replaced, and that's fine. Elevators have seemingly rigorous standards they need to hold up, but also there are companies and people specialized to repair them according to standards.
This case of MyBook seems to be another case of vulnerability caused by C. Actually most CVE vulnerabilities happens due programming mistakes that the C language makes easier to make such as to buffer overflow, out-of-bounds array access, undefined behaviour, use-after-free and etc.
BTW I am not that sure about respect for engineers at least where I live. Medical doctors are looked up to, yes, but engineers are considered "normal people", as are software developers.
I, for one, would love it if there was some way to set agreed-upon software standards with a governing body set up to audit them.
But, it’s voluntary now. You don’t see programmers making the decision to implement certain features… it’s driven by business and management.
>[...], warning that malicious hackers are remotely wiping the drives using a previously unknown critical flaw [...]
This flaw was reported in 2018. Later in the article it even states as much
>Examine the CVE attached to this flaw and you’ll notice it was issued in 2018. [...]
Am I misinterpreting something here? I feel like I am; I'm pretty tired. Or, perhaps, a slight goof in the opening paragraph.
-----
Western Digital’s brief advisory includes a link to an entry in the National Vulnerability Database for CVE-2018-18472. The NVD writeup says Western Digital WD My Book Live and WD My Book Live Duo (all versions) have a root Remote Command Execution bug.
“It can be triggered by anyone who knows the IP address of the affected device, as exploited in the wild in June 2021 for factory reset commands,” NVD wrote.
Examine the CVE attached to this flaw and you’ll notice it was issued in 2018. The NVD’s advisory credits VPN reviewer Wizcase.com with reporting the bug to Western Digital three years ago, back in June 2018.
In some ways, it’s remarkable that it took this long for vulnerable MyBook devices to be attacked: The 2018 Wizcase writeup on the flaw includes proof-of-concept code that lets anyone run commands on the devices as the all-powerful “root” user.
Western Digital’s response at the time was that the affected devices were no longer supported and that customers should avoid connecting them to the Internet. That response also suggested this bug has been present in its devices for at least a decade.
“The vulnerability report CVE-2018-18472 affects My Book Live devices originally introduced to the market between 2010 and 2012,” reads a reply from Western Digital that Wizcase posted to its blog. “These products have been discontinued since 2014 and are no longer covered under our device software support lifecycle. We encourage users who wish to continue operating these legacy products to configure their firewall to prevent remote access to these devices, and to take measures to ensure that only trusted devices on the local network have access to the device.”
Just don't go and expose all your stuff to the internet.
"As of May 15, 2021 the Seagate Access feature of Seagate NAS products will be discontinued. Specifically, the Seagate Access service, Seagate Access through Seagate Sdrive, Seagate Access through Seagate Media App, and Seagate MyNAS will no longer be available after May 15, 2021 at midnight Central European Time. Additionally, customer support for the Seagate Access service will also be discontinued.
The removal of this service means that access to all Seagate NAS devices via the Seagate Access web portal, Seagate Sdrive, Seagate Media App, and Seagate MyNAS will no longer function. However, you will not lose remote access to the files on your Seagate NAS since it can be configured and accessed using the FTP/SFTP service. Similarly, your Seagate NAS will not change for standard network access within the home or office network using common network protocols on macOS and Windows.
Please know that we remain grateful for your purchase of a Seagate NAS and hope you continue to enjoy it despite this change to remote access via Seagate Access, Sdrive, Seagate Media App and MyNAS.
For questions, please contact https://www.seagate.com/contacts/.
Cordially,
The Seagate NAS Team"
Just don’t go storing your money in a bank.
An authenticated, stored XSS on the admin portal of a CMS? Meh. A root remote code exploit on a device which is commonly found plugged into the internet? Definitely.
If I was an user, I could patch it up myself (and I'm sure most people here would be able to, we're on HN).
You're going to rule out all WD products (even the SATA/USB/NVMe, non-networked variety) because their NAS line had 0days? That's like swearing to never buy any philips lightbulbs if their IOT lightbulbs got hacked. I guess if you want to do this to punish WD, that's your prerogative, but it's not really anything rooted in rationality.
And, I dunno, if that's how they conduct business I'm not sure I want to try their other stuff and find out what corners they cut there.
This vulnerability was reported in 2018 and remains unfixed, if I'm understanding correctly.
No, I'm ruling it out because of how they responded to it.