-
krzemien
AskWoody LoungerSeptember 25, 2021 at 10:28 am in reply to: Do we need firmware and software updates forever? #2391768I do not have problem with doing this, however had not had to do this before…
Does it not require rooting the device, which may in turn invalidate all sorts of sensitive apps (banking, security etc.?)
Still, I may give it a pass though, will be replacing this device in the next year probably…
-
krzemien
AskWoody LoungerSeptember 23, 2021 at 2:45 pm in reply to: Do we need firmware and software updates forever? #2391470Well, the short answer is: yes.
But nobody will do anything about it.
Just as an example, take a look here:
https://geekthingy.com/petition-for-sony-xperia-xz1-android-10-update-hits-2k/
SONY quite lightly broke their promise to keep this flagship device updated. I can obviously understand why, but this is quite unacceptable. And nothing happened.
Also, to compound the above: I actually own this very phone and 4 (four) years later it performs like it’s just removed from its box.
Shame.
1 user thanked author for this post.
-
krzemien
AskWoody LoungerLate realisation my end – after goring through all the above at later stage – was/is that v4 is not based on OS3 actually.
Security by obscurity?
-
krzemien
AskWoody LoungerAs per my post on WD Forums:
https://community.wd.com/t/unofficial-patch-for-os3-zero-day-rce-vulnerability/268631/24?u=krzemien
I just revisited all the above with the clear eyes and corrected typos accordingly. Nonetheless the result remains the same(…)
The unit I own is 1st Gen (v4.x), with the latest available firmware (v04.05.00-342) installed. No faffing with its content, with the exception of HD Sentinel installation (as per the other thread & my post here: Monitor Network Attached Storage (NAS) status via HD Sentinel – #6 by krzemien)
(…)
The results I am seeing – but I might be missing something bleeding obvious – seem to indicate that 1st Gen units might be immune to this vulnerability.
And no, I understand that I cannot upgrade this unit to OS5 as it’s not supported on this hardware.
-
krzemien
AskWoody LoungerWell, I just did, and there we are:
(https://community.wd.com/t/unofficial-patch-for-os3-zero-day-rce-vulnerability/268631/18?u=krzemien)
EDITED TO ADD #1: I’m not getting the same response wher **nobody** & **squeezecenter** accounts are considered as authors do to *cat /etc/shadow* command (~5m45s)
Code:nobody:*:15729:0:99999:7:::
**squeezecenter** account does not in fact exist.
EDITED TO ADD #2: I’m not getting the same response as authors do to *curl ‘http://127.0.0.1/api/2.1/rest/device?auth_username=nobody?auth_password=’* command (~9m45s)
Code:<?xml version="1.0" encoding="utf-8"?><core><error_code>401</error_code><http_status_code>401</http_status_code><error_id>57</error_id><error_message>User not authorized</error_message></core>WDMyCloud:~#
EDITED TO ADD #3:
I’m not getting the same response as authors do to *’curl -X POST ‘http://127.0.0.1/api/2.1/rest/firmware_update?auth_username=nobody&auth_password=’* command (~13m00s)
Code:<?xml version="1.0" encoding="utf-8"?><core><error_code>401</error_code><http_status_code>401</http_status_code><error_id>57</error_id><error_message>User not authorized</error_message></core>WDMyCloud:~#
EDITED TO ADD #4: Whole premise of attack assumes using **nobody** account for nefarious purposes (15m30s)
EDITED TO ADD #5: I’m not getting the same response as authors do to *ps faux | grep httpd* command (~21m45s)
Code:root 16889 0.0 0.7 2432 1728 pts/0 S+ 16:26 0:00 \_ grep httpd
What am I seeing is that my device seems to be immune to that vector of attack as user **nobody** does not seem to respond to the commands as shown in this YouTube video. At least that’s my quick conclusion…
-
krzemien
AskWoody LoungerThanks for sharing – had interesting lecture yesterday evening…
Does anybody know what the exact vulnerability is though? I have a skin in the game… For reference:
https://community.wd.com/t/unofficial-patch-for-os3-zero-day-rce-vulnerability/268631/16
That’s what I just got when I created and ran the script:
Patching vulnerability and restarting httpd…
httpd: no process found
authfix.sh: line 15: httpd: command not found
Vulnerability patched. Don’t forget to run this script at every reboot!(…)Also, does anybody actually know what this vulnerability entails exactly, given that the above scrips seems doing something to httpd which apparently does not run on my device?
