20 ms·
My NAS exposes itself over the internet without permission
- alias_neo 6y ago> Unfortunately, disabling uPnP these days is too much of a hit to convenience, so I looked for other solutions. Don't do this, there is no good reason to run UPNP if you care about security, turn it off and learn to manage a firewall. If the author really cares, go one step further and replace the ISP owned router with something with more control. Finally, if one cares about the software one's NAS runs, build or buy from someone like TrueNAS.
- bunnyfoofoo 6y agoEdited: deleted my comment as I was unintentionally offensive.
- rovr138 6y agoIs there a reason why the software claims it’s not available over the internet but still is because of something it did? Because that’s a bug.
- kn100 6y agoTo rephrase this somewhat less offensively (I am the author) "I realised a potential solution but decided the drawbacks of disabling uPnP were larger than the potential risk keeping uPnP enabled poses". My household makes use of many different services that would need to be port forwarded one by one in order to keep everything working, and some games just punch whatever port they like using uPnP so it's hard to keep playing those with it disabled. Sysadminning at home is only fun for a short while, I do this stuff at work, I'd rather keep my home setup as simple as I can help it. As usual, various solutions are available, I described one here. Disabling uPnP is an option for some, and I encourage those who want to go that route to go that route.
- hluska 6y agoI agree with bunnyfoofoo’s conclusion - maybe not the tone but certainly the conclusion. It’s tough to trust an article that makes security claims while ignoring so many self imposed security holes.
- edoceo 6y agoIt's not offensive. But you were offended. Big difference.
- dxdm 6y agoI'm wondering what definition of the word "offensive" you're using.
- edoceo 6y agoOffensive as Rude. Then @kn100 assigns to @bunnyfoofoo the offending behaviour. It's the personal responsibility thing. "I'm offended" vs "You're offensive".
- adamweld 6y agoI think it's pretty clear than the author believes he may have offended people with his statement, and is rephrasing in a more precise manner to avoid confusion.
- vczf 6y agoTo be very exact, being offended is a choice, in that nobody can offend you if you don't let them. You can always choose to not take offense. (The statement in question does seem rude and dismissive to me, however.)
- washadjeffmad 6y agoI believe the eminent feminist and humanitarian, Elanor Roosevelt, would have agreed with the fairness of your assessment. https://quoteinvestigator.com/2012/04/30/no-one-inferior/ https://quoteinvestigator.com/2012/04/30/no-one-inferior/
- crazygringo 6y agoYou mean ignoring the fact that a NAS which claims to not be available over the internet is available over the internet? The correct solution is the NAS manufacturer needs to correct the issue and provide a software update. This article shouldn't be ignored at all. Your supposed "correct solution" does nothing to fix the root issue.
- imwillofficial 6y agoMan, I have to catch myself all the time with this.
- ancarda 6y agoDo you have a router you recommend? Ideally something running free software
- annoyingnoob 6y agoOPNsense or pfSense
- anonymousiam 6y agoI have used both OPNsense and pfSense. I currently OpenWRT which I find to be full featured, secure, and lightweight.
- alias_neo 6y agoHardware wise, I run Ubiquiti EdgeMAX but I wouldn't recommend them anymore, their software has gone down hill since many of their best developers left. Software wise, pfSense is where it's at, but I don't have experience with their own hardware other than the ones we ran at work all failed due to a silicon flaw in the Intel SoCs they ran.
- 7steps2much 6y ago> Ubiquiti EdgeMAX but I wouldn't recommend them anymore Sadly there isn't exactly a lot of alternatives in the hobbyist network setup area ... It's basically just ubiquity and mikrotik at this point as far as I know
- zokier 6y agoI've heard good things about Turris hardware too, but no personal experience. https://www.turris.com/en/omnia/overview/ https://www.turris.com/en/omnia/overview/
- JoshTriplett 6y ago> Software wise, pfSense is where it's at Recent events suggest that the people behind pfSense are not especially responsible stewards; see https://arstechnica.com/gadgets/2021/03/buffer-overruns-license-violations-and-bad-code-freebsd-13s-close-call/ https://arstechnica.com/gadgets/2021/03/buffer-overruns-lice... and https://opnsense.org/opnsense-com/ https://opnsense.org/opnsense-com/ .
- deburo 6y agoI also found this weird, and this got me to check if it was enabled on my business firewall devices: turns out they don't even support UPnP. Is it just consumer routers that support it nowadays? Shouldn't that feature just be nuked? EDIT: Well it sounds like a feature for pro users that know what they are doing and control all devices on the network. Even then, security appliances (eg. from SonicWall) don't support it. I don't know, this is probably a niche feature for a few occasions.
- my123 6y agoFar from only a feature for pro users. Notably, it is a must for VoIP (without going through a relay) and BitTorrent when you don't want to manually configure a firewall. (allows to create holes in a controlled way for a NATted network) Without UPnP, you specifically have to configure your NAT for this...
