WD Sharespace - Hackable?
Forum » Forum / My Book World Edition (blue rings) » WD Sharespace - Hackable?
Started by: alephsmithalephsmith
On: 1231545228|%e %b %Y, %H:%M %Z|agohover
Number of posts: 21
rss icon RSS: New posts
Summary:
Has anyone got one? Can it be hacked in a similar manner?
WD Sharespace - Hackable?
alephsmithalephsmith 1231545228|%e %b %Y, %H:%M %Z|agohover

Was just browsing at the shops and saw this: http://www.wdc.com/en/products/Products.asp?DriveID=501

Has anyone got one? Can it be hacked? At the price it is going for I'd except it to get better network performance than our little boxen.

From the WD site:

High-speed access, Ethernet connectivity - Provides data transfer rates up to 1000 Mbit/s when used in a GigE network

unfold WD Sharespace - Hackable? by alephsmithalephsmith, 1231545228|%e %b %Y, %H:%M %Z|agohover
Re: WD Sharespace - Hackable?
kwyjibokwyjibo 1235015161|%e %b %Y, %H:%M %Z|agohover

I have just got one as a replacement for the MyBook. It is hackable in the sense that it is running Linux and GPL source code
is available. It does not have sshd installed/built as shipped so the 'hack' would not be as easy as the MyBook (no gcc either).

  • just an update, there is a telnet daemon which can be activated via a special url, the only user account with a shell however

is root and without the root password the only way to access the box is to mount the disks in a separate pc and replace the root password.. And really if you are doing that you may as well build an sshd for it anyway or at least just alter inetd.conf to get telnet at boot.

last edited on 1236135481|%e %b %Y, %H:%M %Z|agohover by kwyjibo + show more
unfold Re: WD Sharespace - Hackable? by kwyjibokwyjibo, 1235015161|%e %b %Y, %H:%M %Z|agohover
Re: WD Sharespace - Hackable?
ETMegabyteETMegabyte 1242431434|%e %b %Y, %H:%M %Z|agohover

Wouldn't it be easier to add a shell to a regular user account? edit /etc/passwd and put a shell at the end of a regular user's line?

Just a thought.

-ET

unfold Re: WD Sharespace - Hackable? by ETMegabyteETMegabyte, 1242431434|%e %b %Y, %H:%M %Z|agohover
Re: WD Sharespace - Hackable?
goternemegoterneme 1231555844|%e %b %Y, %H:%M %Z|agohover

yeah, thats what they told us already before we bought the MYbook World Edition ;)

I would ask them first via support etc. for memory and cpu

greetz

unfold Re: WD Sharespace - Hackable? by goternemegoterneme, 1231555844|%e %b %Y, %H:%M %Z|agohover
Re: WD Sharespace - Hackable?
TeinturManTeinturMan 1231592118|%e %b %Y, %H:%M %Z|agohover

I have checked some articles in google it seems that it is as slow as the Mybook 500GB…

the main advantage is that It can hold 4 drives in a nice box…

unfold Re: WD Sharespace - Hackable? by TeinturManTeinturMan, 1231592118|%e %b %Y, %H:%M %Z|agohover
Re: WD Sharespace - Hackable?
goternemegoterneme 1231595892|%e %b %Y, %H:%M %Z|agohover

yeah, tought that :D

unfold Re: WD Sharespace - Hackable? by goternemegoterneme, 1231595892|%e %b %Y, %H:%M %Z|agohover
Re: WD Sharespace - Hackable?
blackjancsiblackjancsi 1243854541|%e %b %Y, %H:%M %Z|agohover

Very true - then we bought it and fastest transfer speeds were 3 MB/s… :-s (as confirmed to me by tech support as well)

unfold Re: WD Sharespace - Hackable? by blackjancsiblackjancsi, 1243854541|%e %b %Y, %H:%M %Z|agohover
WD Sharespace compared to QNap TS-509 and Netgear ReadyNAS
JpgOrganizerJpgOrganizer 1232300595|%e %b %Y, %H:%M %Z|agohover

I've seen an article in the newest c't magazine (ed. 3/2009). This is a German IT magazine. The article is not available in internet. They have tested the QNap TS-509 Pro Turbo NAS, WD Sharespace and Netgear ReadyNAS Pro Business Edition.

