4 ms·
How do you think they accessed your NAS?
by OWaz 12y ago
How do you think they accessed your NAS?
- AmVess 12y agoReally, there aren't that many ways to gain access. Two primary and likely methods: 1) Weak passcode. 2) Security exploit in DSM. The fixes are easy; better passcode, and turn off remote access to the device until whatever flaw(s) can be patched.
- quasse 12y agoyou would still need to have ports forwarded to the NAS from the internet, a compromised router, or the NAS connected directly to the open internet. All of which are a bad idea.
- 0x0 12y agoIf the device is vulnerable to a CSRF, then couldn't it be compromised simply by some browser on the LAN ending up on an unfortunate site that does some javascript hijinks to POST to likely, internal, IP addresses for a NAS? No open WAN ports needed. Also, wasn't there a remote root exploit for samba4 patched just days ago?
- me1010 12y agohttp://www.wegotserved.com/2014/07/30/synology-patches-nas-security-vulnerability-improves-raid-stability/ http://www.wegotserved.com/2014/07/30/synology-patches-nas-s... However, there's really no reason to expose samba shares to the Internet. There are much better and more secure methods. As to the unfortunate victim, there's most likely no way anyone will be able to retrieve what has been locked by the remote attacker - except the remote attacker.