9 ms·
Hard drive hack provides root access, even after reinstall
- deleted 13y ago[deleted]
- wiredfool 13y agoInstalling linux on a hard drive never sounded impressive before.
- cupcake-unicorn 13y agoWell, to be fair, it's a bit of a pain with UEFI. But this is really amazing. I'd love to see how it could be extended to other OSes, if possible?
- McGlockenshire 13y agoI'm not sure about the other controllers, but if this one has a Cortex M3, then anything that runs on an M3 could hypothetically be ported. One of the SE sites assembled a list. Shockingly, the question isn't closed yet! http://electronics.stackexchange.com/questions/27594/what-operating-systems-have-been-ported-to-cortex-m3 http://electronics.stackexchange.com/questions/27594/what-op...
- 0x0 13y agoThe Feroceon CPUs are pretty hefty too. They're powering the Marvell Kirkwood platform which is used in things like the Sheevaplug and some of the QNAP TS-* NAS devices. Debian runs great on those. (2.0ghz CPU, 512mb ram). Probably the biggest trouble here is the lack of an MMU (?) .
- mcpherrinm 13y agouclinux can run on mmu-less systems, so I do suspect you can run Linux on this hard drive.
- yuhong 13y agoI think some hard drives like some Seagates has a serial console in the firmware that provides low level access that data recovery companies for example use.
- 0x0 13y agoI'd love to read more info about this!
- yuhong 13y agohttp://www.msfn.org/board/topic/128807-the-solution-for-seagate-720011-hdds/ http://www.msfn.org/board/topic/128807-the-solution-for-seag... http://elabz.com/forums/electronics-repairs/list-of-seagate-firmware-terminal-commands/ http://elabz.com/forums/electronics-repairs/list-of-seagate-...
- swang 13y agoDoes a jellybean part just mean its very common?
- dsr_ 13y agoYes, it means that you can buy them like jellybeans (and they're about the same size, and black, which is either the best or worst flavor.)
- wereHamster 13y ago> Because Linux caches the shadow file (like all files recently accessed), I have to generate a lot of disk activity for the file to be 'pushed out' of the cache http://linux-mm.org/Drop_Caches http://linux-mm.org/Drop_Caches $ echo 3 > /proc/sys/vm/drop_caches or as non-root $ echo 3 | sudo tee /proc/sys/vm/drop_caches
- 0x0 13y agoI think the idea is you force a disk read or write operation by interacting with the system remotely (for example uploading a file or sending a particular HTTP GET request that ends up in the log), without having shell access or write access to /proc :)
- DHowett 13y agoI do not believe that using sudo exactly counts as "non-root".
- switch007 13y agoThey meant "when not root".
- graue 13y agoIn the attack scenario here, the author doesn't (yet) have root access.
- 0x0 13y agoThis is incredibly scary. Will HD vendors start implementing firmware code signing anytime soon? Or will some enterprising hackers start working on an open source firmware implementation?
- korethr 13y agoThis is very cool. I have a pile of dead and old hard drives. I should see if my local hackerspace has something that can connect to JTAG, and if so, see what secrets the old drives contain.
- kabdib 13y agoMy knee-jerk reaction was, why didn't WD sign the code and use on-chip fuses and a secure boot path to verify the code before transferring control to anything outside their boot ROM? (Many ARM-based systems-on-a-chip are capable of doing this). Adds cost, for one thing. But you can arrange for the unit to never run a byte of code (even one loaded from the platter) that didn't come from WD.
- achille2 13y agoThe knee jerk reaction to secure boot-anything from the technical community has been generally "No!", "It's a trap" etc.
- sspiff 13y agoFor PC's and smartphones, which can have higher level security structures, the community is violently against secure boot. For firmware based embedded components, most people aren't so strongly opposed to it.
- icebraining 13y agoNot that their opinion is the community's, but the FSF is not against secure boot even for PCs and smartphones, only against "restricted boot" - that is, secure boot without giving the keys to the user.
- venomsnake 13y agoThe knee jerk reaction is not to secure boot but to who has the ability to set the keys. The technical community likes to be in control of that.
- aray 13y agoThat is closely tied to "who gets to audit the source". E.g. the FOSS community wasn't a fan of only-trusted-secure-boot when it was microsoft holding the keys and the source and releasing neither.
- 13y ago
- quasque 13y agoA fascinating read, and an excellent piece of work. It reminds me of a similar proof-of-concept hack on a common network card firmware: http://esec-lab.sogeti.com/post/2010/11/21/Presentation-at-Hack.lu-:-Reversing-the-Broacom-NetExtreme-s-firmware http://esec-lab.sogeti.com/post/2010/11/21/Presentation-at-H... (the slides linked from that page have a good more technical overview that the blog post).