Here are the results of the performance tests:

Model SMB/CIFS write [MBytes/s] SMB/CIFS read [MBytes/s]
Netgear ReadyNAS Pro Business Edition 84 104
QNap TS-509 Pro Turbo NAS 70 101
WD Sharespace 12 28

If you compare the performance of these models to our MBWE, then you have to compare the price too:
ReadyNAS ~3900 EUR (6x1TB discs), TS-509 ~770 EUR (without discs), WD Sharespace ~660 EUR (2x1TB discs) (all prices from test report)

Regards,
JpgOrganizer


MBWE II, 2x 500 GB
Firmware 01.01.18
Raid 1
Hacks: SSH, spindown


MBWE II (blue rings), 2x 500 GB in Raid 1 mode
Firmware 01.01.18
Hacks: SSH, spindown
Applications: optware, dokuwiki, nightly backup script

last edited on 1232300658|%e %b %Y, %H:%M %Z|agohover by JpgOrganizer + show more
Re: WD Sharespace compared to QNap TS-509 and Netgear ReadyNAS
goternemegoterneme 1232304136|%e %b %Y, %H:%M %Z|agohover

realisticly you'll have bout 7-9 mybtes, when i turn ervything off on mybook then ill get that too ;)

Re: WD Sharespace - Hackable?
kwyjibokwyjibo 1236744263|%e %b %Y, %H:%M %Z|agohover

I just added a sharespace page on the wiki with details of what you can do.

unfold Re: WD Sharespace - Hackable? by kwyjibokwyjibo, 1236744263|%e %b %Y, %H:%M %Z|agohover
Re: WD Sharespace - Hackable?
JimboLadJimboLad 1236884351|%e %b %Y, %H:%M %Z|agohover

Hello,

I'm a newby in NAS Systems running on Linux. I'm trying to enable telnet on my Sharespace, but I'm stuck.
I have read the wiki, but I don't know what to do.
The only OS I can use to mount the filesystem, is Windows XP. Where can I find the inetd.conf?
How can I gain access to the real filesystem from a XP commandprompt?

unfold Re: WD Sharespace - Hackable? by JimboLadJimboLad, 1236884351|%e %b %Y, %H:%M %Z|agohover
Re: WD Sharespace - Hackable?
kwyjibokwyjibo 1236920241|%e %b %Y, %H:%M %Z|agohover

The best option is to download 'damn small linux' or 'slax' any of those small distro's that will live boot from a cd
or usb stick. Some are easier than others as far as auto mounting disks and things (Puppy Linux is very 1 click gui driven).

A few things to remember, depending on how you have your ShareSpace setup you can loose anything stored on it by
making changes to just 1 disk in a Raid. Unlike the mybook you can't permanently brick your box, if you trash the filesystem you can
just zero the disk and the sharespace will reformat it and rebuild a default filesystem.

you should find a live distro and then work out how to mount a disk once you have that figured out you will find inetd.conf under
$yourmountpoint/etc/inetd.conf (where $yourmountpoint is whatever you have it mounted too ie /mnt/sdb1)

If i get some time I will have a look for a possible php or mini_httpd exploit to enable telnet without having to mount the disks, but for now it is the easiest way.

unfold Re: WD Sharespace - Hackable? by kwyjibokwyjibo, 1236920241|%e %b %Y, %H:%M %Z|agohover
Re: WD Sharespace - Hackable?
lowkeylowkey 1238711583|%e %b %Y, %H:%M %Z|agohover

OK, so I want to mount the root filesystem.

What do I specify for the mount command?

mount -t nfs <IP>:/WHAT? /mnt/point

unfold Re: WD Sharespace - Hackable? by lowkeylowkey, 1238711583|%e %b %Y, %H:%M %Z|agohover
Re: WD Sharespace - Hackable?
gaaronkgaaronk 1244217757|%e %b %Y, %H:%M %Z|agohover

This is a hack a WD ShareSpace with new firmware

1. Enable "Downloader" function in Storage - Downloads
2. Save configure file from device
file like this config-WDShareSpace.20090604153042.xml
3. Unpack and decrypt configure file

./decodex -k="Nj1e2w0a0b" ./config-WDShareSpace.20090604153042.xml ./uploadconfig.xml.tar
tar -xvf ./uploadconfig.xml.tar
rm config.xml.md5

4. Edit config.xml file
that something like this to increase by one
<lastchange>1243940739</lastchange>

search for a similar line
<downloadshare>/DataVolume/Download</downloadshare>

replace it with this
<downloadshare>/etc/init.d</downloadshare>

5. Pack end encrypt new config
md5sum config.xml > config.xml.md5
tar cf config.xml config.xml.md5 config.xml.tar
./encodex -k="Nj1e2w0a0b" ./config.xml.tar config.xml.xtx
mv config.xml.xtx config-WDShareSpace.20090604153050.xml

6. Make a "General restore" with new configure file. data is not lost

7. Make file like this

#!/bin/sh

case "$1" in
  start)
    echo "telnet stream tcp nowait root /usr/sbin/telnetd /usr/sbin/telnetd" >>/etc/inetd.conf
    ;;
    *)
    exit 1
esac

exit $?

