Stories
Slash Boxes
Comments

SoylentNews is people

posted by Fnord666 on Wednesday September 19 2018, @08:40PM   Printer-friendly
from the you-get-a-cloud-and-you-get-a-cloud-and-... dept.

'I am admin' bug turns WD's My Cloud boxes into Everyone's Cloud:

Miscreants can potentially gain admin-level control over Western Digital's My Cloud gear via an HTTP request over the network or internet.

Researchers at infosec shop Securify revealed today the vulnerability, designated CVE-2018-17153, which allows an unauthenticated attacker with network access to the device to bypass password checks and login with admin privileges.

This would, in turn, give the scumbag full control over the NAS device, including the ability to view and copy all stored data as well as overwrite and erase contents. If the box is accessible from the public internet, it could be remotely pwned, it appears. Alternatively, malware on a PC on the local network could search for and find a vulnerable My Cloud machine, and compromise it.

According to Securify, the flaw itself lies in the way My Cloud creates admin sessions that are attached to an IP address. When an attacker sends a command to the device's web interface, as an HTTP CGI request, they can also include the cookie username=admin – which unlocks admin access.

[...] The team has posted a proof-of-concept exploit showing how the bug could be targeted with a few lines of code.

Securify said it reported the vulnerability to Western Digital back in April, but did not receive a response. Now, some five months later, they are finally disclosing the bug.

Western Digital did not return a Reg request for comment on the matter.


Original Submission

 
This discussion has been archived. No new comments can be posted.
Display Options Threshold/Breakthrough Mark All as Read Mark All as Unread
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
  • (Score: 2, Informative) by Anonymous Coward on Wednesday September 19 2018, @10:34PM (3 children)

    by Anonymous Coward on Wednesday September 19 2018, @10:34PM (#737279)

    I'm pretty sure, in these sad times, purchasing and installing something in your house doesn't make it "yours". If you're not in control of the software it runs your "myCloud" still belongs to whoever is.

    Starting Score:    0  points
    Moderation   +2  
       Informative=1, Touché=1, Total=2
    Extra 'Informative' Modifier   0  

    Total Score:   2  
  • (Score: 0) by Anonymous Coward on Wednesday September 19 2018, @11:13PM (2 children)

    by Anonymous Coward on Wednesday September 19 2018, @11:13PM (#737290)

    The My Cloud box runs Linux and can be accessed via the command line. What more do you want?

    • (Score: 0) by Anonymous Coward on Thursday September 20 2018, @12:44AM (1 child)

      by Anonymous Coward on Thursday September 20 2018, @12:44AM (#737317)

      No backdoors, mmk?!

      • (Score: 0) by Anonymous Coward on Thursday September 20 2018, @01:05AM

        by Anonymous Coward on Thursday September 20 2018, @01:05AM (#737323)

        If you enable remote access you opened the backdoor.