MacMusic  |  PcMusic  |  440 Software  |  440 Forums  |  440TV  |  Zicos
data
Search

Buggy Software in Popular Connected Storage Drives Can Let Hackers Read Private Data

Friday October 19, 2018. 10:11 PM , from Slashdot
Security researchers have found flaws in four popular connected storage drives that they say could let hackers access a user's private and sensitive data. From a report: The researchers Paulos Yibelo and Daniel Eshetu said the software running on three of the devices they tested -- NetGear Stora, Seagate Home and Medion LifeCloud -- can allow an attacker to remotely read, change and delete data without requiring a password. Yibelo, who shared the research with TechCrunch this week and posted the findings Friday, said that many other devices may be at risk. The software, Hipserv, built by tech company Axentra, was largely to blame for three of the four flaws they found. Hipserv is Linux-based, and uses several web technologies -- including PHP -- to power the web interface. But the researchers found that bugs could let them read files on the drive without any authentication. It also meant they could run any command they wanted as 'root' -- the built-in user account with the highest level of access -- making the data on the device vulnerable to prying eyes or destruction.

Read more of this story at Slashdot.
rss.slashdot.org/~r/Slashdot/slashdot/~3/X-PTtMPVIbg/buggy-software-in-popular-connected-storage-dri...
News copyright owned by their original publishers | Copyright © 2004 - 2024 Zicos / 440Network
Current Date
Apr, Sat 27 - 01:47 CEST