Disconnect WD My Book Live NAS from the Internet immediately
#1
Exclamation 
Quote:
[Image: wd-my-book-remote-wipe-featured.jpg]

Some network-attached storage from WD has been reset to factory settings, wiping users’ data. Here’s how to protect your WD NAS.

Many Western Digital My Book users are complaining that their devices have been reset to factory defaults. Worse, all of the information on them suddenly disappeared. Whether the cause of the incident was a technical failure or an attack is not yet clear, but we recommend all owners disconnect their My Book Live and My Book Live Duo drives from the Internet, at least until more details from the vendor are available.

What happened to WD My Book Live drives

Log analysis shows that devices received a remote command to reset their settings to factory default, according to Bleeping Computer. That procedure includes a complete wipe of the affected disks.

A message on Western Digital’s support site says the devices were compromised through a remote code execution (RCE)–class vulnerability. WD support suspects CVE-2018-18472, reported in 2018. Any malefactor who knows the exact IP address of a WD My Book Live device can exploit the vulnerability.

Experts assigned the vulnerability a severity rating of 9.8 — critical.

Why My Book Live drives were vulnerable

WD My Book Live drives are network-attached storage (NAS) devices. Popular among home users and small businesses, they support remote access to stored data, as well as backup creation. To work as intended, the devices need a stable Internet connection with access to the My Book Live cloud service.

According to Western Digital‘s message, the last time My Book Live and My Book Live Duo devices received firmware updates was in 2015, well before developers could have taken the CVE-2018-18472 vulnerability into account.

Western Digital continues to investigate the incident and promises to release new details shortly.

How to protect data on My Book Live devices

First, disconnect your My Book Live or My Book Live Duo from the Internet as soon as possible. If using router settings to do so is problematic, disconnect the drive from the network physically and then configure the router correctly.

After that, wait for news from Western Digital. The company may find a way to close the vulnerability, or even to restore lost data.

In general, we recommend using Internet-isolated solutions for creating and storing backups of important information. The isolation will prevent you from accessing backups remotely, but it will also prevent anyone else from accessing them remotely.

Some security solutions help you automate backup creation.
...
Continue Reading
Reply


Forum Jump:


Users browsing this thread: 1 Guest(s)
[-]
Welcome
You have to register before you can post on our site.

Username/Email:


Password:





[-]
Recent Posts
QOwnNotes
26.4.0  LanguageT...Kool — 08:39
Surfshark VPN : Award-winning VPN servi...
Surfshark Apps Ver...jasonX — 04:41
Surfshark VPN : Award-winning VPN servi...
Surfshark launches...jasonX — 03:43
ESET 19.1.12.0
Changes in 19.1.12...harlan4096 — 14:49
Vivaldi 7.9 Build 3970.47
Vivaldi 7.9 Build ...harlan4096 — 07:31

[-]
Birthdays
Today's Birthdays
avatar (41)alapesihy
Upcoming Birthdays
avatar (45)wapedDow
avatar (49)oapedDow
avatar (42)Sanchowogy
avatar (46)MeighGoask
avatar (47)creatralGuelm
avatar (38)procnipsut
avatar (44)accenwibly
avatar (41)ahyvily
avatar (38)urumahiz
avatar (44)techlignub
avatar (43)Stevenmam
avatar (50)onlinbah
avatar (50)fuspeukChark
avatar (44)werriewWaiNg
avatar (38)Freemanleo
avatar (48)cticigges
avatar (50)ecoFit
avatar (44)soccejeS
avatar (43)cdoubapKit
avatar (38)lystraPonia
avatar (31)smith8395john
avatar (51)steakelask
avatar (45)Termoplenka
avatar (43)bycoPaist
avatar (49)pieloKat
avatar (43)ilyagNeexy
avatar (51)donitascene
avatar (51)burntLaw
avatar (41)MrDoorsskibheeds
avatar (51)Toligo
avatar (46)Rodneykak
avatar (49)tradeSmode
avatar (39)vemedProkbior
avatar (38)RobertUtelt
avatar (46)JamesZic
avatar (43)Sanfordbup
avatar (38)Der.Reisende
avatar (36)Kiran78

[-]
Online Staff
There are no staff members currently online.

>