- batiste 13y agoThe first hack read on hacker new I have seen for a long time.
- deleted 13y ago[deleted]
- AsymetricCom 13y agoWhat? You don't consider "growth hacking" real hacking?
- mindslight 13y agoThat depends if you're just buying the pills from the spams or going to the hardware store and building your own pumps etc.
- huhtenberg 13y agoI really hope you are being ironic.
- gabriel34 13y agoWell, HN is not just about hacks, but I did expect more contente derived from Black Hat. EDIT: right now on page 1: https://news.ycombinator.com/item?id=6146279 https://news.ycombinator.com/item?id=6146279
- jrarredondo 13y agoAfter reading this, i know I am unworthy to comment. However, I will be forwarding this to my wife who gives me a hard time when I, before getting rid of an old computer, remove the HD and give five or so well placed hits with a hammer on the whole HD assembly.
- deleted 13y ago[deleted]
- gabriel34 13y agoCould this attack compromisse dedicated/rent servers? If so, the attacker could rent, install the exploit on the hardware and terminate the contract. What about cloud servers? Sure there are virtualization layers, but can't those be breached? If so that would pose imense danger given the distributed nature the hardware exploit could render the entire farm vulnerable
- testbro 13y agoThe attack could compromise other servers yes. I think the scenario you describe is a possibility, although there are some technical feats that would make wide-scale exploitation difficult - you need to know what you want to modify ahead of time which would be difficult. Virtualised environments that don't pass the vendor specific commands should be immune to the attack though. As others have said, encryption would probably allow tampered pages to be detected. I'd be interested to see if the modified firmware could ignore new firmware...
- cbhl 13y ago> encryption would probably allow tampered pages to be detected Careful! It can, but doesn't always. For example, eCryptfs currently doesn't protect against tampering; it uses Cipher Block Chaining (CBC) mode without a HMAC or other signature. (I'm working with some colleagues to add Galois/Counter Mode (GCM) support to eCryptfs, which does provide some form of tamper-detection.)
- munin 13y agosomething I hadn't really considered about hard disk encryption, before reading this, is how it could protect against compromised disk controllers. if the OS encrypts the data stored on the disk, it would be a lot harder (perhaps, with the right composition, impossible) for a malicious disk controller to insert/change/modify important data (like code, or password files) stored on the computer. we think of the system as a holistic entity, but turned on its head, you can see how the inside of a computer is just a network...
- im3w1l 13y agoMaybe I misunderstood, but didn't the harddrive have direct memory access (DMA)?
- __david__ 13y agoIt had DMA to its own memory, not to the host computer's memory.
- MBCook 13y agoThe DMA mentioned in the article was internal to the drive, between the hardware interfaces and it's internal cache. The drive did not have DMA access to system memory.
- 0x0 13y agoEven though it wasn't discussed in the article, I think firewire and thunderbolt external drives DO have direct DMA access to system memory. Google for SBP-2 and DMA, and a bunch of articles about protecting against firewire attacks against full-disk-encryption (among other things) appear.
- MBCook 13y agoI know you're right on FW. I believe DMA was designed in because they recognized that the CPUs of the time weren't powerful enough to move uncompressed full-resolution video from around. I don't know about Thunderbolt, but I'd expect you're right.
- dnautics 13y agowhat is that cortex-M3 chip doing? Did the NSA put it there?
- losethos 13y agoFucken Moron. Why do you think 90% of the world believes in God? Retard. Can you personally prove relativity? Someone can--why do you believe. God spoke to someone. God says... C:\TAD\Text\WEALTH.TXT e very circumstance which ought certainly to alleviate it, the temptation to commit the crime. {See Sketches of the History of Man page 474, and Seq.} Fourthly, by subjecting the people to the frequent visits and the odious examination of the tax-gatherers, it may expose them to much unnecessary trouble, vexation, and oppression; and though vexation is not, strictly speaking, expense, it is certainly equivalent to the expense at which every man would be willing to redeem himself from it. It is in so ---- God can kill with a word.
- deleted 13y ago[deleted]
- WestCoastJustin 13y agoIf you liked this, then you might like Travis Goodspeed's really cool talk about "Writing a Thumbdrive from Scratch" (for antiforensics) [1] at the 29th Chaos Communication Congress [29c3]. [1] http://www.youtube.com/watch?v=D8Im0_KUEf8 http://www.youtube.com/watch?v=D8Im0_KUEf8
- maqr 13y agoTravis Goodspeed is one of my favorite bloggers. Definitely worth checking out if you like this kind of stuff: http://travisgoodspeed.blogspot.com/ http://travisgoodspeed.blogspot.com/
- Florin_Andrei 13y agoAt some point, computer systems will be more like biologic systems - they will just carry a more or less permanent "flora" of parasites, that will have to be tolerated unless they become explicitly hostile. Any sufficiently complex system will exhibit this trait sooner or later.
