× NETGEAR will be terminating ReadyCLOUD service by July 1st, 2023. For more details click here.
Orbi WiFi 7 RBE973
Reply

Serious Security flaw ReadyNAS OS6 (6.2.3 - BETA2)

filippo333
Aspirant

Serious Security flaw ReadyNAS OS6 (6.2.3 - BETA2)

Hi all,
I upgraded my RN102 to firmware 6.2.3 B2 after being the victim of the nasty bug which prevents you from accessing the web interface after uninstalling an app.
I've recently noticed a very bad bugs in this firmware version:

    - The password recovery form for the NAS does not update whatsoever despite rebooting the NAS after changing the admin credentials. The old recovery information still works and does not accept the updated information.

    - I am unable to reset the admin password, despite making changes to the credentials they don't seem to have any affect on logging in to the local web interface.

    - The only way to login to the web interface after changing the password is to perform a password reset using the recovery form. There is no way to change this password without re-generating another from the recovery form.


Some help would be appreciated!
Message 1 of 22
mdgm-ntgr
NETGEAR Employee Retired

Re: Serious Security flaw ReadyNAS OS6 (6.2.3 - BETA2)

Do you still have these issues on beta 3?

If yes,
then:
Can you send me your logs (see the Sending Logs link in my sig)?

Have you tried clearing your web browser cache, closing your web browser then reopening it and seeing if you still have issues?
Message 2 of 22
filippo333
Aspirant

Re: Serious Security flaw ReadyNAS OS6 (6.2.3 - BETA2)

I have tried using a different browser entirely but the issue still persists. I have PM'd you my logs.
Message 3 of 22
mdgm-ntgr
NETGEAR Employee Retired

Re: Serious Security flaw ReadyNAS OS6 (6.2.3 - BETA2)

I didn't get your PM
Message 4 of 22
filippo333
Aspirant

Re: Serious Security flaw ReadyNAS OS6 (6.2.3 - BETA2)

mdgm wrote:
I didn't get your PM


I've just resubmitted the PM, I still get this issue on FW 6.2.3 BETA3 after performing a factory reset.
Message 5 of 22
mdgm-ntgr
NETGEAR Employee Retired

Re: Serious Security flaw ReadyNAS OS6 (6.2.3 - BETA2)

One of your disks has ATA errors. Do you still have this problem if you don't use that disk?

What web browser and version are you using?

Have you tried a different web browser?
Message 6 of 22
filippo333
Aspirant

Re: Serious Security flaw ReadyNAS OS6 (6.2.3 - BETA2)

mdgm wrote:
One of your disks has ATA errors. Do you still have this problem if you don't use that disk?

What web browser and version are you using?

Have you tried a different web browser?


I have just PM'd you new logs since doing a factory reset. I have this issue on Firefox 35.0.1 and I've tried Internet Explorer 11 as well as Chrome.

What does it mean that one of my disks has ATA errors? Is that referring to drive health as the SMART status is green, and the disks are only about 4 months old at most.
Message 7 of 22
mdgm-ntgr
NETGEAR Employee Retired

Re: Serious Security flaw ReadyNAS OS6 (6.2.3 - BETA2)

Yes, I was referring to drive health.

If you look in smart_history.log you will see it.
Message 8 of 22
filippo333
Aspirant

Re: Serious Security flaw ReadyNAS OS6 (6.2.3 - BETA2)

mdgm wrote:
Yes, I was referring to drive health.

If you look in smart_history.log you will see it.


I think it's fine, I was originally transferring data from that drive using HDD dock which had a bad cable which is why it may have communication errors logged. I've since performed a full format and put it back in the NAS. Thanks for pointing it out though!

I'd still expect the admin credentials to update even if the drive was bad to be honest.
Message 9 of 22
StephenB
Guru

Re: Serious Security flaw ReadyNAS OS6 (6.2.3 - BETA2)

filippo333 wrote:
...I'd still expect the admin credentials to update even if the drive was bad to be honest.
Well, they are stored on the drives.
Message 10 of 22
filippo333
Aspirant

Re: Serious Security flaw ReadyNAS OS6 (6.2.3 - BETA2)

StephenB wrote:
filippo333 wrote:
...I'd still expect the admin credentials to update even if the drive was bad to be honest.
Well, they are stored on the drives.


