MultiDrive – free backup, clone & wipe disk utility from Atola Technology

All times are UTC - 5 hours [ DST ]


Forum rules


Please do not post questions about data recovery cases here (use this forum instead). This forum is for topics on finding new ways to recover data. Accessing firmware, writing programs, reading bits off the platter, recovering data from dust...



Post new topic Reply to topic  [ 110 posts ]  Go to page Previous  1, 2, 3, 4, 5, 6  Next
Author Message
 Post subject: Re: WD MCU - No more...
PostPosted: September 2nd, 2026, 15:40 
Offline
User avatar

Joined: September 29th, 2005, 12:02
Posts: 3593
Location: Chicago
fzabkar wrote:
Please excuse ignorant me for asking the obvious question, would @einstein9, or his researchers, not have tested this claim by modifying the copy of the key?

indeed it would be very interesting to know

_________________
SAN, NAS, RAID, Server, and HDD Data Recovery.


Top
 Profile  
 
 Post subject: Re: WD MCU - No more...
PostPosted: September 2nd, 2026, 16:17 
Offline

Joined: October 21st, 2007, 8:48
Posts: 1729
Doomer wrote:
unknown wrote:
That means there's no constant keys located in the FW to compare with the one created randomly in MCU?. If I understand well.

If the keys would have been constant there would be no point using original MCU, any MCU would work.

I see, thank you.


Top
 Profile  
 
 Post subject: Re: WD MCU - No more...
PostPosted: September 3rd, 2026, 3:58 
Offline
User avatar

Joined: May 13th, 2010, 11:17
Posts: 2848
Location: Kuwait
pepe wrote:
even without ROM?


this is totally diff. scenario

_________________
Kuwait Data Recovery - UNIX GTC
The only reason for time is so that everything doesn't happen at once. By: Albert Einstein


Top
 Profile  
 
 Post subject: Re: WD MCU - No more...
PostPosted: September 3rd, 2026, 4:07 
Offline
User avatar

Joined: May 13th, 2010, 11:17
Posts: 2848
Location: Kuwait
Doomer wrote:
einstein9 wrote:
When drive powers ON drive reads & compares both if match will carry on booting

This is very doubtful.
At least I have never seen any comparison.


Then do you have another opinion about this?

I said: When drive powers ON it compares both keys the one on drive SA with the MCU if both match then data will be decrypted if not matching data will be encrypted.
and i link this statement with the enc. pattern when we try diff. donor PCBs (means diff. keys) with the same drive. try it, compare it and then you will understand my point here.

_________________
Kuwait Data Recovery - UNIX GTC
The only reason for time is so that everything doesn't happen at once. By: Albert Einstein


Top
 Profile  
 
 Post subject: Re: WD MCU - No more...
PostPosted: September 3rd, 2026, 4:25 
Offline

Joined: October 3rd, 2005, 0:40
Posts: 4816
Location: Hungary
I doubt it does any comparison.
Data is decrypted using the MCU key even if it is not native. Decryption will be wrong of course, so data is garbage in this case, but still decrypted.
and as you say, you get different decrypted data with different mcus, this lines up with my interpretation.

_________________
Adatmentés - Data recovery


Top
 Profile  
 
 Post subject: Re: WD MCU - No more...
PostPosted: September 3rd, 2026, 6:11 
Offline
User avatar

Joined: September 8th, 2009, 18:21
Posts: 17226
Location: Australia
@einstein9, if there is a copy of the key in the SA, then why do you need the patient MCU at all? Just install the donor PCB + donor MCU + patient adaptives on the patient HDA, recover the key from the SA, and then write the key to the donor MCU, or decrypt in software.

_________________
A backup a day keeps DR away.


Top
 Profile  
 
 Post subject: Re: WD MCU - No more...
PostPosted: September 3rd, 2026, 6:36 
Offline
User avatar

Joined: May 13th, 2010, 11:17
Posts: 2848
Location: Kuwait
pepe wrote:
I doubt it does any comparison.
Data is decrypted using the MCU key even if it is not native. Decryption will be wrong of course, so data is garbage in this case, but still decrypted.
and as you say, you get different decrypted data with different mcus, this lines up with my interpretation.


I tested it myself, writing Native Key to donor MCU ----> drive worked normal as native mcu/pcb (procedure takes time)

@fzabkar

"if there is a copy of the key in the SA, then why do you need the patient MCU at all? Just install the donor PCB + donor MCU + patient adaptives on the patient HDA, recover the key from the SA, and then write the key to the donor MCU, or decrypt in software."

Just install the (donor PCB + donor MCU) which are ONE + patient adaptives which is ROM here
donor PCB/MCU has Diff. key here.

_________________
Kuwait Data Recovery - UNIX GTC
The only reason for time is so that everything doesn't happen at once. By: Albert Einstein


Top
 Profile  
 
 Post subject: Re: WD MCU - No more...
PostPosted: September 3rd, 2026, 7:17 
Offline
User avatar

Joined: September 8th, 2009, 18:21
Posts: 17226
Location: Australia
einstein9 wrote:
Just install the (donor PCB + donor MCU) which are ONE + patient adaptives which is ROM here
donor PCB/MCU has Diff. key here.

Yes, of course, that's what I meant. But you didn't answer my question. If you can extract a copy of the patient's MCU key from the patient's SA, why do you need the patient's MCU?

_________________
A backup a day keeps DR away.


Top
 Profile  
 
 Post subject: Re: WD MCU - No more...
PostPosted: September 3rd, 2026, 7:48 
Offline
User avatar

Joined: May 13th, 2010, 11:17
Posts: 2848
Location: Kuwait
fzabkar wrote:
einstein9 wrote:
Just install the (donor PCB + donor MCU) which are ONE + patient adaptives which is ROM here
donor PCB/MCU has Diff. key here.

Yes, of course, that's what I meant. But you didn't answer my question. If you can extract a copy of the patient's MCU key from the patient's SA, why do you need the patient's MCU?


In another form, if you write native ROM to another SATA PCB data is encrypted why?

because PCB MCU KEY & HDD KEY are not the same.

_________________
Kuwait Data Recovery - UNIX GTC
The only reason for time is so that everything doesn't happen at once. By: Albert Einstein


Top
 Profile  
 
 Post subject: Re: WD MCU - No more...
PostPosted: September 3rd, 2026, 9:55 
Offline

Joined: October 3rd, 2005, 0:40
Posts: 4816
Location: Hungary
"in another form"???
if it is there, what prevents you from decoding it and use it with the donor mcu?

or you don't want to talk about it, that's perfectly understandable as well, just say so.

_________________
Adatmentés - Data recovery


Top
 Profile  
 
 Post subject: Re: WD MCU - No more...
PostPosted: September 4th, 2026, 11:10 
Offline
User avatar

Joined: September 8th, 2009, 18:21
Posts: 17226
Location: Australia
einstein9 wrote:
I said: When drive powers ON it compares both keys the one on drive SA with the MCU if both match then data will be decrypted if not matching data will be encrypted.

If the comparison succeeds, the firmware will use the MCU key to decrypt the data.

If the comparison fails, the firmware will use the MCU key to decrypt the data.

What is the point of a comparison if the result is ignored?

If you can identify the code that executes the comparison, would it be possible to modify it so that it writes the key(s) to an accessible part of memory or ROM or SA?

_________________
A backup a day keeps DR away.


Top
 Profile  
 
 Post subject: Re: WD MCU - No more...
PostPosted: September 4th, 2026, 15:26 
Offline

Joined: May 9th, 2024, 14:00
Posts: 7
Location: india
einstein9 wrote:
Quick for you guys:

Suppose someone replaced the "native usb3 pcb" with another and he wrote native rom to it

Anyone knows how to tell if this pcb is for that drive? (in case if both pcbs have the same native ROM)

:!:

The PCB has a QR code. It contains something like the PCB serial number.
You can see this serial number in the second sector of module 8003. It can be seen among the many symbols in the right field.
Test this method on a working HDD to see for yourself.


Top
 Profile  
 
 Post subject: Re: WD MCU - No more...
PostPosted: September 4th, 2026, 15:29 
Offline

Joined: May 9th, 2024, 14:00
Posts: 7
Location: india
einstein9 wrote:
samstown wrote:
Is there any update ?


Of course there is..

here is how the MCU unique code looks like..
close to figure out the equation with a shortcut to bypass :idea:

Also first sector of module 8003 has this unique MCU Code.

MSM DATA RECOVERY


Top
 Profile  
 
 Post subject: Re: WD MCU - No more...
PostPosted: September 4th, 2026, 15:34 
Offline

Joined: May 9th, 2024, 14:00
Posts: 7
Location: india
pepe wrote:
even without ROM?

If we can access SA modules. Why not :?:


Top
 Profile  
 
 Post subject: Re: WD MCU - No more...
PostPosted: September 4th, 2026, 15:42 
Offline
User avatar

Joined: September 8th, 2009, 18:21
Posts: 17226
Location: Australia
Thanks @msmdatarecovery.

