• Welcome to TechPowerUp Forums, Guest! Please check out our forum guidelines for info related to our community.

Western Digital Ships "Someone's Backdoor" With My Cloud Drives

Raevenlord

News Editor
Joined
Aug 12, 2016
Messages
3,755 (1.23/day)
Location
Portugal
System Name The Ryzening
Processor AMD Ryzen 9 5900X
Motherboard MSI X570 MAG TOMAHAWK
Cooling Lian Li Galahad 360mm AIO
Memory 32 GB G.Skill Trident Z F4-3733 (4x 8 GB)
Video Card(s) Gigabyte RTX 3070 Ti
Storage Boot: Transcend MTE220S 2TB, Kintson A2000 1TB, Seagate Firewolf Pro 14 TB
Display(s) Acer Nitro VG270UP (1440p 144 Hz IPS)
Case Lian Li O11DX Dynamic White
Audio Device(s) iFi Audio Zen DAC
Power Supply Seasonic Focus+ 750 W
Mouse Cooler Master Masterkeys Lite L
Keyboard Cooler Master Masterkeys Lite L
Software Windows 10 x64
Western Digital has seemingly been shipping their My Cloud personal network attached storage solutions with an integrated backdoor. It's not really that complicated a backdoor either - a malicious user should always be able to use it. That stems from the fact that it's a hard coded backdoor with unchangeable credentials - logging in to someone's My Cloud is as simple as inputing "mydlinkBRionyg" as the Administrator username and "abc12345cba" as the respective password. Once logged in, shell access is unlocked, which allows for easy injection of commands.

The backdoor has been published by James Bercegay, with GulfTech Research and Development, and was disclosed to Western Digital on June 12th 2017. However, since more than 6 months have passed with no patch or solution having been deployed, the researchers disclosed and published the vulnerability, which should (should) finally prompt WD to action on fixing the issue. Making things even worse, no user action is required to enable attackers to take advantage of the exploit - simply visiting malicious websites can leave the drives wide open for exploit - and the outing of a Metasploit module for this very vulnerability means that the code is now out there, and Western Digital has a race in its hands. The thing is, it needn't have.





Exploitable models of Western Digital's MyCloud devices include My Cloud Gen 2, My Cloud EX2, My Cloud EX2 Ultra, My Cloud PR2100, My Cloud PR4100, My Cloud EX4, My Cloud EX2100, My Cloud EX4100, My Cloud DL2100 and My Cloud DL4100. Needless to say, until a patch is issued, the best thing to do is to thoroughly disconnect these drives from your local area network and Internet access. But that isn't what users originally bought these drives for, now is it, WD?



View at TechPowerUp Main Site
 

newtekie1

Semi-Retired Folder
Joined
Nov 22, 2005
Messages
28,473 (4.08/day)
Location
Indiana, USA
Processor Intel Core i7 10850K@5.2GHz
Motherboard AsRock Z470 Taichi
Cooling Corsair H115i Pro w/ Noctua NF-A14 Fans
Memory 32GB DDR4-3600
Video Card(s) RTX 2070 Super
Storage 500GB SX8200 Pro + 8TB with 1TB SSD Cache
Display(s) Acer Nitro VG280K 4K 28"
Case Fractal Design Define S
Audio Device(s) Onboard is good enough for me
Power Supply eVGA SuperNOVA 1000w G3
Software Windows 10 Pro x64
It's a sad thing that WD has known about this issue for 6 months and not bothered to address it. But I also know that the fix for it would be a firmware update that most users probably wouldn't even bother to install...
 
Joined
Nov 3, 2013
Messages
2,141 (0.53/day)
Location
Serbia
Processor Ryzen 5600
Motherboard X570 I Aorus Pro
Cooling Deepcool AG400
Memory HyperX Fury 2 x 8GB 3200 CL16
Video Card(s) RX 6700 10GB SWFT 309
Storage SX8200 Pro 512 / NV2 512
Display(s) 24G2U
Case NR200P
Power Supply Ion SFX 650
Mouse G703 (TTC Gold 60M)
Keyboard Keychron V1 (Akko Matcha Green) / Apex m500 (Gateron milky yellow)
Software W10
They had 6 months to fix this and couldn't/wouldn't.
What the hell WD...
 

