Welcome Guest ( Log In | Register )

Outline · [ Standard ] · Linear+

 NAS hacked

views
     
TSnate_nightroad
post Aug 3 2021, 03:32 PM, updated 5y ago

Endless numbered days...
*******
Senior Member
3,639 posts

Joined: Mar 2007


Just an awareness post. last weekend i suffered a massive data loss, over 1 tb of files and folders deleted. I investigated the issue and found out, some random IPs were scanning my IP ports and found an opening on my synology NAS.

needless to say, they login to my Synology through brute force and managed to randomly deleted my files and folders.

My advise is, if you are using synology and have quickconnect turned on. if you are not using the feature, turn it off. quickconnect allows you to connect to the NAS even if you are outside of your network. Eg, if you are at work using mobile, you can connect to the NAS through quickconnect.

If you need quickconnect, turn on 2-factor authentication. Even with brute force entry, they cant brute force the 6 digit authentication code. please refer to this site for a more thorough walk through: https://kb.synology.com/en-us/DSM/tutorial/...ur_Synology_NAS

Stay safe digitally guys.
l4nunm4l4y4
post Aug 3 2021, 03:34 PM

Enthusiast
*****
Junior Member
749 posts

Joined: Aug 2011
Woah, OK. Was thinking of investing in NAS. Now maybe not.
TSnate_nightroad
post Aug 3 2021, 03:35 PM

Endless numbered days...
*******
Senior Member
3,639 posts

Joined: Mar 2007


I am looking for a reliable data recovery expert, if you have any recommendation - please let me know

thank you
JK-Rai
post Aug 3 2021, 03:38 PM

New Member
*
Junior Member
37 posts

Joined: Oct 2015
You should turn on 2FA for login.
If you have quickconnect turned on.

Or use the built in OpenVPN.

This post has been edited by JK-Rai: Aug 3 2021, 03:41 PM
Lurker
post Aug 3 2021, 03:40 PM

L U R K I N G
Group Icon
Elite
4,420 posts

Joined: Jan 2003
how do you check if your NAS is being scanned?
matiko95
post Aug 3 2021, 03:41 PM

Enthusiast
*****
Senior Member
922 posts

Joined: Dec 2006
enable firewall
enable ip banning for number of login failed
2fa
enable ssl

because synology have these capability to
detterent brute force login.

crimv
post Aug 3 2021, 03:42 PM

Getting Started
**
Junior Member
242 posts

Joined: Jun 2009
i kena also but im using 2fa need token .. so cannot masuk
matiko95
post Aug 3 2021, 03:42 PM

Enthusiast
*****
Senior Member
922 posts

Joined: Dec 2006
QUOTE(Lurker @ Aug 3 2021, 03:40 PM)
how do you check if your NAS is being scanned?
*
in synology nas have detailed log for scanned / request activity

crimv
post Aug 3 2021, 03:42 PM

Getting Started
**
Junior Member
242 posts

Joined: Jun 2009
QUOTE(Lurker @ Aug 3 2021, 03:40 PM)
how do you check if your NAS is being scanned?
*
ada log will tell you .. something like an ip tried to attempt .. then locked etc etc
acbc
post Aug 3 2021, 03:43 PM

Look at all my stars!!
*******
Senior Member
9,037 posts

Joined: Jan 2003
Never allow the NAS to access the internet except for firmware updates.
TSnate_nightroad
post Aug 3 2021, 03:44 PM

Endless numbered days...
*******
Senior Member
3,639 posts

Joined: Mar 2007


QUOTE(Lurker @ Aug 3 2021, 03:40 PM)
how do you check if your NAS is being scanned?
*
from the my firewall log.. for example:

[LAN access from remote] from 99.253.XXX.XX:XXXXX to 192.168.X.X:XXXXX, Tuesday, Aug 03,2021 14:30:15
TSnate_nightroad
post Aug 3 2021, 03:45 PM

Endless numbered days...
*******
Senior Member
3,639 posts

Joined: Mar 2007


QUOTE(matiko95 @ Aug 3 2021, 03:42 PM)
in synology nas have detailed log for scanned / request activity
*
Yes, you can install log activity app from the store to have a more detailed report
SUSifourtos
post Aug 3 2021, 03:46 PM

Look at all my stars!!
*******
Senior Member
2,256 posts

Joined: Feb 2012



QUOTE(nate_nightroad @ Aug 3 2021, 03:35 PM)
I am looking for a reliable data recovery expert, if you have any recommendation - please let me know

thank you
*
https://undelete360.com/




honestly.

with the speed of Internet today.
why using Local Storage? instead of Cloud?

honesly, extreme important data better be on cloud. or Double cloud.
Lurker
post Aug 3 2021, 03:46 PM

L U R K I N G
Group Icon
Elite
4,420 posts

Joined: Jan 2003
QUOTE(matiko95 @ Aug 3 2021, 03:42 PM)
in synology nas have detailed log for scanned / request activity
*
QUOTE(crimv @ Aug 3 2021, 03:42 PM)
ada log will tell you .. something like an ip tried to attempt .. then locked etc etc
*
QUOTE(nate_nightroad @ Aug 3 2021, 03:44 PM)
from the my firewall log.. for example:

[LAN access from remote] from 99.253.XXX.XX:XXXXX to 192.168.X.X:XXXXX, Tuesday, Aug 03,2021 14:30:15
*
security advisor >login analysis?
y888c
post Aug 3 2021, 03:49 PM

