Welcome Guest ( Log In | Register )

Outline · [ Standard ] · Linear+

 NAS hacked

views
     
TSnate_nightroad
post Aug 3 2021, 03:32 PM, updated 5y ago

Endless numbered days...
*******
Senior Member
3,639 posts

Joined: Mar 2007


Just an awareness post. last weekend i suffered a massive data loss, over 1 tb of files and folders deleted. I investigated the issue and found out, some random IPs were scanning my IP ports and found an opening on my synology NAS.

needless to say, they login to my Synology through brute force and managed to randomly deleted my files and folders.

My advise is, if you are using synology and have quickconnect turned on. if you are not using the feature, turn it off. quickconnect allows you to connect to the NAS even if you are outside of your network. Eg, if you are at work using mobile, you can connect to the NAS through quickconnect.

If you need quickconnect, turn on 2-factor authentication. Even with brute force entry, they cant brute force the 6 digit authentication code. please refer to this site for a more thorough walk through: https://kb.synology.com/en-us/DSM/tutorial/...ur_Synology_NAS

Stay safe digitally guys.
l4nunm4l4y4
post Aug 3 2021, 03:34 PM

Enthusiast
*****
Junior Member
749 posts

Joined: Aug 2011
Woah, OK. Was thinking of investing in NAS. Now maybe not.
TSnate_nightroad
post Aug 3 2021, 03:35 PM

Endless numbered days...
*******
Senior Member
3,639 posts

Joined: Mar 2007


I am looking for a reliable data recovery expert, if you have any recommendation - please let me know

thank you
JK-Rai
post Aug 3 2021, 03:38 PM

New Member
*
Junior Member
37 posts

Joined: Oct 2015
You should turn on 2FA for login.
If you have quickconnect turned on.

Or use the built in OpenVPN.

This post has been edited by JK-Rai: Aug 3 2021, 03:41 PM
Lurker
post Aug 3 2021, 03:40 PM

L U R K I N G
Group Icon
Elite
4,420 posts

Joined: Jan 2003
how do you check if your NAS is being scanned?
matiko95
post Aug 3 2021, 03:41 PM

Enthusiast
*****
Senior Member
922 posts

Joined: Dec 2006
enable firewall
enable ip banning for number of login failed
2fa
enable ssl

because synology have these capability to
detterent brute force login.

crimv
post Aug 3 2021, 03:42 PM

Getting Started
**
Junior Member
242 posts

Joined: Jun 2009
i kena also but im using 2fa need token .. so cannot masuk
matiko95
post Aug 3 2021, 03:42 PM

Enthusiast
*****
Senior Member
922 posts

Joined: Dec 2006
QUOTE(Lurker @ Aug 3 2021, 03:40 PM)
how do you check if your NAS is being scanned?
*
in synology nas have detailed log for scanned / request activity

crimv
post Aug 3 2021, 03:42 PM

Getting Started
**
Junior Member
242 posts

Joined: Jun 2009
QUOTE(Lurker @ Aug 3 2021, 03:40 PM)
how do you check if your NAS is being scanned?
*
ada log will tell you .. something like an ip tried to attempt .. then locked etc etc
acbc
post Aug 3 2021, 03:43 PM

Look at all my stars!!
*******
Senior Member
9,037 posts

Joined: Jan 2003
Never allow the NAS to access the internet except for firmware updates.
TSnate_nightroad
post Aug 3 2021, 03:44 PM

Endless numbered days...
*******
Senior Member
3,639 posts

Joined: Mar 2007


QUOTE(Lurker @ Aug 3 2021, 03:40 PM)
how do you check if your NAS is being scanned?
*
from the my firewall log.. for example:

[LAN access from remote] from 99.253.XXX.XX:XXXXX to 192.168.X.X:XXXXX, Tuesday, Aug 03,2021 14:30:15
TSnate_nightroad
post Aug 3 2021, 03:45 PM

