Jump to content

WD My Cloud drive contains a backdoor

NumLock21

Western Digital My Cloud external drive contains a backdoor. The backdoor is actually hardware coded so formatting the drives isn't going to help. The hardware coded user name and password is

Quote

"mydlinkBRionyg" as the Administrator username and "abc12345cba" as the respective password. Once logged in, shell access is unlocked, which allows for easy injection of commands.The backdoor has been published by James Bercegay, with GulfTech Research and Development, and was disclosed to Western Digital on June 12th 2017. However, since more than 6 months have passed with no patch or solution having been deployed, the researchers disclosed and published the vulnerability, which should (should) finally prompt WD to action on fixing the issue.

 

Making things even worse, no user action is required to enable attackers to take advantage of the exploit - simply visiting malicious websites can leave the drives wide open for exploit - and the outing of a Metasploit module for this very vulnerability means that the code is now out there, and Western Digital has a race in its hands.

 

Exploitable models of Western Digital's MyCloud devices include My Cloud Gen 2, My Cloud EX2, My Cloud EX2 Ultra, My Cloud PR2100, My Cloud PR4100, My Cloud EX4, My Cloud EX2100, My Cloud EX4100, My Cloud DL2100 and My Cloud DL4100. Needless to say, until a patch is issued, the best thing to do is to thoroughly disconnect these drives from your local area network and Internet access. But that isn't what users originally bought these drives for, now is it, WD?

I personally never bother with external HDDs, not because of this backdoor but the crappy enclosures out there, bought 5 of them throughout the years and they either don't work properly or died a early death. The HDDs are find and I'm still using them. Now I just use a SATA to USB adapter and they work much better than some external enclosure.

 

http://gulftech.org/advisories/WDMyCloud Multiple Vulnerabilities/125

https://www.techpowerup.com/240306/western-digital-ships-someones-backdoor-with-my-cloud-drives

Intel Xeon E5 1650 v3 @ 3.5GHz 6C:12T / CM212 Evo / Asus X99 Deluxe / 16GB (4x4GB) DDR4 3000 Trident-Z / Samsung 850 Pro 256GB / Intel 335 240GB / WD Red 2 & 3TB / Antec 850w / RTX 2070 / Win10 Pro x64

HP Envy X360 15: Intel Core i5 8250U @ 1.6GHz 4C:8T / 8GB DDR4 / Intel UHD620 + Nvidia GeForce MX150 4GB / Intel 120GB SSD / Win10 Pro x64

 

HP Envy x360 BP series Intel 8th gen

AMD ThreadRipper 2!

5820K & 6800K 3-way SLI mobo support list

 

Link to comment
Share on other sites

Link to post
Share on other sites

Wow, amazing start to year. Time to pull out my WD drive from WD Cloud Gen 2 and slap it into PC.

PC Specs : i7 7700k, 24 GB @ 2666 MHz, ASUS Strix GTX 970, ASUS Z170-K, 960 EVO 250 GB, 850 EVO 250 GB, 2x 2 TB WD Purple RAID 0, Green 1 TB

Link to comment
Share on other sites

Link to post
Share on other sites

Luckily I stopped using my WD mycloud about a month or 2 back, I pulled the 3TB red and put in my backup server.

Please quote my post, or put @paddy-stone if you want me to respond to you.

Spoiler
  • PCs:- 
  • Main PC build  https://uk.pcpartpicker.com/list/2K6Q7X
  • ASUS x53e  - i7 2670QM / Sony BD writer x8 / Win 10, Elemetary OS, Ubuntu/ Samsung 830 SSD
  • Lenovo G50 - 8Gb RAM - Samsung 860 Evo 250GB SSD - DVD writer
  •  
  • Displays:-
  • Philips 55 OLED 754 model
  • Panasonic 55" 4k TV
  • LG 29" Ultrawide
  • Philips 24" 1080p monitor as backup
  •  
  • Storage/NAS/Servers:-
  • ESXI/test build  https://uk.pcpartpicker.com/list/4wyR9G
  • Main Server https://uk.pcpartpicker.com/list/3Qftyk
  • Backup server - HP Proliant Gen 8 4 bay NAS running FreeNAS ZFS striped 3x3TiB WD reds
  • HP ProLiant G6 Server SE316M1 Twin Hex Core Intel Xeon E5645 2.40GHz 48GB RAM
  •  
  • Gaming/Tablets etc:-
  • Xbox One S 500GB + 2TB HDD
  • PS4
  • Nvidia Shield TV
  • Xiaomi/Pocafone F2 pro 8GB/256GB
  • Xiaomi Redmi Note 4