_________________
A backup a day keeps DR away.


Top
 Profile  
 
 Post subject: Re: WD MCU - No more...
PostPosted: September 4th, 2026, 16:20 
Offline

Joined: May 9th, 2024, 14:00
Posts: 7
Location: india
:agree:
fzabkar wrote:
Thanks @msmdatarecovery.

:agree:


Top
 Profile  
 
 Post subject: Re: WD MCU - No more...
PostPosted: September 4th, 2026, 22:30 
Offline
User avatar

Joined: September 8th, 2009, 18:21
Posts: 17226
Location: Australia
None of these records seems random.

Charger

Code:
H1 2063 81      01121P4000000P
71BCFA13YEEKPC5
7I 2053 80 0780 40509H01001999 9506 0FBMT
8S 2053 80 0766 00003H02001999 9416 0OC00
9I 2053 80 0805 0070301809033D 8Y16 530B6
AL 2053 80 0845 001AASWEB38G9D 9611 32900
DH 2R53 80 0891 00000B43T000ZD 9728 35800
JI 2059 81 0008 B1A05ANNN05GNN 9604 A6091
KI 2053 81 0057 00003000042302 9424 BLKUE
MI 2096 80 0049 5B4BZXUCMBA21J 9510
MI 2096 80 0049 5B4BZXUWLBA21J 9509
ON 2053 80 0684 000AA19056303B 9517 00500
PI 2053 80 0767 00004TM0000000 9518 DAPN8
VI 2053 80 0770 00004SC0001210 9513 24245

SpyGlass3

Code:
H4 2063 81      06734W8000000W
74H14T11F99WWS9
37 2053 80 0262 000AA124040000 4723 08200
7I 2053 81 0201 000AAITH020000 4618 030DS
81 2053 80 0196 000AATDI010000 4527 38000
AM 2053 80 0845 001AADMEB00440 4829 05100
BZ 2053 80 0539 000AASWEB24G96 4613 04600
DC 2053 80 0729 00002000000000 4611 BJR00
JI 2059 80 0012 R5AADQFETADTJT 4910 03271
KI 2053 80 0176 713AET6A01XT1T 4904 284BR
MI 2096 80 0020 5GDBZXU1VBA33A 4911
MI 2096 80 0020 5GDBZXUTABA33A 4911
PI 2053 80 0169 000AASM0001210 4831 04321
VI 2053 80 0168 000AASM0001210 4831 21121

_________________
A backup a day keeps DR away.


Top
 Profile  
 
 Post subject: Re: WD MCU - No more...
PostPosted: September 5th, 2026, 15:27 
Offline
User avatar

Joined: September 8th, 2009, 18:21
Posts: 17226
Location: Australia
einstein9 wrote:
here is how the MCU unique code looks like..
close to figure out the equation with a shortcut to bypass :idea:

To me, that looks like a bill of materials with the serial numbers of the various components. I don't see an MCU key anywhere. :-?

Module 0x8003

Code:
7I 2053 80 0780 405 09 H03001999 8Z03 AYZMT
8S 2053 80 0766 000 03 H02001999 8Z06 0BD00
9I 2053 80 0805 007 03 018110952 8Y27 213B6
AL 2053 80 0845 001 AA SWEB38G9D 8Z07 97700
DH 2053 80 0891 000 02 8441301TI 8Y16 26300
H1 2063 81 0097 1N4 000000N
71HH0A95RBBGNC6                             <-- headstack
JI 2059 81 0008 B1A 05 ANNY05GNN 8Z27 G09FF
KI 2053 81 0057 000 03 MN367000M 8Z19 367ET
MI 2096 80 0049 5B4 BZ XUCMBA21H 8Z31       <-- 5B4 glass media
MI 2096 80 0049 5B4 BZ XUWUBA21H 8Z31       <-- 5B4 glass media
OB 2053 80 0684 002 AB 802311N2P 8Y23 14500
PI 2053 80 0767 000 03 TM0000000 8Z12 0NPN8
VI 2053 80 0770 000 04 SC0001110 8Z18 17845