eidairaman1

The Exiled Airman
Joined
Jul 2, 2007
Messages
42,679 (6.68/day)
Location
Republic of Texas (True Patriot)
System Name PCGOD
Processor AMD FX 8350@ 5.0GHz
Motherboard Asus TUF 990FX Sabertooth R2 2901 Bios
Cooling Scythe Ashura, 2×BitFenix 230mm Spectre Pro LED (Blue,Green), 2x BitFenix 140mm Spectre Pro LED
Memory 16 GB Gskill Ripjaws X 2133 (2400 OC, 10-10-12-20-20, 1T, 1.65V)
Video Card(s) AMD Radeon 290 Sapphire Vapor-X
Storage Samsung 840 Pro 256GB, WD Velociraptor 1TB
Display(s) NEC Multisync LCD 1700V (Display Port Adapter)
Case AeroCool Xpredator Evil Blue Edition
Audio Device(s) Creative Labs Sound Blaster ZxR
Power Supply Seasonic 1250 XM2 Series (XP3)
Mouse Roccat Kone XTD
Keyboard Roccat Ryos MK Pro
Software Windows 7 Pro 64
Backdoors should only be accessible by the end user and only enabled by them for troubleshhoting with technical support, and only commanded to do so by them. Once technical support is finished they should shut it and lock it. It should not be able to be opened externally whether is the company that made the device or criminals/terrorists. And it should by default not be open at all but shut and locked.
 
Joined
Apr 24, 2008
Messages
2,025 (0.33/day)
Processor RyZen R9 3950X
Motherboard ASRock X570 Taichi
Cooling Coolermaster Master Liquid ML240L RGB
Memory 64GB DDR4 3200 (4x16GB)
Video Card(s) RTX 3050
Storage Samsung 2TB SSD
Display(s) Asus VE276Q, VE278Q and VK278Q triple 27” 1920x1080
Case Zulman MS800
Audio Device(s) On Board
Power Supply Seasonic 650W
VR HMD Oculus Rift, Oculus Quest V1, Oculus Quest 2
Software Windows 11 64bit
These are not the best products overall. a Q-NAP or Synology is a far better option in most if not all cases. The WD MyCloud Linux interface is abysmal. Such security related issues are inexcusable especially so if they went unpatched for so long and are now publicly known.
 
Joined
Oct 2, 2004
Messages
13,791 (1.87/day)
When I buy any storage device, the first thing I always do is format the thing. I don't trust or need any apps that come with it.
 

newtekie1

Semi-Retired Folder
Joined
Nov 22, 2005
Messages
28,473 (4.08/day)
Location
Indiana, USA
Processor Intel Core i7 10850K@5.2GHz
Motherboard AsRock Z470 Taichi
Cooling Corsair H115i Pro w/ Noctua NF-A14 Fans
Memory 32GB DDR4-3600
Video Card(s) RTX 2070 Super
Storage 500GB SX8200 Pro + 8TB with 1TB SSD Cache
Display(s) Acer Nitro VG280K 4K 28"
Case Fractal Design Define S
Audio Device(s) Onboard is good enough for me
Power Supply eVGA SuperNOVA 1000w G3
Software Windows 10 Pro x64
When I buy any storage device, the first thing I always do is format the thing. I don't trust or need any apps that come with it.

And that would do nothing for this exploit.
 
Joined
Oct 13, 2015
Messages
44 (0.01/day)
"Exploiting this issue to gain a remote shell as root is a rather trivial process" says the advisory.

So it's basically a set of critical vulnerabilities that leave the devices open to remote exploit, which WD were told about six months ago, and they did nothing?

Oh well. We'll all have forgotten about it in a week.
 
Joined
Mar 18, 2008
Messages
5,717 (0.93/day)
System Name Virtual Reality / Bioinformatics
Processor Undead CPU
Motherboard Undead TUF X99
Cooling Noctua NH-D15
Memory GSkill 128GB DDR4-3000
Video Card(s) EVGA RTX 3090 FTW3 Ultra
Storage Samsung 960 Pro 1TB + 860 EVO 2TB + WD Black 5TB
Display(s) 32'' 4K Dell
Case Fractal Design R5
Audio Device(s) BOSE 2.0
Power Supply Seasonic 850watt
Mouse Logitech Master MX
Keyboard Corsair K70 Cherry MX Blue
VR HMD HTC Vive + Oculus Quest 2
Software Windows 10 P
Cloud this, connection that. Some people working in IT thinking "connect everything" is a good idea. Hell no. Take a page from nature. Evolution over billions of years have given us some of the finest example of logical coding. You don't have to dig deep to see that organisms have gone to pretty extreme extent to block direct coding exchange. Connect everything is a bad, it just leaves the entire connected system vulnerable to a wipe-out scale attack. I would never trust or use cloud.
 

