slshn
December 27, 2021, 10:50am
1
hello guys. I bought a blank device. I inserted a 5 terabyte disk with the original operating system installed in it. After running the driver, I turned off the software update check from the settings.The system is running smoothly now. I found this patch.
If you have a Western Digital My Book Live or My Book Duo Live, your data is at risk. Here's what you need to do to protect it.
Est. reading time: 6 minutes
#!/bin/bash
echo "> weekend_destroyer_patch: patch for 0 day sploit by"
echo " Pedro Ribeiro (@pedrib1337 | pedrib@gmail.com)"
echo " Radek Domanski (@RabbitPro | radek.domanski@gmail.com)"
echo "v0.1, released 25/02/2021"
echo ""
echo "> Patching vulnerability and restarting httpd..."
# Yup, this is the only POST with USER_AUTH in the whole file, so this is safe
sed -i 's/<post>USER_AUTH<\/post>/<post>ADMIN_AUTH<\/post>/' /var/www/rest-api/api/System/config/module.config.xml
killall httpd
sleep 1
httpd -f /usr/local/apache2/conf/httpd.conf -k graceful &
sleep 1
echo "> Vulnerability patched. Don't forget to run this script at every reboot!"
Hi @slshn ,
We deeply apologize for the inconvenience caused.
Please be informed that WD does not recommend taking out the internal drive from the enclosure.
We request you to please contact any third-party data recovery services