Ok but the SMART information is good and I have performed a factory reset since going from 6.2.3 B2 to 6.2.3 B3, so the drives have been reformatted very recently.
Message 11 of 22
filippo333
Aspirant

Re: Serious Security flaw ReadyNAS OS6 (6.2.3 - BETA2)

Just as another update, I enabled SSH access on my 6.2.3 B3 system for the first time and manually reset the password using "passwd admin". Everything worked great, a couple hours later, I changed a user's password on the ReadyNAS interface and the admin password was reset back to "password". Something is seriously screwed up!
Message 12 of 22
StephenB
Guru

Re: Serious Security flaw ReadyNAS OS6 (6.2.3 - BETA2)

You reset the admin password with ssh, or the root password?
Message 13 of 22
filippo333
Aspirant

Re: Serious Security flaw ReadyNAS OS6 (6.2.3 - BETA2)

StephenB wrote:
You reset the admin password with ssh, or the root password?


I reset the admin password from SSH, I followed this guide: http://ram.kossboss.com/readynas-versions-change-password-command-line/
Message 14 of 22
StephenB
Guru

Re: Serious Security flaw ReadyNAS OS6 (6.2.3 - BETA2)

Might be worth repeating this experiment, and also try setting the admin password from the UI, and see if that makes a difference.
Message 15 of 22
Skywalker
NETGEAR Expert

Re: Serious Security flaw ReadyNAS OS6 (6.2.3 - BETA2)

filippo333 wrote:
I reset the admin password from SSH, I followed this guide: http://ram.kossboss.com/readynas-versio ... mand-line/

That's not enough. The salted password hashes are stored in readynasd's database, and re-exported to /etc/{passwd,shadow} whenever any settings change. Those instructions do not touch the database, and thus those changes will not be preserved.
Message 16 of 22
Skywalker
NETGEAR Expert

Re: Serious Security flaw ReadyNAS OS6 (6.2.3 - BETA2)

And BTW, maybe some screenshots of how you're trying to change the admin password would be helpful, since you seem to be the only one experiencing this.
Message 17 of 22
filippo333
Aspirant

Re: Serious Security flaw ReadyNAS OS6 (6.2.3 - BETA2)

StephenB wrote:
Might be worth repeating this experiment, and also try setting the admin password from the UI, and see if that makes a difference.


Just tried resetting the password via the web interface again, it didn't work. The password_recovery page also doesn't work as it says it hasn't been setup. I don't get any errors or anything, when I press okay to apply the changes in Firefox and Chrome, the window disappears.

Changing the password via SSH worked perfectly though. Also, it's worth reiterating that I did a factory reset before upgrading to 6.2.3 BETA 3, so previous settings were completely wiped.
Message 18 of 22
StephenB
Guru

Re: Serious Security flaw ReadyNAS OS6 (6.2.3 - BETA2)

Try giving skywalker the screenshots he's asking for. He's a netgear developer.
Message 19 of 22
filippo333
Aspirant

Re: Serious Security flaw ReadyNAS OS6 (6.2.3 - BETA2)

Skywalker wrote:
And BTW, maybe some screenshots of how you're trying to change the admin password would be helpful, since you seem to be the only one experiencing this.


Here you go! https://drive.google.com/file/d/0B2OeA4Xy1JA6RFg4ZC1uWUFhTUk/view?usp=sharing
Message 20 of 22
filippo333
Aspirant

Re: Serious Security flaw ReadyNAS OS6 (6.2.3 - BETA2)

Just as an update, it appears the issue was using special characters in my recovery question. Although, I don't recall this being an issue in previous versions of the firmware.
Message 21 of 22
Skywalker
NETGEAR Expert

Re: Serious Security flaw ReadyNAS OS6 (6.2.3 - BETA2)

Can you specify what special character(s) caused this, so we can get a bug filed internally? I've tried many special characters in the recovery question field, and I still can't get it to fail.
Message 22 of 22
Top Contributors
Discussion stats
  • 21 replies
  • 5997 views
  • 0 kudos
  • 4 in conversation
Announcements