- nobody9999 6y ago>Without UPnP, you specifically have to configure your NAT for this... While I realize that configuring nftables/iptables is beyond most folks, there are many firewalls out there that have a GUI/webui which makes this dead simple. Not sure why this should be an issue in 2021, except for users' trained-in helplessness.
- hluska 6y agoUgh, users trained in helplessness. I just had an utterly annoying conversation with my cell phone provider whose reps have been trained in helplessness and thus fail to follow really simple security procedures. This phrase is a thing of nightmares now. Stay tuned for a really scary Haunted House full of users trained in helplessness...coming Halloween 2021.
- benlivengood 6y ago> Not sure why this should be an issue in 2021, except for users' trained-in helplessness. Kids hosting games on random ports (terraria, etc.) benefit from UPnP. I'd rather enable it than manually enter firewall rules for each game or give them admin access to the firewall. UPnP is only an additional risk if you have malware inside your network already and then it mostly allows malware to host services in a simpler way, but capable malware will be able to use TCP hole punching to establish arbitrary connections between infected networks.
- KozmoNau7 6y agoThe issue is letting untrusted or badly behaved devices on the network. UPnP works great, if you control which devices get on your network. Static port forwarding combined with DHCP gets annoying quickly, you end up having to set up static assignments for every device that may need a port forwarded, which can be a lot, with modern multiplayer gaming and p2p. And for applications that select a random port on startup, such as some bittorrent clients, you either have to manually forward the port every time or select a static port. UPnP serves a purpose and is extremely convenient, as long as you trust the devices on your network.
- lostlogin 6y ago> And for applications that select a random port on startup, such as some bittorrent clients, you either have to manually forward the port every time or select a static port. What if you run them over a VPN? I don’t use torrents much but have a client containerised with OpenVPN. I’m not a networking expert but I had assumed (with all the dangers that comes with) that this moved the problem to the VPN provider?
- mercora 6y agoit will work as long as you are the one initiating the connection. if some peer suspects you have a wanted piece available i.e. from another peer in the swarm it can not communicate the intent to get that piece from you to your client directly. i think BitTorrent can relay messages through intermediate peers to make your client establish the connection to that other peer (reversing the initiator). Otherwise peers will exchange other peers that are visible to them so that your client might eventually learn how the other peer that wanted that piece is reachable and connects to it. So it actually will work without port forwarding but reaching your client will be harder and thus less peers inside the swarm will be available to you or them, likely making it slower.
- daniellarusso 6y agoSo, keeping track of which device on your network belongs to which MAC address, and reserving an address for each, is that what you mean by ‘annoying’ - the administration of that?
- procombo 6y agoDoesn't TrueNAS (was FreeNAS) connect to iXsystem servers from the NAS and from the NAS web interface?
- kalleboo 6y agoUPnP is also sometimes used to refer to some forms of zeroconf/mDNS/Bonjour/DLNA. Maybe he is under the impression if he turns off UPnP on his router (the automatic port forwarding feature), that his LAN device discovery features will break?
- sdflhasjd 6y agoUPNP is pretty important for a lot of online games.
- Spivak 6y agoYeah, you can’t really “manage your firewall” when consumer software doesn’t open fixed ports and assumes upnp.
- Daho0n 6y agoWhy not? Which consumer software breaks? Normally people say games. I have disabled upnp on my firewall and there're two gaming PCs, a PS3, a PS4 and a PS5 running happily behind it. I just finished a Demon Soul's session with voice chat with friends with no problems. NAT type 2, because I managed my firewall to enable this.
- BlueTemplar 6y agoHave you tried a client/server style game not relying on Steam multiplayer?
- Daho0n 6y agoIt makes no difference since as I wrote I manage the firewall to allow this. But yes, since none of the games on consoles use Steam. If NAT wasn't set up I would get NAT type 3 on the PlayStations for example. ETA: My point was to get an example of something that breaks "because it doesn't work without upnp". I have yet to see a game that doesn't support a fixed set of ports.
- Tepix 6y agoWhich ones? I have it turned off and haven't had any issues with games.
- sdflhasjd 6y agoGames that use Peer-to-peer lobbies instead of dedicated servers, more popular with multiplayer co-op games. Typically, it can be possible to join another lobby, but impossible to host (insofar as other people can't connect to it)
- takeda 6y agoI find it amusing that many people are convinced that IPv6 is less safe, because there is no NAT, and at the same time use UPnP. No, NAT isn't designed for security, the blocking of incoming traffic is just side effect, you should use a firewall for security.
- mavhc 6y agoNAT can mean 2 things, 1 to 1, and 1 to many. Firewall is a concept not a thing. IPv6 could be set up so every computer has an internal address and you choose to map external to internet using 1 to 1 NAT.