Endless numbered days...
*******
Senior Member
3,639 posts

Joined: Mar 2007


QUOTE(matiko95 @ Aug 3 2021, 03:42 PM)
in synology nas have detailed log for scanned / request activity
*
Yes, you can install log activity app from the store to have a more detailed report
SUSifourtos
post Aug 3 2021, 03:46 PM

Look at all my stars!!
*******
Senior Member
2,256 posts

Joined: Feb 2012



QUOTE(nate_nightroad @ Aug 3 2021, 03:35 PM)
I am looking for a reliable data recovery expert, if you have any recommendation - please let me know

thank you
*
https://undelete360.com/




honestly.

with the speed of Internet today.
why using Local Storage? instead of Cloud?

honesly, extreme important data better be on cloud. or Double cloud.
Lurker
post Aug 3 2021, 03:46 PM

L U R K I N G
Group Icon
Elite
4,420 posts

Joined: Jan 2003
QUOTE(matiko95 @ Aug 3 2021, 03:42 PM)
in synology nas have detailed log for scanned / request activity
*
QUOTE(crimv @ Aug 3 2021, 03:42 PM)
ada log will tell you .. something like an ip tried to attempt .. then locked etc etc
*
QUOTE(nate_nightroad @ Aug 3 2021, 03:44 PM)
from the my firewall log.. for example:

[LAN access from remote] from 99.253.XXX.XX:XXXXX to 192.168.X.X:XXXXX, Tuesday, Aug 03,2021 14:30:15
*
security advisor >login analysis?
y888c
post Aug 3 2021, 03:49 PM

Getting Started
**
Junior Member
57 posts

Joined: Jun 2013
Sorry to hear that TS, hope you can recover your files. btw agree with cloud solution. I am choosing between NAS/cloud and I choose cloud in the end
Xaphier
post Aug 3 2021, 03:52 PM

Casual
***
Junior Member
495 posts

Joined: Sep 2007


Also disable the default Admin user. Create a new user with admin privilege. Knowing the correct ID to login is already half the game.
TSnate_nightroad
post Aug 3 2021, 03:52 PM

Endless numbered days...
*******
Senior Member
3,639 posts

Joined: Mar 2007


Yes.. allow me to share my corrective and preventive actions:

1. Install DS finder and turn on notification on synology - therefore any funny stuff, you get notified immediately

2. ALWAYS do back up, depending on the importance of the files, do it daily, weekly, monthly, quarterly, half yearly or yearly

3. do a security audit from time to time

4. change any default ports, these are frequently scanned by hackers or malware

5. use cloud back up and back up the cloud data too from time to time
TSnate_nightroad
post Aug 3 2021, 03:53 PM

Endless numbered days...
*******
Senior Member
3,639 posts

Joined: Mar 2007


QUOTE(Lurker @ Aug 3 2021, 03:46 PM)
security advisor >login analysis?
*
Yes, but the one i shared is from my personal firewall…so i have 2 firewalls - one on the NAS and another is from the router end
TSnate_nightroad
post Aug 3 2021, 03:54 PM

Endless numbered days...
*******
Senior Member
3,639 posts

Joined: Mar 2007


QUOTE(ifourtos @ Aug 3 2021, 03:46 PM)
https://undelete360.com/
honestly.

with the speed of Internet today.
why using Local Storage? instead of Cloud?

honesly, extreme important data better be on cloud. or Double cloud.
*
have you use undelete before? i was thinking about https://www.mydatarecovery.my
Saitama
post Aug 3 2021, 03:58 PM

Casual
***
Junior Member
307 posts

Joined: Sep 2013
QUOTE(nate_nightroad @ Aug 3 2021, 03:54 PM)
have you use undelete before? i was thinking about https://www.mydatarecovery.my
*
used their services b4. good service. fair charging rate.

2 Pages  1 2 >Top
 

Change to:
| Lo-Fi Version
0.0190sec    0.79    6 queries    GZIP Disabled
Time is now: 29th November 2025 - 05:12 AM