name it S50hack.sh and put on the web or ftp server

extension ".sh" is very important

7. Go to "downloader" interface of WD and add this S50hack.sh to download task - like http://yourwebserver/S50hack.sh

8. Reboot the WD ShareSpace

9. Telnet to ShareSpace with l:root and p:welc0me

10. rm /etc/init.d/S50hack.sh

11. Go to Downloader WEB user interface and remove incomlete task

12. Restore old configure file (via web interface)

PS use encodex/decodex from this url: http://www.geodyssey.com/cryptography/textec.html

last edited on 1244260433|%e %b %Y, %H:%M %Z|agohover by gaaronk + show more
unfold Re: WD Sharespace - Hackable? by gaaronkgaaronk, 1244217757|%e %b %Y, %H:%M %Z|agohover
Re: WD Sharespace - Hackable?
moop2000moop2000 1246077336|%e %b %Y, %H:%M %Z|agohover

gaaronk,
So I've tried your instructions, but I can never get past the uploading and general restore of the configuration. Whenever I try, it just tells me invalid file uploaded. Any suggestions that I should go back to double check? I use encodex/decodex from the site you linked to.
Thanks!

unfold Re: WD Sharespace - Hackable? by moop2000moop2000, 1246077336|%e %b %Y, %H:%M %Z|agohover
Re: WD Sharespace - Hackable?
zimozimo 1246149374|%e %b %Y, %H:%M %Z|agohover

Hey,

l just found this about 30 mins ago and tried it to the letter and got same issue so then l did it again but when making changes to the file l did not touch <lastchange>1243940739</lastchange> l only made changes to <downloadshare>/DataVolume/Download</downloadshare> and it worked,

Thanx Mate.

unfold Re: WD Sharespace - Hackable? by zimozimo, 1246149374|%e %b %Y, %H:%M %Z|agohover
Re: WD Sharespace - Hackable?
gaaronkgaaronk 1246169282|%e %b %Y, %H:%M %Z|agohover

Hello!

I increased the number one lastchange and number in the file name.
For example, it was

<lastchange>1243940739</lastchange>
config-WDShareSpace.20090604153042.xml

and get

<lastchange>1243940740</lastchange>
config-WDShareSpace.20090604153043.xml

Try not to touch lastchange

last edited on 1246169319|%e %b %Y, %H:%M %Z|agohover by gaaronk + show more
unfold Re: WD Sharespace - Hackable? by gaaronkgaaronk, 1246169282|%e %b %Y, %H:%M %Z|agohover
Re: WD Sharespace - Hackable?
SCJSCJ 1248701703|%e %b %Y, %H:%M %Z|agohover

Hello !
I've a problem with sharespace and I want to try to fix it with telnet. And I've tried garronk's instructions but I've the same message than moop2000: "Invalid file uploaded".
And In fact, my initial problem is :
1/ I've my sharespace on my enterprise domain => it's OK
2/ I've created shared directory : "Test" => it's OK, I see this directory from a windows XP computer
3/ I've created a directory from XP computer : I can modify, delete it => it's OK
4/ I've created a file from XP computer: I can modify it but I don't delete it or not replace it.
thanks.

unfold Re: WD Sharespace - Hackable? by SCJSCJ, 1248701703|%e %b %Y, %H:%M %Z|agohover
Re: WD Sharespace - Hackable?
gaaronkgaaronk 1250846869|%e %b %Y, %H:%M %Z|agohover

This is new firmware version 2.1.92
Added SSH Service ability

unfold Re: WD Sharespace - Hackable? by gaaronkgaaronk, 1250846869|%e %b %Y, %H:%M %Z|agohover
Re: WD Sharespace - Hackable?
GlowDogGlowDog 1257637583|%e %b %Y, %H:%M %Z|agohover

Well I managed to do it all, but the telnet just doesnt work :( what can I be doing wrong ? if I download the config and decode the download share is /etc/init.d but after reboot no ssh nor telnet possible :(

unfold Re: WD Sharespace - Hackable? by GlowDogGlowDog, 1257637583|%e %b %Y, %H:%M %Z|agohover
Re: WD Sharespace - Hackable?
GlowDogGlowDog 1257859153|%e %b %Y, %H:%M %Z|agohover

Got a bit further on the problem. Last time I tried also changed a sharename in the config. After the whole packing/encoding/uploading/restoring/rebooting process … still the old sharename !

so for some reason the changes in the config are not accepted :S

unfold Re: WD Sharespace - Hackable? by GlowDogGlowDog, 1257859153|%e %b %Y, %H:%M %Z|agohover
New post
Unless otherwise stated, the content of this page is licensed under Creative Commons Attribution-ShareAlike 3.0 License