- imwillofficial 6y agoAs a former maintainer of firewalls... You are wrong. From beginning to end, utterly, and completely. ::Pets His firewalls lovingly:: “Don’t listen to Him, He didn’t mean it.”
- nix23 6y agoAh yeah the good old IPv6-NAT....
- rubatuga 6y agoYep, the author depends on NAT as a security feature, when it was never designed to be one. UPnP is a convenience feature, and is disabled in all security focused networks. If you want convenience and security, set up two VLANs, one for your insecure UPnP devices, and one for your more sensitive devices.
- nemosaltat 6y agoThis is what I did a couple years ago. The documentation for OpenWRT is great, and Luci/LDE makes it approachable if you don’t feel comfortable managing from the CLI. I have one VLAN for my “privileged” devices and one for the “IO(shi)T” devices.
- kaylynb 6y ago
- the8472 6y agoOpening ports for a specific machine with dynamic IPv6 addresses can be difficult though. If the suffix stays stable then with iptables you can use netmasks where you mask out the prefix rather than the suffix. If both prefix and suffix are dynamic you need a solution that takes dhcp or host names into account. Not all router firmwares support something like that. Another alternative is to use UPnP or PCP with authentication.
- mnd999 6y agoSuffix should always be static with SLAAC because it’s your MAC address. Even if you’re using privacy extensions (and you should) you should still be able listen on the MAC address one. If you’re using DHCPv6 then the DHCP server should take care of DNS as it would for v4.
- the8472 6y ago> Suffix should always be static with SLAAC because it’s your MAC address. Except for devices that randomize mac addresses. Normally even those that do that only try do so when connecting to a new network but that's not always reliable. > Even if you’re using privacy extensions (and you should) you should still be able listen on the MAC address one. I'm doubtful that all applications make that distinction and advertise the right address. If they just use some external "what is my IP" service to determine their address because that's what they did for IPv4 then they'll get the privacy address and advertise that to peers because that'll be picked by default for outgoing connections. Being able to allow incoming connections to a port for any address belonging to a particular machine would be less error-prone.
- BlueTemplar 6y agoThese issues will keep happening, in completely unrelated domains, as long there are not fines for violating security best practices.
- BlueTemplar 6y agoAFAIK the goal is to get rid of MAC adresses entirely - so how is this going to work?
- hh3k0 6y ago> If the author really cares, go one step further and replace the ISP owned router with something with more control. I wanted to do that for a while now. Do you happen to have a good suggestion regarding whose products are worthwhile?
- alias_neo 6y agoIts muddy right now, I run Ubiquiti EdgeMAX switches and EdgeRouter at home, but I wouldn't recommend them right now (see another comment of mine, or check out the subreddit), for NAS I run TrueNAS, on a home built server.
- daniellarusso 6y agoFor your NAS, to you have a mobo and case recommendation?
- eikenberry 6y agoNot OP, but I built a NAS not that long ago. For the case I purchased the Fractal Design Node 304 (https://www.fractal-design.com/products/cases/node/node-304/black/ https://www.fractal-design.com/products/cases/node/node-304/...) and am very happy with it. For the Mobo I suggest finding a decent board (AMD based one if you want ECC RAM) and then use a PCI-e controller card to support the hard drives you need. It is hard to find a nice MB with all the SATA ports you need, using an external card gives you a lot more options. When I researched it everyone recommended an "LSI Logic Controller Card LSI00301 SAS 9207-8i" (eg. https://www.amazon.com/LSI-Controller-LSI00301-9207-8i-Internal/dp/B008J49G9A/ https://www.amazon.com/LSI-Controller-LSI00301-9207-8i-Inter...) and it has performed very well for me. If you go that way you'll need a SAS to SATA cable, they are easy to find as well.
- spockz 6y agoUp until a week ago I would have suggested the UniFi. Since the latest snafu, the handling of the breach not the breach itself, I’m not so sure anymore what would be the best alternative. Perhaps just their EdgeRouter devices or a mikrotik device. The snafu: https://news.ycombinator.com/item?id=26638145 https://news.ycombinator.com/item?id=26638145
- watermelon0 6y agoSure, UPnP can open ports to the outside world, but that's something that might be desired in some cases. However, devices should default to local access only, and offer an option to expose them to the world, with appropriate warning.
- kn100 6y agoThis is exactly my opinion and exactly how I use uPnP. I can't control exactly what runs on my network since I'm not the only one using it, but I can guard certain parts of my network more thoroughly.
- rubatuga 6y agoYou have to choose: security or convenience.
- rembicilious 6y ago“They that would give up a little convenience for a little security deserve neither and they shall lose them both.” -Beenjammin Frankmon
- imwillofficial 6y agoIt’s a sliding scale, otherwise you’d run an airgapped network and hand carry your info into and out of your home on CDs...