newtekie1

Semi-Retired Folder
Joined
Nov 22, 2005
Messages
28,473 (4.08/day)
Location
Indiana, USA
Processor Intel Core i7 10850K@5.2GHz
Motherboard AsRock Z470 Taichi
Cooling Corsair H115i Pro w/ Noctua NF-A14 Fans
Memory 32GB DDR4-3600
Video Card(s) RTX 2070 Super
Storage 500GB SX8200 Pro + 8TB with 1TB SSD Cache
Display(s) Acer Nitro VG280K 4K 28"
Case Fractal Design Define S
Audio Device(s) Onboard is good enough for me
Power Supply eVGA SuperNOVA 1000w G3
Software Windows 10 Pro x64
"Exploiting this issue to gain a remote shell as root is a rather trivial process" says the advisory.

So it's basically a set of critical vulnerabilities that leave the devices open to remote exploit, which WD were told about six months ago, and they did nothing?

Oh well. We'll all have forgotten about it in a week.


Here is the interesting thing, I don't even think Western Digital knows how to fix the problem. The reason being that they obvious get their hardware, and firmware, from Dlink(hence the exploit username being mydlinkBRionyg). So they likely rely entirely on dlink to provide the firmware for these devices, and dlink just skins their firmware with WD branding. So WD has to rely on Dlink to fix the problem. However, Dlink is notorious bad at fixing security vulnerabilities with their products. So bad, in fact, that the FTC sued them early last year for failing to fix security problems with their routers, IP cameras, and NAS devices.
 

bug

Joined
May 22, 2015
Messages
13,844 (3.95/day)
Processor Intel i5-12600k
Motherboard Asus H670 TUF
Cooling Arctic Freezer 34
Memory 2x16GB DDR4 3600 G.Skill Ripjaws V
Video Card(s) EVGA GTX 1060 SC
Storage 500GB Samsung 970 EVO, 500GB Samsung 850 EVO, 1TB Crucial MX300 and 2TB Crucial MX500
Display(s) Dell U3219Q + HP ZR24w
Case Raijintek Thetis
Audio Device(s) Audioquest Dragonfly Red :D
Power Supply Seasonic 620W M12
Mouse Logitech G502 Proteus Core
Keyboard G.Skill KM780R
Software Arch Linux + Win10
Joined
Sep 15, 2007
Messages
3,946 (0.63/day)
Location
Police/Nanny State of America
Processor OCed 5800X3D
Motherboard Asucks C6H
Cooling Air
Memory 32GB
Video Card(s) OCed 6800XT
Storage NVMees
Display(s) 32" Dull curved 1440
Case Freebie glass idk
Audio Device(s) Sennheiser
Power Supply Don't even remember
Joke's on them. I yank the drive and trash the enclosure (even if I'm going to use it as an external).
 

newtekie1

Semi-Retired Folder
Joined
Nov 22, 2005
Messages
28,473 (4.08/day)
Location
Indiana, USA
Processor Intel Core i7 10850K@5.2GHz
Motherboard AsRock Z470 Taichi
Cooling Corsair H115i Pro w/ Noctua NF-A14 Fans
Memory 32GB DDR4-3600
Video Card(s) RTX 2070 Super
Storage 500GB SX8200 Pro + 8TB with 1TB SSD Cache
Display(s) Acer Nitro VG280K 4K 28"
Case Fractal Design Define S
Audio Device(s) Onboard is good enough for me
Power Supply eVGA SuperNOVA 1000w G3
Software Windows 10 Pro x64
Joined
Sep 15, 2007
Messages
3,946 (0.63/day)
Location
Police/Nanny State of America
Processor OCed 5800X3D
Motherboard Asucks C6H
Cooling Air
Memory 32GB
Video Card(s) OCed 6800XT
Storage NVMees
Display(s) 32" Dull curved 1440
Case Freebie glass idk
Audio Device(s) Sennheiser
Power Supply Don't even remember
What part of Network Attached Storage is hard to understand? This has nothing to do with their USB external drives.

Oh, I'm betting those have one, too (for data mining). Have you seen the garbage on them? And tricking dummies into installing the backup software.

The NAS ones do come in single cheapos, too. That's the reason for buying the WDs. They're super cheap on clearance.
 