 

  • Unused Hardware currently :-
  • 4670K MSI mobo 16GB ram
  • i7 6700K  b250 mobo
  • Zotac GTX 1060 6GB Amp! edition
  • Zotac GTX 1050 mini

 

 

Link to comment
Share on other sites

Link to post
Share on other sites

6 minutes ago, NumLock21 said:

Western Digital My Cloud external drive contains a backdoor. The backdoor is actually hardware coded so formatting the drives isn't going to help. The hardware coded user name and password is

I personally never bother with external HDDs, not because of this backdoor but the crappy enclosures out there, bought 5 of them throughout the years and they either don't work properly or died a early death. The HDDs are find and I'm still using them. Now I just use a SATA to USB adapter and they work much better than some external enclosure.

 

http://gulftech.org/advisories/WDMyCloud Multiple Vulnerabilities/125

https://www.techpowerup.com/240306/western-digital-ships-someones-backdoor-with-my-cloud-drives

jesus christ, GG 2018 now i got to tear apart my mycloud and throw it into a PC

Link to comment
Share on other sites

Link to post
Share on other sites

Just now, paddy-stone said:

Luckily I stopped using my WD mycloud about a month or 2 back, I pulled the 3TB red and put in my backup server.

do you know if there is hardware encryption? i have a 6TB MyCloud and i need to know if i need to backup the data or not

Link to comment
Share on other sites

Link to post
Share on other sites

Solution: N/A

My eyes see the past…

My camera lens sees the present…

Link to comment
Share on other sites

Link to post
Share on other sites

1 minute ago, luigi90210 said:

jesus christ, GG 2018 not i got to tear apart my mycloud and throw it into a PC

Well just to note you before you proceed anywhere, you'll have to run Linux distro to pull files cause its RAW file format :/

PC Specs : i7 7700k, 24 GB @ 2666 MHz, ASUS Strix GTX 970, ASUS Z170-K, 960 EVO 250 GB, 850 EVO 250 GB, 2x 2 TB WD Purple RAID 0, Green 1 TB

Link to comment
Share on other sites

Link to post
Share on other sites

Just now, luigi90210 said:

do you know if there is hardware encryption? i have a 6TB MyCloud and i need to know if i need to backup the data or not

No, don't know sorry.. I was wiping the drive anyway as I was adding it into my freenas volume. But I suspect will have at least some security.

Please quote my post, or put @paddy-stone if you want me to respond to you.

Spoiler
  • PCs:- 
  • Main PC build  https://uk.pcpartpicker.com/list/2K6Q7X
  • ASUS x53e  - i7 2670QM / Sony BD writer x8 / Win 10, Elemetary OS, Ubuntu/ Samsung 830 SSD
  • Lenovo G50 - 8Gb RAM - Samsung 860 Evo 250GB SSD - DVD writer
  •  
  • Displays:-
  • Philips 55 OLED 754 model
  • Panasonic 55" 4k TV
  • LG 29" Ultrawide
  • Philips 24" 1080p monitor as backup
  •  
  • Storage/NAS/Servers:-
  • ESXI/test build  https://uk.pcpartpicker.com/list/4wyR9G
  • Main Server https://uk.pcpartpicker.com/list/3Qftyk
  • Backup server - HP Proliant Gen 8 4 bay NAS running FreeNAS ZFS striped 3x3TiB WD reds
  • HP ProLiant G6 Server SE316M1 Twin Hex Core Intel Xeon E5645 2.40GHz 48GB RAM
  •  
  • Gaming/Tablets etc:-
  • Xbox One S 500GB + 2TB HDD
  • PS4
  • Nvidia Shield TV
  • Xiaomi/Pocafone F2 pro 8GB/256GB
  • Xiaomi Redmi Note 4

 

  • Unused Hardware currently :-
  • 4670K MSI mobo 16GB ram
  • i7 6700K  b250 mobo
  • Zotac GTX 1060 6GB Amp! edition
  • Zotac GTX 1050 mini

 

 

Link to comment
Share on other sites

Link to post
Share on other sites

4 minutes ago, SilkyDistress said:

Well just to note you before you proceed anywhere, you'll have to run Linux distro to pull files cause its RAW file format :/

can i just copy all the data to another HDD instead of doing that?

Link to comment
Share on other sites

Link to post
Share on other sites

3 minutes ago, Zodiark1593 said:

Solution: N/A

At this point, we need to throw everything electronic away and go back to the old ways.

 

Make sure to quote or tag people, so they get notified.

Link to comment
Share on other sites

Link to post
Share on other sites

So this backdoor still works if the HDD is removed from its caddy (because that's all external HDD and ODD are -drives in caddies)?

