Dad On Retire
  • About Us
  • Contact Us
  • Privacy Policy
  • Terms & Conditions
  • Email Whitelisting
  • Economy
  • Editor’s Pick
  • Investing
  • Stock
No Result
View All Result
  • Economy
  • Editor’s Pick
  • Investing
  • Stock
No Result
View All Result
Dad On Retire
No Result
View All Result
Home Editor's Pick

Hackers exploited 0-day, not 2018 bug, to mass-wipe My Book Live devices [Updated]

by
June 30, 2021
in Editor's Pick
0
0
SHARES
3
VIEWS
Share on FacebookShare on Twitter

Enlarge (credit: Getty Images)

Update 6/29/2021, 9:00 PM: Western Digital has published an update that says the company will provide data recovery services starting early next month. My Book Live customers will also be eligible for a trade-in program so they can upgrade to My Cloud devices. A spokeswoman said the data recovery service will be free of charge.

The company also provided new technical details about the zeroday, which is now being tracked as CVE-2021-35941. Company officials wrote:

We have heard concerns about the nature of this vulnerability and are sharing technical details to address these questions. We have determined that the unauthenticated factory reset vulnerability was introduced to the My Book Live in April of 2011 as part of a refactor of authentication logic in the device firmware. The refactor centralized the authentication logic into a single file, which is present on the device as includes/component_config.php and contains the authentication type required by each endpoint. In this refactor, the authentication logic in system_factory_restore.php was correctly disabled, but the appropriate authentication type of ADMIN_AUTH_LAN_ALL was not added to component_config.php, resulting in the vulnerability. The same refactor removed authentication logic from other files and correctly added the appropriate authentication type to the component_config.php file.

The post added:

Read 26 remaining paragraphs | Comments

Previous Post

Microsoft digitally signs malicious rootkit driver

Next Post

Musk aims to cut Starlink user terminal price from $500 to as low as $250

Next Post

Musk aims to cut Starlink user terminal price from $500 to as low as $250

Get the daily email that makes reading the news actually enjoyable. Stay informed and entertained, for free.
Your information is secure and your privacy is protected. By opting in you agree to receive emails from us. Remember that you can opt-out any time, we hate spam too!
  • Trending
  • Comments
  • Latest

VPN servers seized by Ukrainian authorities weren’t encrypted

July 26, 2021

With help from Google, impersonated Brave.com website pushes malware

July 31, 2021

Prebiotics consumption expands in food and beverage applications – key nutritional benefits drive the ingredient demand

June 11, 2021

With help from Google, impersonated Brave.com website pushes malware

July 31, 2021

The 40 Weirdest (And Best) Charts We Made In This Long, Strange Year

0

How U.S. Government Paper Currency Began, and How Private Banknotes Ended

0

Covid Inside Rural India

0

Reply to “Reply to Whitehead” by Desvousges, Mathews and Train: (4) My treatment of the weighted WTP is biased in favor of the DMT (2015) result/conclusion

0
Wife of Connecticut Democrat involved in COVID fraud scheme gets 6 months

Wife of Connecticut Democrat involved in COVID fraud scheme gets 6 months

March 24, 2023
Alabama lawmakers vote to rein in use of good behavior incentives

Alabama lawmakers vote to rein in use of good behavior incentives

March 24, 2023
18 state AGs urge Senate to reject Nancy Abudu’s judicial nomination: ‘She is an activist’

18 state AGs urge Senate to reject Nancy Abudu’s judicial nomination: ‘She is an activist’

March 24, 2023
Maine chief justice says case backlogs ‘hurt her heart’

Maine chief justice says case backlogs ‘hurt her heart’

March 24, 2023

Recent News

Wife of Connecticut Democrat involved in COVID fraud scheme gets 6 months

Wife of Connecticut Democrat involved in COVID fraud scheme gets 6 months

March 24, 2023
Alabama lawmakers vote to rein in use of good behavior incentives

Alabama lawmakers vote to rein in use of good behavior incentives

March 24, 2023
18 state AGs urge Senate to reject Nancy Abudu’s judicial nomination: ‘She is an activist’

18 state AGs urge Senate to reject Nancy Abudu’s judicial nomination: ‘She is an activist’

March 24, 2023
Maine chief justice says case backlogs ‘hurt her heart’

Maine chief justice says case backlogs ‘hurt her heart’

March 24, 2023

Disclaimer: DadOnRetire.com, its managers, its employees, and assigns (collectively "The Company") do not make any guarantee or warranty about what is advertised above. Information provided by this website is for research purposes only and should not be considered as personalized financial advice. The Company is not affiliated with, nor does it receive compensation from, any specific security. The Company is not registered or licensed by any governing body in any jurisdiction to give investing advice or provide investment recommendation. Any investments recommended here should be taken into consideration only after consulting with your investment advisor and after reviewing the prospectus or financial statements of the company.

  • About Us
  • Contact Us
  • Privacy Policy
  • Terms & Conditions
  • Email Whitelisting

Copyright © 2022 DadOnRetire. All Rights Reserved.

No Result
View All Result
  • Economy
  • Editor’s Pick
  • Investing
  • Stock

Copyright © 2022 DadOnRetire. All Rights Reserved.