SECURITY BUG! Can access files from within private shares publicly!

Hello, any news about the fix??

Sorry, i just figured out that this was only posted last wednesday!! I just hope a fix is released soon.

Don’t have a clue. Ask BBBBBrandon.

hashkar wrote:

Hello, any news about the fix??

 

 

Sorry, i just figured out that this was only posted last wednesday!! I just hope a fix is released soon.

We have a fix for this already.  We are doing regression testing and will be releasing very soon.  This is very high priority.

Cool.  Thanks for the update.  So hopefully . . .

  1. Computers on the LAN will connect with Samba and not WebDAV.
  2. WebDAV, internally, on the MyBook Live itself will honour the security settings set-up by the user/owner and this  applies to LAN and WAN connections.
  3. If someone is irresponsible and puts their MyBook Live on the router’s DMZ, that WebDAV will not be accessible to anyone that’s not on the LAN’s subnet and can only be accessed by WD2GO for the purpose of providing remote access to files.  (Same goes for Linux’s native NFS as that’ll also be exposed to the Internet when on the DMZ.)

Plus…  The regression testing will include testing to see if this update is liable to brick a MyBook Live.

A slight addition.  Is there a fix for the Dashboard/Web UI vanishing after a reboot? When this happens then there is no way to connect to the web server within the MyBook Live.

Hope this also gets fixed:

http://community.wdc.com/t5/My-Book-Live/BUG-MyBook-Live-overidden-static-DNS-entries-MyBookLive-02-02-02/td-p/274698

This was fix and released, reference the following post:

http://community.wdc.com/t5/News-Announcements/New-Release-Firmware-Version-02-03-01-024-for-My-Book-Live-10-25/m-p/281988#M219

1 Like

Awesome. Thank-you.  :smiley: