Remote-access Guide

my book live duo remote access fail

by Van Lebsack Published 2 years ago Updated 1 year ago
image

What is the Western Digital my book Live Duo vulnerability?

"Western Digital has determined that some My Book Live and My Book Live Duo devices are being compromised through exploitation of a remote command execution vulnerability," the company said. "In some cases, the attackers have triggered a factory reset that appears to erase all data on the device."

What happened to my book Live and my book Live Duo?

In an advisory published June 24, the hardware vendor said that My Book Live and My Book Live Duo network-attached storage (NAS) devices are being remotely wiped through factory resets, leaving users at risk of losing all of their stored data.

Do I need to disconnect My my Book Live from the Internet?

At this time, we recommend you disconnect your My Book Live and My Book Live Duo from the Internet to protect your data on the device. Reports of the issue emerged on Thursday after owners of the NAS devices took to Western Digital's support forums to complain.

What is MyMy book Live and how was it affected?

My Book Live devices are thought to be the only products involved in this widespread attack. WD cloud services, firmware update systems, and customer information is not believed to have been compromised. Western Digital is urging customers to pull their devices from the internet as quickly as possible.

image

Is WD Mybook live still supported?

We are here to help . Although this product family is no longer sold or supported by Western Digital, we know some of our customers have been impacted and we want to help. If you have lost your data as a result of these attacks, we will provide data recovery services which will be available beginning in July.

How do I protect my book live?

Fix Your WD My Book Live in 3 Easy StepsDisable Auto Updates.Disable Remote Access.Remove Your NAS's Access to the Gateway.

How do I connect to my WD My Book Live?

How to connect My Book Live with WIndows 10Open your file browser.In the Network pane under Storage section, you should see your My Book Live device.RIGHT click that icon, select Open option.A file browser will appear, you now should have access to your My Book Live storage.

How do I recover data from WD My Book Live Duo?

Steps to recover data from factory reset or hacked WD MyBook devices:Connect the WD MyBook Live hard drive to a Windows PC using the steps described earlier.Download and run Stellar Data Recovery Professional software on the system.Select 'All Data' or the specific type of files you wish to recover. Click Next.

Can I connect WD My Book Live directly to computer?

It is possible to connect the MyBookLive to the computer directly and use it from the computer but you would not be able to see the unit from other computers on the networks because you would have to share the drive in a way that it is visible on other devices even when the unit its connected directly to your computer.

Where is reset button on WD My Book?

Turn around the drive and locate the "Reset" button on the back panel of the unit. It is a recessed button inside a small hole.

How do I access my external hard drive book?

How to Use a My Book External Hard DriveInsert the My Book power adapter into the back of the hard drive, and plug the other end into a standard electrical outlet. ... Connect the My Book external hard drive to your PC computer using a USB cable.Open the "Start" menu and click on the "My Computer" icon.More items...

How do I access my WD network drive?

Head to the File Explorer and locate your WD Cloud drive. It should be called WDMyCloud. Right-click on the public folder, then select the map network drive option. Choose an available letter from the drive list (drop-down), ensuring to tick the box that says Reconnect at login.

How does My Book Live work?

It plugs into computers, typically through USB. The affected model, known as My Book Live, uses an Ethernet cable to connect to a local network. From there, users can remotely access their files and make configuration changes through Western Digital cloud infrastructure.

How do I transfer files from My Book Live?

Go to MY PC.Right click on Mybook live and Open it rather than double click it.It asks for your user name and password. After you sign in ( if you remember them ) the folders appear with a green handle.You can open them and paste your files onto them.

How do I register my WD Passport for warranty?

All you have to do is:Go to WD support portal and sign in or register an account if you don't have one.Next, register your product if you haven't done so when you first purchased it.Once your product is registered, go to WD Product Support and under RMA click “create”.More items...•

How do I access My Book Live on my iPhone?