Last edited:

newtekie1

Semi-Retired Folder
Joined
Nov 22, 2005
Messages
28,473 (4.08/day)
Location
Indiana, USA
Processor Intel Core i7 10850K@5.2GHz
Motherboard AsRock Z470 Taichi
Cooling Corsair H115i Pro w/ Noctua NF-A14 Fans
Memory 32GB DDR4-3600
Video Card(s) RTX 2070 Super
Storage 500GB SX8200 Pro + 8TB with 1TB SSD Cache
Display(s) Acer Nitro VG280K 4K 28"
Case Fractal Design Define S
Audio Device(s) Onboard is good enough for me
Power Supply eVGA SuperNOVA 1000w G3
Software Windows 10 Pro x64
Oh, I'm betting those have one, too (for data mining). Have you seen the garbage on them? And tricking dummies into installing the backup software.

The NAS ones do come in single cheapos, too. That's the reason for buying the WDs. They're super cheap on clearance.

No, the USB ones don't have a backdoor. Because they don't have a WebGUI. The software that the users install might have a backdoor, but the unit itself does not. If you just use it as a normal drive and never install any of the WD software, you have nothing to worry about.

The single units usually aren't that cheap though, unless they are refurbished, and I wouldn't trust my data on a refurbished hard drive if WD was paying me to use the drive. And even the refurbished My Cloud drives aren't usually cheap enough to warrant buying just to shuck. The 4TB MyCloud refurbished is $150. You can get a brand new 4TB hard drive for $100. I've never seen a NAS unit on sale for cheap enough to buy just to shuck.
 

bug

Joined
May 22, 2015
Messages
13,844 (3.95/day)
Processor Intel i5-12600k
Motherboard Asus H670 TUF
Cooling Arctic Freezer 34
Memory 2x16GB DDR4 3600 G.Skill Ripjaws V
Video Card(s) EVGA GTX 1060 SC
Storage 500GB Samsung 970 EVO, 500GB Samsung 850 EVO, 1TB Crucial MX300 and 2TB Crucial MX500
Display(s) Dell U3219Q + HP ZR24w
Case Raijintek Thetis
Audio Device(s) Audioquest Dragonfly Red :D
Power Supply Seasonic 620W M12
Mouse Logitech G502 Proteus Core
Keyboard G.Skill KM780R
Software Arch Linux + Win10
What part of Network Attached Storage is hard to understand? This has nothing to do with their USB external drives.
My bad, I thought "My Cloud" is the name of the admin software, not their line of NAS hardware.
 
Joined
Jul 5, 2013
Messages
28,295 (6.75/day)
Cloud this, connection that. Some people working in IT thinking "connect everything" is a good idea. Hell no. Take a page from nature. Evolution over billions of years have given us some of the finest example of logical coding. You don't have to dig deep to see that organisms have gone to pretty extreme extent to block direct coding exchange. Connect everything is a bad, it just leaves the entire connected system vulnerable to a wipe-out scale attack. I would never trust or use cloud.
Right there with you. I never connect anything to the internet unless it is absolutely needed. It's also why I have two different networks in my house, one of them completely isolated from the internet. So in my house, this vulnerability would be a non-issue.
 
Joined
Apr 24, 2008
Messages
2,025 (0.33/day)
Processor RyZen R9 3950X
Motherboard ASRock X570 Taichi
Cooling Coolermaster Master Liquid ML240L RGB
Memory 64GB DDR4 3200 (4x16GB)
Video Card(s) RTX 3050
Storage Samsung 2TB SSD
Display(s) Asus VE276Q, VE278Q and VK278Q triple 27” 1920x1080
Case Zulman MS800
Audio Device(s) On Board
Power Supply Seasonic 650W
VR HMD Oculus Rift, Oculus Quest V1, Oculus Quest 2
Software Windows 11 64bit
Right there is the WD My Book line of drives which are USB and can be quite cheap. I have bought a number of WD My Book USB and WD EasyStore USB drives at 8TB for ~$159. I also bought a WD MyBook Duo 16TB which had 2x 8TB drives. All were WD Red 8TB drives. The MyBook Duo drives themselves are under warranty in or out of the enclosure.

Then there are the WD MyCloud line of products which are NAS units. They come in single drive, dual drive and quad drive models. I bought a WD MyCloud EX2 (discless, as in no included drives) a while back and I wasn’t impressed with it. The WD interface software (Linux OS) implementation is extremely weak. One of the worst I’ve ever seen. If it is actually coming from D-Link then fine but but no matter what it’s not something you’ll likely want to use even if this security related issue were not a problem. I took my WD MyCloud EX2 offline long ago and upgraded to a Synology I bay model. I’m thinking of upgrading again to a QNAP 12 or 16 bay sometime this year.

Maybe something in the QNAP TVS-1282 line so it can double as a NAS and a DAS.
 
Top