- Hellenion 13y agoThat's an interesting way of looking at "parasitic" programs. Maybe we could even get those parasites to work for us, like trapping them as the house pen-tester. You could employ the constant barrage of attempted ssh logins as remote connectivity check or something.
- ChuckMcM 13y agoThis was a great read. One of the things we've done in the past is to modify the firmware of the drive to be able to give errors on command. The purpose was for testing RAID systems in real life scenarios. One can include a 'unit test' drive in a RAID array which will run through a series of known bad disk behaviours. From the simple like returning read failure, to the more complex like returning the wrong block or returning a block that has been silently corrupted (both things NetApp observed in the wild on 'real' drives), and my personal favourite acknowledging a write but not actually writing the data (nearly killed the Cisco relationship they had at the time)
- stephengillie 13y agoI especially like the idea of cannibalizing old HDDs (with bad spindles but good controllers) to become microcontrollers in new projects.
- aray 13y agoNot a bad idea, but also nearly everything we interact with, technology-wise, has microcontrollers of some form or another. The AVRs so adored by the arduino community actually exist in large volumes in automobiles, and even crappy USB keyboards and mice which we might throw out have microcontrollers in them. So I'm all for scavenging compute bits for future projects, but it is by no means unique to HDDs.
- ChuckMcM 13y agoThe key is tools, and OpenOCD is one of them, which let you "talk" to these systems. I picked up a Black Magic probe [1] and am building cables for it to talk to one of my ARM boards. That kind of stuff makes the spelunking possible. [1] http://www.blacksphere.co.nz/main/blackmagic http://www.blacksphere.co.nz/main/blackmagic
- logicallee 13y agoalso the things cost pennies! For example the ATMEGA328 will run you a grand total of $2.88 in a quantity of 1.
- b0rsuk 13y agoThat's a whole world of spying opportunities. A government could make secret deals with hard drive manufacturers. Perhaps not US government, but Taiwan government, if it makes you happier... (I'm from neither country)
- mariusz79 13y agoCould? How do you know they didn't do it already?
- lsc 13y agoThe thing that interests me, though, is the idea of modifying your hard drive firmware for better performance. My understanding is that the effective width of the write head is 10x the width of the read head... E.g. with the right firmware, it should be possible, if you are okay with a write-once medium, to write the outermost track, move the write head in 1/10th what you'd normally move it, then write the next track, etc... and get 10x the space out of the drive you normally would. In theory, the read head wouldn't have trouble. (of course, this would be write once storage, as the effective width of your write head is still pretty huge; but for a bunch of things? I can totally work with that... if more than X% of a drive was garbage data, I copy the good data to a new drive and reformat the old one. Done.) I hear rumors that both the major drive manufacturers are actually shipping drives with this technology, but are only selling those drives to really big players, for some reason. Here's a reasonable reference to the 'shingle' technology, and he roadmap for the rest of us: http://www.theregister.co.uk/2013/06/25/wd_shingles_hamr_roadmap/ http://www.theregister.co.uk/2013/06/25/wd_shingles_hamr_roa... but that's the thing, with the datasheets (and, well, a lot more skill than I personally have) we should be able to setup something like shingling on the cheap disks we have today. Of course, from reading the article, I'm not sure I'm any closer to that particular dream.
- magila 13y agoShingled writes require a special asymmetrical write head, you can't do it with current drives. Actual shingled write drives are not yet shipping AFAIK.
- lsc 13y agoI'm just using shingled writes as one example. Your kernel could, for example, more efficiently reorder reads and writes with more information about the physical drive layout. Hell, just removing the bad-sector remapping (and moving it up to the kernel or the like) would help solve the performance degradation that remapped sectors cause during apparently sequential reads/writes.
- AsymetricCom 13y ago
- brudgers 13y agoGreat article. But what I came away from it thinking was about how much money is spent by state security institutions to prevent this sort of thing, and yet secrecy breeches at scale are the Walkers, Mannings, and Snowdens using USB sticks and DVD's and copiers.
- vlr 13y agoI remember Dejan Kalijevik from them nokia s/w. Is he talking of the same Dejan?
- x0054 13y agoThis is some hard core hacking! Love it! First, as others mentioned, this is why you should always encrypt your os drives. Second, it also got me thinking, how many other devices are open to this kind of attack. Like a network switch, perhaps? Say you buy 100 network switches, alter the firmware to call home and maybe even load a Linux instance, and then resell them on amazon, eBay, or even better, give a "good" cash deal to some local IT company. Then you just seat back and wait for your 100 bots to call home for their new business class Internet homes.