• We’re currently investigating an issue related to the forum theme and styling that is impacting page layout and visual formatting. The problem has been identified, and we are actively working on a resolution. There is no impact to user data or functionality, this is strictly a front-end display issue. We’ll post an update once the fix has been deployed. Thanks for your patience while we get this sorted.

Do you own a WD My Cloud device (NAS)? Well, congrats, you have a backdoor pre-installed!

lol that's a terrible backdoor. Who the hell would code a backdoor login with the password in cleartext within the open code?
 
Yikes.

When they say remote, they mean it still requires you to forward the port at the firewall right? Or does this thing actually connect out to some kind of cloud server and become publicly accessible?

Either way, stuff like this is why I prefer to build my own NAS vs use premade ones. It seems there's backdoors in everything now.
 
Yikes is right. That is really something stupid.
 
Yikes.

When they say remote, they mean it still requires you to forward the port at the firewall right? Or does this thing actually connect out to some kind of cloud server and become publicly accessible?

Either way, stuff like this is why I prefer to build my own NAS vs use premade ones. It seems there's backdoors in everything now.

Not necessarily. It's exploiting the web server built into the NAS. You could theoretically compromise it by visiting a malicious site from any system on the same network.
 
I would have thought this would have been caught in a security audit... unless of course WD doesn't have a security audit program. 🙁
 
I would have thought this would have been caught in a security audit... unless of course WD doesn't have a security audit program. 🙁

Having a security audit doesn't mean you have to do anything about it. Or even if you "have to" (meaning pressure from some other source to fix it), that often gets dragged out as long as possible.
 
WOW! World's largest hard disk manufacturer has worst backdoor technology.

Would never buy any NAS product from WD or Seagate.
 
Back
Top