- MomoXenosaga 6y agoReminds me of a state secretary who decided to use gmail because it was more convenient than the secure smartphone provided to him. Ofcourse for most people who aren't dealing with state secrets convenience is a priority.
- zokier 6y ago> However, devices should default to local access only Unfortunately we need to act based on what is and not what should be.
- testfoobar 6y agoAgreed. My router firewall drops all packets from my NAS to my WAN. Doesn’t matter what software it runs.
- dijit 6y agoOn the other hand, if you want to play games on your network you absolutely must have UPNP. Unless the game has a dedicated server infrastructure. But even then you risk higher latency on VOIP if it even works at all.
- clajiness 6y agoI'm gaming on my Xbox right now with specific ports forwarded. I guess "absolutely must" is a bit much, huh? UPNP has no place in a secure network.
- dijit 6y agoThis is not a reasonable solution for most people, it requires intimate knowledge of the games you play (which ports they use), a static IP for your console and no more than one player/console per household. Heaven forbid you have a PC game and a Xbox game that have conflicting ports. And, I just have to say: you open arbitrary ports to your game console from the internet and talk about security.
- easton 6y agon>1, not n=1.
- BlueTemplar 6y agoWell, NAT itself has pretty much no place on a network these days, so the point is kind of moot...
- rubatuga 6y agoThis is completely false. Almost all home networks use port-restricted NAT, which allows for STUN for NAT traversal. You do not need UPnP to play games, even those that have peer to peer multiplayer. Also STUN for VOIP does not increase latency. It tells you your external IP and port. Edit: Port symmetric —> port restricted
- waffle_ss 6y agoI get the feeling you’ve never ran n>1 Xbox Ones connecting to Xbox Live at the same time. Without UPnP only one will be able to connect.
- atmosx 6y agoIndeed, UPNP effectively turns on "auto-pilot". The fridge running on 10 years old firmware might open ports dynamically. Networks featuring UPNP should be marked as "open/insecure".
- KozmoNau7 6y agoIf your fridge has a MAC address, you have much much deeper problems than UPnP.
- xyst 6y agoalso dont buy Ubiquiti gear :)
- rufius 6y agoHonest question - what would I use UPnP for? I discovered a similar issue as the blog poster with my QNAP NAS which was easily remedied by disabling UPnP. I’ve not noticed any issues. We can do all the same things we did before. My Xbox and Switch still do online multiplayer just fine. I remember hearing Xbox/PS3-4 and UPnP mentioned together but it’s been a while.
- rand49an 6y agoUPnP allows devices to open up firewall ports for themselves to allow traffic to reach them inbound. Games (for example) that that host a server on the users local machine may require an open port to allow access inbound so UPnP can help with this. Now-a-days it's not used much and quite frankly it was always a fairly bad idea.
- BlueTemplar 6y agoNowadays you should use IPv6 anyway, which doesn't need NAT.
- stilisstuk 6y agoSo I don't know about routers or networks. I live in a an apartment. Which router (+ a extra point / 2 hub mesh) is recommended these days. There seems to be a plethora of options. But most of always end with ubiquity, which today feels like a bad choice. Also kind of expensive. Preferable something Completely local. No cloud service. Preferable opens source. I live in EU. (Sorry if it's bad form to ask for product recommendations, but I am unhappy with/ don't trust, my isp provided router, and gp explicitly mentions buying a router)
- newsclues 6y agoMikrotik
- katbyte 6y agoThe ux is... not good and I wouldn’t recommend it for anyone not experienced
- omnimus 6y agoyeah i bought Mikrotik for home and i have no idea what to do there. I tried to do hairpin nat with it and after 3 tutorials i somehow managed to get it working and now i have no clue how does it work or what its it really doing. I think its only for real networking pros
- stefan_ 6y agoCan you get rid of your ISP provided router? There are lots of obstacles there.
- stilisstuk 6y agoI don't know to be honest?
- alias_neo 6y agoI've replied to a couple of others, normally I would have recommended Ubiquiti, but I no longer do. Not just because of their recent breach debackle, but because their software quality has declined since some of their best developers left. The short but not so useful answer is, run something with pfSense or similar, I hear PCEngines hardware works well and is open source from the bootloader up. Ubiquiti has hardware offloading using Cavium hardware so you need to get some throughout tests if you need high bandwidth in hardware without the offloading hardware.
- gsich 6y agoThat sounds like he didn't even try.
- rdudek 6y agoNothing wrong with uPnP. If you’re worried about something opening up ports on your network, you’re already compromised.
- Daho0n 6y agoLike a buggy NAS. So yes, lots wrong with upnp. Letting anything with an IP forward ports is being auto compromised.
- milleramp 6y agoYes, the real lesson here is, I learned not to trust random vendors and turned off upnp.
