Dec. 7, 2023, 11:55 a.m. | Black Hat

Black Hat www.youtube.com

Have you ever wondered how you can access your family pictures on your home network-attached storage (NAS) device remotely from your mobile? Do you know how this magic works? At Pwn2Own Toronto 2022, we chained multiple bugs to exploit both Synology and Western Digital NAS devices by abusing vulnerabilities in the device, cloud and the mutual trust between them.

In our research, we reviewed the pairing mechanism of NAS devices with the WD and Synology cloud platforms...

By: Sharon Brizinov …

abusing access bugs cloud connectivity device devices digital exploit exploiting family home home network magic mobile nas network network-attached storage pictures pwn2own pwn2own toronto 2022 storage synology toronto western western digital

CyberSOC Technical Lead

@ Integrity360 | Sandyford, Dublin, Ireland

Cyber Security Strategy Consultant

@ Capco | New York City

Cyber Security Senior Consultant

@ Capco | Chicago, IL

Sr. Product Manager

@ MixMode | Remote, US

Corporate Intern - Information Security (Year Round)

@ Associated Bank | US WI Remote

Senior Offensive Security Engineer

@ CoStar Group | US-DC Washington, DC