Do you own a WD My Cloud device (NAS)? Well, congrats, you have a backdoor pre-installed!

Malogeek

Golden Member
Mar 5, 2017
1,390
778
136
yaktribe.org
lol that's a terrible backdoor. Who the hell would code a backdoor login with the password in cleartext within the open code?
 

Red Squirrel

No Lifer
May 24, 2003
70,212
13,600
126
www.anyf.ca
Yikes.

When they say remote, they mean it still requires you to forward the port at the firewall right? Or does this thing actually connect out to some kind of cloud server and become publicly accessible?

Either way, stuff like this is why I prefer to build my own NAS vs use premade ones. It seems there's backdoors in everything now.
 

Shmee

Memory & Storage, Graphics Cards Mod Elite Member
Super Moderator
Sep 13, 2008
8,147
3,085
146
Yikes is right. That is really something stupid.
 

XavierMace

Diamond Member
Apr 20, 2013
4,307
450
126
Yikes.

When they say remote, they mean it still requires you to forward the port at the firewall right? Or does this thing actually connect out to some kind of cloud server and become publicly accessible?

Either way, stuff like this is why I prefer to build my own NAS vs use premade ones. It seems there's backdoors in everything now.

Not necessarily. It's exploiting the web server built into the NAS. You could theoretically compromise it by visiting a malicious site from any system on the same network.
 

Elixer

Lifer
May 7, 2002
10,371
762
126
I would have thought this would have been caught in a security audit... unless of course WD doesn't have a security audit program. :(
 

XavierMace

Diamond Member
Apr 20, 2013
4,307
450
126
I would have thought this would have been caught in a security audit... unless of course WD doesn't have a security audit program. :(

Having a security audit doesn't mean you have to do anything about it. Or even if you "have to" (meaning pressure from some other source to fix it), that often gets dragged out as long as possible.
 

mxnerd

Diamond Member
Jul 6, 2007
6,799
1,103
126
WOW! World's largest hard disk manufacturer has worst backdoor technology.

Would never buy any NAS product from WD or Seagate.
 
  • Like
Reactions: rchunter