-
krzemien
AskWoody LoungerAh, but I’m merely a humble and boring home user so really it’s not end of the world for me…
Still, I simply cannot comprehend how something such basic like core functionality – ability to read messages in e-mail client – can be made broken, and across multiple versions. And not to mention: released to the wide world and on a planned date either.
Mind truly boggles (and I thought I’ve seen it all…!)
1 user thanked author for this post.
-
krzemien
AskWoody LoungerJune 20, 2020 at 1:20 pm in reply to: Yes,. you read that correctly: Win7 machines don’t get free security patches, but they do get a free copy of Chredge #2273837Quite! I was wondering about the same thinking: ‘Have I missed something and actually did get Edge installed incautiously already’?
-
krzemien
AskWoody LoungerJune 20, 2020 at 6:31 am in reply to: Yes,. you read that correctly: Win7 machines don’t get free security patches, but they do get a free copy of Chredge #2273757Same here, listed under Optional updates on Win 8.1
Microsoft Edge Update for Windows 8.1 for x64-based Systems (KB4567409)
Download size: 80.6 MB
You may need to restart your computer for this update to take effect.
Update type: Recommended
This update provides the latest feature and quality updates to Microsoft Edge.
More information:
https://support.microsoft.com/help/4567409Help and Support:
https://support.microsoft.com/help/4567409 -
krzemien
AskWoody LoungerAs I wrote elsewhere recently about the same: Plus ça change, plus c’est la même chose.
-
krzemien
AskWoody LoungerJune 5, 2020 at 3:57 am in reply to: KB 4541302 – The new Chromium-based version of Edge is coming #2269477Likewise.
Also, if I read that correctly, does that mean that in effect I will have three MS browsers installed on my PC simultaneously?
*IE
*Edge (legacy)
*Chredge
-
krzemien
AskWoody LoungerReally heart-warming that one can issue a major OS release with such a bug. if DISM gives inconsistent results, where’s the source of truth?
Also, does it not imply (yet again) that this release was pushed out of the door hastily and prematurely (yet again)?
One really wonders what else is there to be found.
-
This reply was modified 4 years, 11 months ago by
krzemien. Reason: SPELLING
1 user thanked author for this post.
-
This reply was modified 4 years, 11 months ago by
-
krzemien
AskWoody LoungerCheck this out as well:
https://boingboing.net/2020/05/05/adobe-to-read-the-terms-of-us.html
…so in order to use this software one needs to agree that one does not sue them?
Nice.
2 users thanked author for this post.
-
krzemien
AskWoody Lounger…so does latest SKYPE as well:
Why don’t I see the option to blur or customize my video background?
To blur your background in Skype, your computer processor needs to support Advanced Vector Extensions 2 (AVX2). For more information, check with your computer manufacturer.
https://support.skype.com/en/faq/FA34896/how-do-i-customize-my-background-for-skype-video-calls
For Intel-based CPUs it’s everything from Haswell (i.e. series 4 – year 2014) onwards.
-
krzemien
AskWoody LoungerApril 17, 2020 at 2:37 am in reply to: Windows 10 version “twenty – oh – four” hits Release Preview Ring #2242657You did not confuse ‘updated’ with ‘upgraded’ surely? Just checkin’…
-
This reply was modified 5 years ago by
krzemien.
-
This reply was modified 5 years ago by
![]() |
Patch reliability is unclear, but widespread attacks make patching prudent. Go ahead and patch, but watch out for potential problems. |
SIGN IN | Not a member? | REGISTER | PLUS MEMBERSHIP |

Plus Membership
Donations from Plus members keep this site going. You can identify the people who support AskWoody by the Plus badge on their avatars.