- daveoc64 6y agoPeople make blanket statements like this without thinking of how it is used by popular consumer devices. As others have said it's really necessary for some consumer devices to work properly - especially if you have more than one of the same device. Games consoles are the best example. If you have one console only, then you can usually forward ports manually, but if you have two or more of the same console, and want them to go online at the same time, then you need to use UPnP. If you don't have UPnP enabled on one of the consoles, you'll see issues like being unable to join some games or being unable to do voice chat with certain players.
- monocasa 6y agoThat's not true, at least for xbox live. It's NAT punching will gladly use UPnP if available, but doesn't rely on it, even for multiple devices on the same public IP.
- daveoc64 6y agoIt's unlikely that you will have an "OPEN NAT" status on more than one console without UPnP at the same time. Depending on the game you're playing, that may or may not be an issue. It can stop you connecting to certain players in a peer to peer scenario.
- monocasa 6y agoIt'll be fine. They'll be on two pretty arbitrary public ports, but it works just fine if you have a vaguely sane nat implementation in your router. That's the whole point of nat punching. And even if you have an incredibly broken nat implementation that won't accept UDP packets from other sources than the server you originally connected to, there's a fallback pathway at the first layer of that port 3074 protocol that bridges p2p messages through live's backend. As another example, last time I checked WebRTC didn't use UPnP, but has all the same issues as a fundamentally P2P UDP protocol. They use STUN/ICE/TURN, live uses custom protocols filling the same niches.
- 6y ago
- pabs3 6y agoI would never use the pre-installed software on a device, always replace it with a bare-bones install of a generic Linux/BSD distro and add any packages really needed.
- dcow 6y agoOr/also, nag your ISP to give you an IPv6 prefix (or switch to Comcast, because they delegate you a /62). If you still want to manage a stateful firewall then go for it. But we shouldn't still need this NAT traversal crap in an IPv6 world.
- InafuSabi 6y agoThere are ISP's out there which disallow the use of gateways other than theirs to enter their WAN. That means you are stuck with whatever config it allows. I have root access to mine, so I can configure it to my liking, but the device is _not_ blinking out in quality, needing to be reset at least once every 14 days, otherwise it starts chocking when I need to transmit my radio stations over the NET These type of ISP's make a lot of cash, selling bulk purchased cheap hardware, esp mine, which still sells services over copper using VDSL & ADSL2. Their FTTH speeds are also inconveniently capped on VDSL speeds
- gfxgirl 6y agoCan you not just put something behind their gateway?
- HeadsUpHigh 6y agoBuilding your own is probably the easiest of all the options presented.
- kn100 6y agohttps://kn100.me/turning-upnp-off/ https://kn100.me/turning-upnp-off/ I've written a follow up, which you may find interesting.
- rkagerer 6y agoI've never enabled uPnP, and get by just fine.
- tyingq 6y ago"CAN USER NAME AND PASSWORD OF TNAS ADMINISTRATOR BE CHANGED? Administrator’s username is admin and the initial password is admin as well. " https://www.terra-master.com/us/faq/category/detail/?id=3303 https://www.terra-master.com/us/faq/category/detail/?id=3303 Oy.
- lostlogin 6y ago“Users can change the password of administrator but cannot change the administrator’s username. Is this article helpful? Yes / No” At least you change the password...
- Hnrobert42 6y agoWhat does the author mean that the NAS punched a hole through the firewall? They say it several times. Do they mean enabled port forwarding on the router? If so, that seems like a router issue.
- tyingq 6y agoWelcome to uPnP. https://en.wikipedia.org/wiki/Universal_Plug_and_Play https://en.wikipedia.org/wiki/Universal_Plug_and_Play
- rovr138 6y agoUPnP is added to the NAS that allows it to request ports to be open and mapped. There is software needed on the router side too to make it work. They don’t want to disable this. This is covered in the article.
- IceWreck 6y agoRouters have this thing called universal plug and play which enables applications to enable port forwarding on their own without the user having to dive into router firewall settings.
- im_down_w_otp 6y agoI'm confused. Some significant length was gone to in attempting to interrogate the device and modify it in such a way that it wouldn't try to open uPnP ports anymore. Further, a lot of devices try to leverage uPnP by default, and many of them are significantly more opaque than this NAS proved to be. However, the author doesn't want to just disable uPnP in their router and manage forwarding directly due to a perceived loss of convenience. Surely, first discovering by happenstance that a devices is doing this in the first place, then trying to figure out how to go through idiosyncratic & unsupported means to change the device's behavior, is significantly less convenient than updating a router/firewall config rules in supported standard predictable ways on occasion?
- bscphil 6y agoGiven this: > My router is an ISP provisioned one so the feature-set there is somewhat limited My assumption was that their router doesn't support disabling uPnP for a single client, so it's 100% on or 100% off. If they play a significant number of p2p games or use p2p applications with non-predictable ports, it might well be more difficult to do manual port-forwarding when needed than to leave uPnP enabled (or even impossible, depending on what the router can do).
