Buffalo Forums

Products => Storage => Topic started by: w7mCh4Df on July 29, 2013, 04:24:21 AM

Title: Security issue with TS X8.0TL/R5 firmware: Log files are publically accessible
Post by: w7mCh4Df on July 29, 2013, 04:24:21 AM
I just noticed that all the Terastation log files are publically available to everyone in the network at

http://x.x.x.x/static/log/file.smb
http://x.x.x.x/static/log/linkstation.log
http://x.x.x.x/static/log/xferlog

These files contain user account names, file names, system information and configuration...
Browser ID: smf (is_webkit)
Templates: 1: Printpage (default).
Sub templates: 4: init, print_above, main, print_below.
Language files: 1: index+Modifications.english (default).
Style sheets: 0: .
Hooks called: 45 (show)
Files included: 27 - 1055KB. (show)
Memory used: 733KB.
Tokens: post-login.
Queries used: 10.

[Show Queries]