AskWoody Plus members not only get access to all of the contents of this site -- including Susan Bradley's frequently updated Patch Watch listing -- they also receive weekly AskWoody Plus Newsletters (formerly Windows Secrets Newsletter) and AskWoody Plus Alerts, emails when there are important breaking developments.
Get Plus!
Welcome to our unique respite from the madness.
It's easy to post questions about Windows 11, Windows 10, Win8.1, Win7, Surface, Office, or browse through our Forums. Post anonymously or register for greater privileges. Keep it civil, please: Decorous Lounge rules strictly enforced. Questions? Contact Customer Support.
Search Newsletters
Search Forums
View the Forum
Search for Topics
Recent Topics
-
Proton to drop prices after ruling against “Apple tax”
by
Cybertooth
2 hours, 2 minutes ago -
24H2 Installer – don’t see Option for non destructive install
by
JP
2 hours, 27 minutes ago -
Asking Again here (New User and Fast change only backups)
by
thymej
13 hours, 23 minutes ago -
How much I spent on the Mac mini
by
Will Fastie
2 hours, 50 minutes ago -
How to get rid of Copilot in Microsoft 365
by
Lance Whitney
5 hours, 11 minutes ago -
Spring cleanup — 2025
by
Deanna McElveen
19 hours, 15 minutes ago -
Setting up Windows 11
by
Susan Bradley
2 hours, 50 minutes ago -
VLC Introduces Cutting-Edge AI Subtitling and Translation Capabilities
by
Alex5723
14 hours, 42 minutes ago -
Powershell version?
by
CWBillow
15 hours, 35 minutes ago -
SendTom Toys
by
CWBillow
10 hours, 15 minutes ago -
Add shortcut to taskbar?
by
CWBillow
19 hours, 31 minutes ago -
Sycophancy in GPT-4o: What happened
by
Alex5723
1 day, 11 hours ago -
How can I install Skype on Windows 7?
by
Help
1 day, 10 hours ago -
Logitech MK850 Keyboard issues
by
Rush2112
17 hours, 31 minutes ago -
We live in a simulation
by
Alex5723
2 days, 2 hours ago -
Netplwiz not working
by
RetiredGeek
1 day, 12 hours ago -
Windows 11 24H2 is broadly available
by
Alex5723
2 days, 14 hours ago -
Microsoft is killing Authenticator
by
Alex5723
1 day, 2 hours ago -
Downloads folder location
by
CWBillow
2 days, 20 hours ago -
Remove a User from Login screen
by
CWBillow
1 day, 16 hours ago -
TikTok fined €530 million for sending European user data to China
by
Nibbled To Death By Ducks
2 days, 12 hours ago -
Microsoft Speech Recognition Service Error Code 1002
by
stanhutchings
2 days, 12 hours ago -
Is it a bug or is it expected?
by
Susan Bradley
14 hours, 9 minutes ago -
Image for Windows TBwinRE image not enough space on target location
by
bobolink
2 days, 11 hours ago -
Start menu jump lists for some apps might not work as expected on Windows 10
by
Susan Bradley
1 day, 10 hours ago -
Malicious Go Modules disk-wiping malware
by
Alex5723
3 days ago -
Multiple Partitions?
by
CWBillow
3 days, 1 hour ago -
World Passkey Day 2025
by
Alex5723
2 hours, 11 minutes ago -
Add serial device in Windows 11
by
Theodore Dawson
4 days, 10 hours ago -
Windows 11 users reportedly losing data due forced BitLocker encryption
by
Alex5723
2 days, 10 hours ago
Recent blog posts
Key Links
Want to Advertise in the free newsletter? How about a gift subscription in honor of a birthday? Send an email to sb@askwoody.com to ask how.
Mastodon profile for DefConPatch
Mastodon profile for AskWoody
Home • About • FAQ • Posts & Privacy • Forums • My Account
Register • Free Newsletter • Plus Membership • Gift Certificates • MS-DEFCON Alerts
Copyright ©2004-2025 by AskWoody Tech LLC. All Rights Reserved.