- IceWreck 6y ago> Unfortunately, disabling uPnP these days is too much of a hit to convenience Why ? Its only used for torrents and some games, just note down their port numbers and enable those in your firewall once, thats it.
- KozmoNau7 6y agoYou mean "enable them all over again for every new DHCP assignment, unless you insist on static IP assignments".
- iso1210 6y agoWhy wouldn't I use static dhcp?
- KozmoNau7 6y agoForwarded ports are not always static, we're not in the world of just web servers and SSH. Different devices may need to use VoIP, P2P, games and other applications that cannot be strictly mapped to just one system or even just one port. UPnP handles dynamic mappings, so you don't have to update your port forwards every time.
- Zombieball 6y agoWhat’s wrong with static IP assignments? Doesn’t this solve the issue?
- stonesweep 6y agoStory time: It depends on the hardware at your disposal. I'm now on the new T-Mobile Home Internet service, the router+wifi device supplied (a Nokia 5G LTE based unit with a SIM on one side) firmware has basically no configuration - you cannot assign static DHCP, no bridge mode, no port forwarding - it has UPNP on or off, that's it. A truly sparse webUI, frustrating no-config device at 1.0 firmware level that doesn't even show you what the DHCP ranges in use are. My G-Shock watch has more configuration options than this thing does. :-/
- Klwohu 6y agoYou “agreed” and gave your permission when you bought a product with mystery functions. Look at all the Einstein’s who buy smart TVs and then become baffled when they start showing ads.
- SMAAART 6y agoWhat.The.Actual.Fuck.
- diarrhea 6y agoThe JSON config is strange, the keys contain type information. But any JSON parser worth its salt should not require that since JSON is natively typed, no?
- tyingq 6y agoWhere? I don't see that. What type info is below? Do you mean "mapList"? I suspect it's just what they chose to name the key. "triestimes": 3, "mapList": [ { "desc": "ftp", "nExternalPort": 6221, "nInternalPort": 21, "sProtocol": "TCP", "bEnable": 0 },...
- philo23 6y agoI suspect they mean the letter prefixes: _n_ExternalPort + _n_InternalPort for number, _s_Protocol for string and _b_Enable for boolean. It's probably just a convention they use in the source code that's made its way into the JSON by serializing something? Either that or old habits die hard.
- rahimnathwani 6y ago9091 might be for the transmission web UI
- lostlogin 6y agoThere is a distinct whiff of Docker to the ports it’s using. But maybe I’ve been too far down that hole and am just seeing things though Docker tinted spectacles.
- LeanderK 6y agoI use a lot of software/devices which I think is using UPnP (airplay, airdrop, pioneer dj pro link, maybe the printer etc.). There's talk here about disabling UPnP but does that mean that the devices wouldn't be able to find each other? I don't want to babysit my router. Or aren't they using UPnP? Quick googling wasn't successful. I thought most of those autodiscover-services use UPnP.
- kalleboo 6y agoThere are 2 parts to UPnP. One is service discovery, in cooperation with zeroconf (aka bonjour/mDNS). This is handled 100% by devices themselves. The other is the port forwarding protocol, where devices can ask your router to open a port in the NAT to the wide internet forwarded to them. This is done in the router. It's also a potential massive security hole. If you disable UPnP on your router, you only disable the second thing. The first thing keeps working.
- ryandrake 6y agoThe service discovery isn't really the security hole though, is it? I mean I have mDNS configured on my LAN. It's the port forwarding, and specifically, configuring it so that any rando device on the network can set up port forwarding, which is the security problem. If you really want the dubious convenience of UPnP port forwarding, at least limit it to the one or two devices on your LAN that need it.
- kalleboo 6y agoRight, service discovery is fine. It's just that two things with wildly different security profiles get referred to with the same name
- daniellarusso 6y agoNo, mDNS it is not really the issue. Even most VPNs won’t, by default, allow mDNS packets across, without adding a relay server and some additional configuration. But, yeah, letting any application basically go into ‘server’ mode on your home network at-will is not the most secure setup.
- vidarh 6y agoDon't know if it's true for this model, but at least some Terramaster NAS's are just x86 computers [EDIT: I see the model in the article is an ARM box, but also that it's already running a Terramaster specific Linux distro, so just nuking most of the Terramaster specific stuff might be easier than trying to find a way to do a clean reinstall]. For at least some of the x86 ones, you just need the right cable to connect to a suitable monitor, and it can boot from a USB drive. You don't need the VGA cable to replace the OS, but it helps a lot. You may have to dismantle the whole thing to get at the boot drive, but they're pretty easy to take apart. First I did with mine was to install Open Media Vault.
- annoyingnoob 6y agoI'd argue that the right approach is to replace the ISP router with your own and disable uPnP, for your own security. Otherwise its only a matter of time before you see this again. You cannot count on having only trusted devices on your network.