1:152:01My Book Live Access Your Digital Life from Anywhere (English) - YouTubeYouTubeStart of suggested clipEnd of suggested clipUsing your iPhone iPod Touch iPad. Or an Android device. It's WD photos WD photos is a free app thatMoreUsing your iPhone iPod Touch iPad. Or an Android device. It's WD photos WD photos is a free app that you can download. And it accesses all the photos that are stored on your home network drive.

What is Western Digital urging customers to do?

Western Digital is urging customers to pull their devices from the internet as quickly as possible.

Is My Book Live compromised?

WD cloud services, firmware update systems, and customer information is not believed to have been compromised.

Is Western Digital urging legacy My Book owners to unplug their devices from the internet without delay?

Western Digital is urging legacy My Book owners to unplug their devices from the internet without delay following a series of remote attacks.

Qualifying Products

The following models of My Book Live and My Book Live Duo products from Western Digital:

Eligibility Requirements

The following requirements must be met in order to be eligible for this DRS Offer:

Turnaround Time

The duration for the Data Recovery to receive, process, and ship a physical drive back to the customer, or send a communication that no data could be recovered may vary. Customers should expect an outcome typically within two to six weeks of sending in their drive to the DRS vendor.

When did WD drop My Book Live?

Launched in 2011, WD dropped support for the My Book Live/Live Duo four years later. It's quite possible that the 'threat actor' exploited a vulnerability that remains unpatched to this day. Despite being discontinued in 2015, the drives can still be found for purchase online. Users looking for this type of external storage typically expect the hardware to fail first, however, compromised software can be equally damaging when it comes to cloud-connected drives.

What is the second vulnerability in WD?

The second vulnerability allowed for factory resetting the drive without authentication. Introduced as part of a firmware update in April 2011, WD says that a refactor of the authentication logic resulted in vulnerable code. Essentially, the user authentication check required for a factory reset had been disabled, followed by a failure to add the correct authentication type in the drives' config file.

Does WD have a security feature for My Book Live?

WD has posted recommended security measuresfor the My Book Live/Live Duo drives following user complaints of remote factory reset and data wipes. The company's investigation has discovered multiple vulnerabilities, including a command injection exploit that remotely let attackers run arbitrary code with root privileges on drives with remote access enabled. Some drives were also infected with a trojan binary, which has been sampled for further analysis.

Is WD advising owners to unplug their drives from the internet?

Since the threat is still active, WD is advising owners to unplug their drives from the internet as it investigates the incident. WD has posted recommended security measures for the My Book Live/Live Duo drives following user complaints of remote factory reset and data wipes.

How Can A Vulnerability of the WD My Book Live Not Be Patching in a Firmware Update?

As previously mentioned, the WD My Book Live and My Book Live Duo were some of their earliest real NAS releases, as far back as 2010. Although these systems received numerous updates, the final update for this system was officially issued in 2015 (see below)

Can The Lost Data on the WD My Book Live and My Book Live Duo Be Recovered?

As this has been a format conducted on the system as a whole, it makes the recovery of data on a Factory Reset/Wipred WD My Book Live very difficult! In previous cases of malware encryption or malicious data destruction, many users have taken advantage of the tremendously useful PhotoRec tool (previously featured in the QNAP Qlocker Recovery guides). PhotoRec is a file data recovery software designed to recover lost files including video, documents and archives from hard disks (as well as legacy storage media like CD-ROMs) and memory cards. PhotoRec ignores the file system and goes after the underlying data, so it will still work even if your media’s file system has been severely damaged or reformatted. However, this is by no means full proof and does require a little more technical knowledge than many might have (with interfacing with the NAS in a software-accessible way being the first major hurdle). Here is an example of a PhotoRec recovery guide, but we are hoping quite soon for a more WD My Book Live specific guide with surface shortly.

image
A B C D E F G H I J K L M N O P Q R S T U V W X Y Z 1 2 3 4 5 6 7 8 9