Your hard disk may have been cracked by hackers and used for mining. Recently, the sudden automatic formatting is because another wave of hackers want to "grab territory" with them.


Last Thursday, a large number of Western data my book mobile hard disk user data was remotely cleared event caused public concern. As Western Digital officials asked users to unplug the cable, things began to get a bit chaotic.


This week, another security official revealed that there are still new loopholes in these hard disks.

After submitting these findings to Western data, the security personnel received the following reply: "we can confirm that, at least in some cases, the attacker exploited a command injection vulnerability (cve-2018-18472), followed by a factory reset vulnerability. It is not clear why attackers exploit these two vulnerabilities. We will request CVE for factory setup recovery vulnerability and will update our bulletin to include this information. "


The vulnerability is protected by a password


This discovery raises a thorny question: if hackers have obtained full root access by using cve-2018-18472, what do they need for the second security vulnerability? At present, there is no clear answer, but based on the existing evidence, abdine put forward a plausible theory, that is, a hacker first used cve-2018-18472 to attack, while another competitor then used another loophole to try to seize control of those devices that have been attacked.

The attacker used the code execution ability provided by cve-2018-18472 to modify the code named language in my book live stack_ Configuration.php file, which is the location of the vulnerability. According to the recovery file, modify the code and add the following lines:


This change prevents anyone from exploiting the vulnerability without a password corresponding to the encrypted SHA1 hash 56f650e16801d38f47bb0eeac39e21a8142d7da1. It turns out that the hash password is p $efx3tqwoubfc% B% R $k @.


Another modified language recovered from the hacked device_ The configuration.php file uses different passwords, corresponding to the hash value 05951edd7f05318019c4cfafab8e567afe7936d4. Hackers use the third hash value b18c379fd377b51b7925b2b68ff818cc9115a47 to password protect a separate file called accessdenied.php. This is probably to prevent the western data from affecting the language_ Configuration.


So far, attempts to crack these two hashes have not been successful.

According to the western data bulletin, some of my book live hard disks were broken by hackers through cve-2021-18472, infected with malicious software named. Nttpd, 1-ppc-be-t1-z. The malware runs on hardware that uses PowerPC, and my book live is such a device.

In a forum in Western Digital, a user reported that my book live, which had been hacked, had received the malware, which made the device part of a botnet called Linux. Ngioweb.


A possibility

So why do hackers who have successfully involved so many my book live devices in botnets suddenly delete everything? Why do they use undocumented authentication when they already have root privileges?


It seems that the most likely answer is that massive erasures and resets are caused by another wave of attackers, most likely a competitor trying to control a competitor's Botnet, or just to destroy it.


"As for large-scale posting to [sysem]_ factory_ We don't know the motivation of the endpoint. It may be that the botnet operators of competitors try to take over these devices or make them useless, or someone wants to destroy them in other ways. These devices may have been invaded for some time. After all, the vulnerability existed as early as 2015. " Abdine said.

Anyway, the discovery of the second vulnerability means that my book live is more insecure than you think. It may be the real reason why Western data lets all users unplug the network cable immediately - any user with these hard disks should do so immediately.