- sandreas 6y agoOnce more a sad story about so called plug and play devices doing weird stuff. I prefer getting my hands a bit dirty using: - FreeNAS / NAS4free / OpenMediaVault (for Home-NAS) - OpenWRT / OPNsense / PFSense (for Home-Firewall) Nearly Plug and play with this Hardware: - Dell T20 / T30 / T40 - HP Microserver N54L / Gen8 / Gen10 - Linksys WRT 1200 / 1900 / 3200 / 32X (https://dc502wrt.org/) - Alix APU
- kitsunesoba 6y agoBeen running a T20 w/4x 4TB HDs with plain FreeBSD for a few years now and it works pretty well. I'm barely even competent when it comes to sysadmin sorts of things, but it was pretty easy to get set up following a blog post I found years ago. The consistency of FreeBSD is a real benefit here — it's well documented to begin with, and since things change so little between releases, bits and pieces you find online are largely still relevant even if they're a little old.
- ryandrake 6y agoFirst thing I did when I got my Buffalo Terastation was look up how to install plain Debian Linux on it and set it up myself. There is usually very little benefit to using the manufacturer's neutered, cobbled-together firmware. Same thing with my Internet router. Flash it with non-manufacturer firmware so I can configure it properly.
- dbeley 6y agoI also had good experience with mini-PCs like Chuwi's. They are pretty cheap, have a good amount of ports and have the advantage of having newer CPUs with very little power consumption.
- canada_dry 6y ago+1 for FreeNAS. Its use of ZFS and ability to easily manage multiple "jails" and vms is perfect for a reliable home automation platform! The only major downside I've found thus far it that you cannot pass USB devices selectively to a jail/vm.
- deleted 6y ago[deleted]
- TerminalSystem3 6y agoCan someone ELI5 on what a NAS is and why someone would need a NAS?
- skizm 6y agoJust a computer with a bunch of hard drives so you can store your media all in one place. Most of the time people expose this to their home network so they can access the files from all their devices while on the same wifi, but you can also expose it to the internet so you can access the files anywhere.
- xyst 6y agoIt stands for "network attached storage", it's basically a standalone disk drive that is accessible to all devices within the local network (or public internet, if the device is setup that way). In home setups, it's often used as a way to store terabytes of digital media (movies, videos, locally hosted wikipedia)
- notamy 6y agoAdding on to what others have said, I have one set up that's also used as part of my backup strategy for the important stuff on all the other boxes around here.
- kotsec 6y agoYou should NOT have any terramaster NAS internet facing right now. I disclosed a bug last month to Terramaster that still hasn't been fixed. Go to http://NAS_IP/module/api.php?wap/ http://NAS_IP/module/api.php?wap/ and it will give your admin password out as an md5crypt hash. Why? I assume it's some sort of backdoor/dev code but I don't know.
- kn100 6y agoJesus, confirmed here. That is tragic.
- terramaster 5y agoHi friend, Could you please send a description of the specific problem to our email:support@terra-master.com? TerraMaster will do our best to serve every customer.
- kotsec 5y agoI sent an email to that address on the 19th of March. The issue is that millions of passwords per second can be tried against the hash on an average computer and there's no good reason to give the hash out in production. To anybody owning a Terramaster NAS then i'd advise to set a random password of the maximum length possible.
- geocrasher 6y agoThe article focuses on the security issues surrounding his new NAS, and that's fine. But the problem isn't security. It's Trust. Consumers generally trust that manufacturers will follow Best Practices and that security is part of the deal: I pay you money, you give me a quality product that Just Works and is Secure. False. Products are made to be sold at a profit. You can imagine that some engineer at that company knows about this problem, put in a Jira bug for it and since it didn't affect overall functionality, and because the product needed to be released as soon as possible, they rejected the bug and sent it off. By default, we should NOT trust that things are Good and Secure. If we are security conscious, then it's on us as consumers to figure out how to mitigate these problems. Or is it? If I was this guy, I'd box that thing up and send it back and give the company feedback as to why, and then I'd show them this very blog post. The manufacturer probably won't care. They know that until the average consumer cares about security and knows how to mitigate problems it won't matter. And we all know that the average consumer, even of technical products, has security habits. Now if you'll excuse me, I need to go take care of some security stuff on my boxes, this really got me thinking about it! sudo passwd root greatnewpassword11 greatnewpassword11
- geocrasher 6y agoThat was supposed to say "has terrible security habits." But the time to edit has passed. sigh.
- BlueTemplar 6y agoYeah, until we see these companies get large fines for not following the best practices, and the engineers in charge lose their licenses, nothing will change.
- starky 6y agoInteresting, I have the 4 bay version of this NAS (F4-210) and I don't see anything along the lines of what the author is showing.