Code:
Offset(h) 00 01 02 03 04 05 06 07 08 09 0A 0B 0C 0D 0E 0F

00000500  30 2C 32 35 35 2C 34 2C 57 44 32 30 53 4D 5A 57  0,255,4,WD20SMZW
00000510  2D 31 31 4A 57 38 53 30 2C 30 30 30 2C 57 44 32  -11JW8S0,000,WD2
00000520  30 53 4D 5A 57 2D 31 31 4A 57 38 53 30 2C 32 35  0SMZW-11JW8S0,25
00000530  35 2C 32 35 35 2C 31 2C 2C 2C 2C 2C 2C 2C 2C 2C  5,255,1,,,,,,,,,
00000540  2C 2C 43 52 41 36 39 33 50 2C 31 35 2C 31 2C 2C  ,,CRA693P,15,1,,
00000550  36 2C 36 2C 52 54 2D 30 32 34 35 30 20 31 2F 33  6,6,RT-02450 1/3
00000560  31 2F 32 30 31 39 20 31 30 3A 30 34 3A 32 38 20  1/2019 10:04:28
00000570  41 4D 2C 33 39 30 36 39 36 33 36 33 32 2C 52 45  AM,3906963632,RE
00000580  50 52 4F 43 45 53 53 2C 34 2C 2C 30 2C 2C 2C 30  PROCESS,4,,0,,,0
00000590  2C 30 2C 30 2C 30 2C 30 2C 30 2C 39 2C 2C 2C 2C  ,0,0,0,0,0,9,,,,
000005A0  30 2C 58 4C 59 43 38 31 33 47 48 53 37 45 30 37  0,XLYC813GHS7E07
000005B0  35 32 35 30 39 2C 32 2C 34 2C 31 2C 2C 37 52 48  52509,2,4,1,,7RH  <-- headstack S/N
000005C0  48 30 41 39 35 52 44 30 43 36 2C 2C 2C 2C 30 2C  H0A95RD0C6,,,,0,
000005D0  2C 2C 2C 2C 2C 2C 2C 2C 2C 2C 2C 2C 2C 2C 2C 2C  ,,,,,,,,,,,,,,,,
000005E0  2C 2C 2C 2C 2C 2C 30 2C 43 48 41 52 47 45 52 2E  ,,,,,,0,CHARGER.
000005F0  34 2E 30 31 32 2C 32 2C 2C 2C 36 3B 33 3B 32 31  4.012,2,,,6;3;21
00000600  2C 30 20 00 00 00 00 00 00 00 00 00 00 00 00 00  ,0 .............

Module 0xC5

Code:
Offset(h) 00 01 02 03 04 05 06 07 08 09 0A 0B 0C 0D 0E 0F

00000050  43 48 41 52 47 45 52 00 01 81 01 10 00 00 81 01  CHARGER.........
00000060  10 00 02 81 01 10 00 04 82 03 E0 06 00 14 00 03  ........‚.à.....
00000070  00 04 82 68 11 4D 34 33 2E 33 42 32 5F 32 35 33  ..‚h.M43.3B2_253
00000080  34 00 00 00 00 00 00 00 00 57 44 42 5F 32 35 33  4........WDB_253
00000090  34 5F 58 30 00 00 00 00 00 00 00 00 00 57 44 42  4_X0.........WDB
000000A0  5F 32 35 33 34 5F 58 31 00 00 00 00 00 00 00 00  _2534_X1........
000000B0  00 53 41 45 5F 57 46 33 34 30 00 00 00 00 00 00  .SAE_WF340......
000000C0  00 00 00 00 00 53 41 45 5F 53 42 5F 58 30 00 00  .....SAE_SB_X0..
000000D0  00 00 00 00 00 00 00 00 00 53 41 45 5F 53 42 5F  .........SAE_SB_
000000E0  58 31 00 00 00 00 00 00 00 00 00 00 00 4D 34 33  X1...........M43
000000F0  2E 33 44 31 5F 32 35 33 34 00 00 00 00 00 00 00  .3D1_2534.......
00000100  00 57 44 42 5F 32 35 33 34 5F 59 30 00 00 00 00  .WDB_2534_Y0....
00000110  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
00000120  00 00 00 00 00 00 00 00 00 4D 34 33 2E 33 42 32  .........M43.3B2
00000130  5F 45 43 30 5F 32 35 50 4C 4D 33 00 00 57 44 42  _EC0_25PLM3..WDB
00000140  5F 32 35 50 4C 4D 33 5F 58 30 00 00 00 00 00 00  _25PLM3_X0......
00000150  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
00000160  00 00 00 00 00 4D 34 33 2E 33 42 32 5F 45 43 30  .....M43.3B2_EC0
00000170  43 5F 32 35 33 34 00 00 00 57 44 42 5F 32 35 33  C_2534...WDB_253
00000180  34 5F 5A 30 00 00 00 00 00 00 00 00 00 00 00 00  4_Z0............
00000190  00 00 00 00 00 00 00 00 00 00 00 00 00 00 00 00  ................
000001A0  00 4D 34 33 2E 33 42 32 5F 45 43 30 43 5F 32 35  .M43.3B2_EC0C_25
000001B0  50 4C 4D 33 00 57 44 42 5F 32 35 50 4C 4D 33 5F  PLM3.WDB_25PLM3_
000001C0  59 30 00 00 00 00 00 00 00 00 00 00 00 00 00 00  Y0..............
000001D0  00 00 00 00 00 00 00 00 00 00 00 00 00 05 82 03  ..............‚.
000001E0  E0 02 00 04 00 01 00 05 82 08 10 4C 53 49 00 4D  à.......‚..LSI.M
000001F0  56 00 00 06 82 03 E0 03 00 0A 00 01 00 06 82 1E  V...‚.à.......‚.
00000200  10 57 44 5F 35 42 34 5F 47 4C 00 57 44 5F 35 42  .WD_5B4_GL.WD_5B  <-- 5B4 or 5B8 glass media
00000210  38 5F 47 4C 00 47 4F 5F 47 42 38 5F 47 4C 00 07  8_GL.GO_GB8_GL..
00000220  82 02 E0 06 00 03 00 07 82 12 10 37 30 41 55 56  ‚.à.....‚..70AUV
00000230  57 39 32 00 42 44 00 50 51 00 43 45 00 08 82 02  W92.BD.PQ.CE..‚.
00000240  E0 02 00 01 00 08 82 02 10 00 01 09 82 02 E0 03  à.....‚.....‚.à.
00000250  00 01 00 09 82 03 10 5A 53 54 3D 01 01 50 99 07  ....‚..ZST=..P™.

