How I got a root shell in my NAS, 0day inside
blog.pentbox.net
blog.pentbox.net
Unless an unprivileged, remote attacker can also get a shell on the box, it's not a big deal.
And this guy reports the means of getting root on his own device as a "defect" to be "fixed"? That is disgraceful.
You can make a NAS from generic PC equipment, altho it takes some work to get a lot of convenient features.
http://sourceforge.net/projects/qosgpl/
http://wiki.qnap.com/wiki/Debian_Installation_On_QNAP
http://www.cyrius.com/debian/kirkwood/qnap/
with decent Debian solutions:
Went to "Terminal" in the web control panel.
Enabled the SSH service.
SSHed in as root.
This is an off-the-shelf device, not an OS I installed myself.
http://www.support.dlink.com/emulators/dns320/200/login.html
I love posts like this, well written and easy to understand. This show that finding vulnerabilities is not magic for some ubergeeks but straightforward analysis with a bit of trial and error.