- cibyr 6y agoWhen there's a typo is the message telling you "Tt is only available on the local network" that might be a sign of how much care was taken with regard to it.
- xtat 6y agoExactly why to never turn on upnp
- BlackiceNetwork 6y agoTrust but verify. Just wanted to add that in my opinion it is best practice to schedule a recurrent task for scanning the network using tools like nmap. On top, add. After done (re)configuring a (new)device on you network, scan and document baseline. Verify baseline recurrently.
- aborsy 6y agoIs there an app to comprehensively test the security of a router? One usually runs Nmap or similar from WAN side to check for open ports. How to test if a router permits UPnP? Checking that UPnP is disabled in router’s GUI is not sufficient. An app should try to punch holes, and run tests for various things. Also, what else needs to be checked?
- a-dub 6y agoaren't all these prosumer nas devices just out of date foss with a clunky webgui that ultimately is sufficiently limited such that you spend more time working around limitations then you would have just setting up foss yourself or are they actually getting good now?
- Wolfenstein98k 6y agoWho hasn't exposed themselves over the internet without permission once or twice?
- lgats 6y agoCVE Assigned https://cve.report/CVE-2021-30127 https://cve.report/CVE-2021-30127
- CrLf 6y ago> Unfortunately, disabling uPnP these days is too much of a hit to convenience I've disabled UPnP on every router I owned. Never did I notice any problems from doing it.
- breakingcups 6y ago> Upon SSHing into the NAS and having a dig around the file system, I discovered a file that could be modified. /etc/upnp.json seems to contain a list of port forwarding rules. Thank you to Terramaster for providing root access to these at least. Simply change bEnable to 0 for whatever ports you don’t want exposed, reboot the NAS, and check the port forwarding rules. And don't forget to do all this each time the NAS updates. And pray to whatever entity you wish that auto-updates don't get enabled. Seriously, after a blunder like this, why not return the device and find a manufacturer you can trust?
- qwerty456127 6y agoWhy would anybody need UPNP anyway? This has always been a mystery to me.
- lilyball 6y agoMostly to make P2P software work (which includes gaming software, such as voice chat or serverless multiplayer games)
- djrogers 6y ago> Unfortunately, disabling uPnP these days is too much of a hit to convenience, No. Just, no. There is NOTHING you need on your network that should require UPNP. It’s a horrible, insecure, and completely irresponsible protocol that does not need to exist.
- cjtrowbridge 6y agoThree dumb routers
- devwastaken 6y agoAre there actually good alternatives to consumer NAS that don't break the bank? I'd love to just throw a raspi4b at some HDD's - but no sata, and no ECC. And the hard drives need to be kept safe from their vibrations.
- Tildey 6y agoSome USB drives with a Pi is a decent solution, given that the most cost effective option for HDDs is usually shucking WD easystores anyway. USB HDDs usually have decent vibration damping and cooling also. USB might be less ideal than SATA, same with ECC, but you’re also saving a major amount of money, % wise.
- KozmoNau7 6y agoDon't do that, you'll have no redundancy in case of disk errors, the performance will be abysmal (Pi4 possibly excluded) and USB drive spindown and SMART support is sketchy at best. I bought a Fractal Node 304 case (room for 6 drives), put an ITX board in it, a PCIe SATA controller and set it up as btrfs RAID, with CIFS, NFS and FTP. Not a huge outlay and so much better than a hacked-together Pi solution. It also functions as my DNS and DHCP (Pi-Hole in a Docker container) and since it has hardware video decoding, it works great as an always-on HTPC, which is practical for apartment living.
- Tildey 6y ago3 USB drives in a raid setup isn’t any less redundant than 3 SATA drives in the same setup (mathematically anyway, excluding potential bus problems which don’t really seem to be much of an issue these days). Personally I also have a node 304 based nas, but I’ve seen plenty of people with low cost Pi setups and no major issues. Plugging a few drives into a Pi is much easier if you don’t have experience with building computers, and is still a couple hundred dollars cheaper than something like that. Also worth noting that it’s possible to connect PCIe devices to a Pi, although I believe you need a specific model.
- Ballas 6y ago
- charcircuit 6y ago>however it seems the ports 8181 and 5443 remain punched, but result in a 404, since we moved the web server earlier If you actually moved the server the connection should time out.
- unnouinceput 6y agoQuote: "...as well as 8800 - I’m not sure what this port is." 800 / 880 / 8080 & 8800 are variations of classic 80. Try an http request there, see what you get. Or telnet to it at least.
- chkaloon 6y agoMy takeaway from these comment threads is no one is really quite sure how uPnP actually works.
- ksec 6y agoWe need a new term & new hardware that is an NAS but only available to Internal Network with no option of Internet access. I have for years wished Apple made something like that and has iPhone / iPad Backup automatically to it or Time Capsule for iOS. Instead they continue to push their iCloud for services revenue increase.