"We also blind small animals with cosmetics.
We do not sell cosmetics. We just blind animals."

 

"Please don't mistake us for Equifax. Those fuckers are evil"

 

This PSA brought to you by Equifacks.
PMSL

Link to comment
Share on other sites

Link to post
Share on other sites

1 minute ago, Dabombinable said:

So this backdoor still works if the HDD is removed from its caddy (because that's all external HDD and ODD are -drives in caddies)?

it shouldnt, the backdoor is in the software not the HDD itself 

Link to comment
Share on other sites

Link to post
Share on other sites

Just now, Cyberspirit said:

At this point, we need to throw everything electronic away and go back to the old ways.

 

Can we start teaching paper cryptography in schools. Should be entertaining for professors to have to decode messages passed by students.

My eyes see the past…

My camera lens sees the present…

Link to comment
Share on other sites

Link to post
Share on other sites

BRB going to rob some bois of their pr0n

Our Grace. The Feathered One. He shows us the way. His bob is majestic and shows us the path. Follow unto his guidance and His example. He knows the one true path. Our Saviour. Our Grace. Our Father Birb has taught us with His humble heart and gentle wing the way of the bob. Let us show Him our reverence and follow in His example. The True Path of the Feathered One. ~ Dimboble-dubabob III

Link to comment
Share on other sites

Link to post
Share on other sites

All of my externals are standard drivers in an enclosure. Was always cheaper than trying the WD or Seagate boxed solutions. I don't need the fancy stuff. I do direct connection when I need the info; otherwise the drive offline most of the time.

Link to comment
Share on other sites

Link to post
Share on other sites

2 minutes ago, Ryujin2003 said:

All of my externals are standard drivers in an enclosure. Was always cheaper than trying the WD or Seagate boxed solutions. I don't need the fancy stuff. I do direct connection when I need the info; otherwise the drive offline most of the time.

i liked the fact i can access my stuff on the go so when im out of the office i can access my files from my laptop so that was a big selling point for me 

Link to comment
Share on other sites

Link to post
Share on other sites

1 hour ago, NumLock21 said:

I personally never bother with external HDDs, not because of this backdoor but the crappy enclosures out there

Yep I generally make my own "external" HDD with an internal drive and a enclosure, usually about the same price for me and much much more reliable

 

 

Never ever leave backdoors in your software people, or at the bear minimum remove them once you finalize the software, though the second option leads to potential forgetfulness so it is in your best interest to never do so as a safeguard

https://linustechtips.com/main/topic/631048-psu-tier-list-updated/ Tier Breakdown (My understanding)--1 Godly, 2 Great, 3 Good, 4 Average, 5 Meh, 6 Bad, 7 Awful

 

Link to comment
Share on other sites

Link to post
Share on other sites

Noob Question: Is it possible to turn a RAID 0 (3 1TB 7200 rpm drives) to a NAS? 

There is more that meets the eye
I see the soul that is inside

 

 

Link to comment
Share on other sites

Link to post
Share on other sites

8 minutes ago, hey_yo_ said:

Noob Question: Is it possible to turn a RAID 0 (3 1TB 7200 rpm drives) to a NAS? 

Yes. You can have any drive configuration in a NAS. Even a single external drive hooked up on the network is a NAS.

Link to comment
Share on other sites

Link to post
Share on other sites

2 hours ago, Cyberspirit said:

At this point, we need to throw everything electronic away and go back to the old ways.

 

*watches Cyberspirit pull out a stone tablet and chisel* 


Dear god...

- Fresher than a fruit salad.

Link to comment
Share on other sites

Link to post
Share on other sites

1 hour ago, Bit_Guardian said:

Yes. You can have any drive configuration in a NAS. Even a single external drive hooked up on the network is a NAS.

So after setting up RAID 0 in Windows disk management, all I need to do is connect it to a router or wireless AP? 

There is more that meets the eye
I see the soul that is inside

 

 

Link to comment
Share on other sites

Link to post
Share on other sites

1 hour ago, hey_yo_ said:

Noob Question: Is it possible to turn a RAID 0 (3 1TB 7200 rpm drives) to a NAS? 

So long as it's open to the network, yes.

Come Bloody Angel

Break off your chains

And look what I've found in the dirt.

 

Pale battered body

Seems she was struggling

Something is wrong with this world.

 

Fierce Bloody Angel

The blood is on your hands

Why did you come to this world?

 

Everybody turns to dust.

 

Everybody turns to dust.

 

The blood is on your hands.

 

The blood is on your hands!

 

Pyo.

Link to comment
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×