_________________
A backup a day keeps DR away.


Top
 Profile  
 
 Post subject: Re: WD MCU - No more...
PostPosted: September 5th, 2026, 17:33 
Offline
User avatar

Joined: September 29th, 2005, 12:02
Posts: 3593
Location: Chicago
A wild guess.
These do look like serial numbers of different components, and they are likely serial numbers. One could be the MCU serial number. which is I guess reprogrammable.
These cannot be the keys which are written to the MCU - there is simply not enough data (generated keys occupy at least 192 bytes of random data).
Also the keys are generated using SysTick RTOS MCU timer (as a source of pseudo random information) with various mathematical equations and the MCU serial number could be a part of hashing of that random data.
There are three caveats.
1. To re-create the keys the exact firmware code need to be run inside the exact MCU model (the code that uses SysTick and allegedly uses MCU SN).
2. On top of that initial SysTick value also need to be exact as it was during original keys generation (not sure how it's achieved).
3. AFAIR keys generation code requires MCU in an unlocked state (not the ROM patched but actual MCU unlocked).
This is strongly hinting that to re-create all that one would need a PC with official WD remanufacturing software and hardware to connect to the drive.

_________________
SAN, NAS, RAID, Server, and HDD Data Recovery.


Top
 Profile  
 
 Post subject: Re: WD MCU - No more...
PostPosted: September 5th, 2026, 17:41 
Offline

Joined: November 24th, 2011, 21:48
Posts: 260
Location: Canada
Original PCB. Original MCU. Normal plaintext baseline. Modified the SA structure being discussed, power cycled, and read the same area again.
=Encrypted (Charger)

That changes my view of this quite a bit.

Whatever @einstein9 has been pointing at in the SA is not just an identifier or some unrelated structure. With the original MCU still sitting there, changing it changed the crypto result.

So there is clearly something real here.

I am not sure I would describe it as a simple "comparison" yet, but at this point that is almost secondary. I do not think MCU alone is not enough.

There is another recovery-critical component in the SA. That actually makes @einstein9's comments about reading something from the MCU and transferring it to a donor much more interesting.

I suspect there is some secret sauce being left out of this thread. That makes the most sense. If somebody has figured out how to extract the MCU-side component, reconstruct whatever relationship exists with the SA-side component, and make a foreign MCU behave like the original, I wouldn't expect the complete recipe to be posted on HDDGuru five minutes before selling it... Hopefully you cash in before the suppliers do...

The public part may simply be enough to show the direction without giving away the useful bit.

Possible ?
MCU secret + SA component = usable decryption material.
Maybe one is checked against the other.
Maybe one unwraps the other.
Maybe both participate in derivation.

Also the biggest take-away the pogo method also makes more sense in this context.

It keeps the original MCU doing whatever magic it normally does, then gives us SATA after that work has already happened. So the pogo fixture may only be the visible part of the solution. I am thinking read the unique MCU-side material and make another MCU use it.

If @einstein9's group genuinely has that working, that is the breakthrough here. The rest is plumbing.


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 110 posts ]  Go to page Previous  1, 2, 3, 4, 5, 6  Next

All times are UTC - 5 hours [ DST ]


Who is online

Users browsing this forum: No registered users and 69 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  
Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group