Getting Started
**
Junior Member
57 posts

Joined: Jun 2013
Sorry to hear that TS, hope you can recover your files. btw agree with cloud solution. I am choosing between NAS/cloud and I choose cloud in the end
Xaphier
post Aug 3 2021, 03:52 PM

Casual
***
Junior Member
495 posts

Joined: Sep 2007


Also disable the default Admin user. Create a new user with admin privilege. Knowing the correct ID to login is already half the game.
TSnate_nightroad
post Aug 3 2021, 03:52 PM

Endless numbered days...
*******
Senior Member
3,639 posts

Joined: Mar 2007


Yes.. allow me to share my corrective and preventive actions:

1. Install DS finder and turn on notification on synology - therefore any funny stuff, you get notified immediately

2. ALWAYS do back up, depending on the importance of the files, do it daily, weekly, monthly, quarterly, half yearly or yearly

3. do a security audit from time to time

4. change any default ports, these are frequently scanned by hackers or malware

5. use cloud back up and back up the cloud data too from time to time
TSnate_nightroad
post Aug 3 2021, 03:53 PM

Endless numbered days...
*******
Senior Member
3,639 posts

Joined: Mar 2007


QUOTE(Lurker @ Aug 3 2021, 03:46 PM)
security advisor >login analysis?
*
Yes, but the one i shared is from my personal firewall…so i have 2 firewalls - one on the NAS and another is from the router end
TSnate_nightroad
post Aug 3 2021, 03:54 PM

Endless numbered days...
*******
Senior Member
3,639 posts

Joined: Mar 2007


QUOTE(ifourtos @ Aug 3 2021, 03:46 PM)
https://undelete360.com/
honestly.

with the speed of Internet today.
why using Local Storage? instead of Cloud?

honesly, extreme important data better be on cloud. or Double cloud.
*
have you use undelete before? i was thinking about https://www.mydatarecovery.my
Saitama
post Aug 3 2021, 03:58 PM

Casual
***
Junior Member
307 posts

Joined: Sep 2013
QUOTE(nate_nightroad @ Aug 3 2021, 03:54 PM)
have you use undelete before? i was thinking about https://www.mydatarecovery.my
*
used their services b4. good service. fair charging rate.
SUSifourtos
post Aug 3 2021, 03:59 PM

Look at all my stars!!
*******
Senior Member
2,256 posts

Joined: Feb 2012



QUOTE(nate_nightroad @ Aug 3 2021, 03:54 PM)
have you use undelete before? i was thinking about https://www.mydatarecovery.my
*
go youtube educate yourself.

i using undelete since MSDOS era.


Delete is not Delete in filesystem.

Wipe is Delete.

Delete is only remove the file entry data on file system registry.

all the sector contain the data is untouched.

as long as the free space after delete is "UNTOUCHED"
undelete is possible.


but when the sector is re-written by new data. another story.

dont use Malaysia tech lah.. or malaysia software.
TSnate_nightroad
post Aug 3 2021, 04:10 PM

Endless numbered days...
*******
Senior Member
3,639 posts

Joined: Mar 2007


QUOTE(ifourtos @ Aug 3 2021, 03:59 PM)
go youtube educate yourself.

i using undelete since MSDOS era.
Delete is not Delete in filesystem.

Wipe is Delete.

Delete is only remove the file entry data on file system registry.

all the sector contain the data is untouched.

as long as the free space after delete is "UNTOUCHED"
undelete is possible.
but when the sector is re-written by new data. another story.

dont use Malaysia tech lah.. or malaysia software.
*
i know this buddy.. and synology format is linux and my harddrive is ext4..i can install driver to read the drive but i cant be sure if undelete could scan and recover
TSnate_nightroad
post Aug 3 2021, 04:10 PM

Endless numbered days...
*******
Senior Member
3,639 posts

Joined: Mar 2007


QUOTE(Saitama @ Aug 3 2021, 03:58 PM)
used their services b4. good service. fair charging rate.
*
you mean mydatarecovery is good?
megahertz
post Aug 3 2021, 04:17 PM

i always smiling, problem?
******
Senior Member
1,846 posts

Joined: Apr 2008
u didnt set limit on brute force trial ? im using synology for years. i think around 7-8 years.
so far only few times got notified some login failure by some brute force bot. btw please disable default admin as well. use diff username


This post has been edited by megahertz: Aug 3 2021, 04:20 PM
Saitama
post Aug 3 2021, 04:22 PM

Casual
***
Junior Member
307 posts

Joined: Sep 2013
QUOTE(nate_nightroad @ Aug 3 2021, 04:10 PM)
you mean mydatarecovery is good?
*
yeah
TSnate_nightroad
post Aug 3 2021, 06:21 PM

Endless numbered days...
*******
Senior Member
3,639 posts

Joined: Mar 2007


QUOTE(megahertz @ Aug 3 2021, 04:17 PM)
u didnt set limit on brute force trial ? im using synology for years. i think around 7-8 years.
so far only few times got notified some login failure by some brute force bot. btw please disable default admin as well. use diff username
*
Unfortunately i did not get it
driftmeister
post Aug 3 2021, 06:57 PM

Penggadai Rakyat®
*******
Senior Member
4,133 posts

Joined: Jan 2003
From: Cameron Highlands Rank: Amateur
have tried using UFS file explorer?
TSnate_nightroad
post Aug 3 2021, 07:37 PM

Endless numbered days...
*******
Senior Member
3,639 posts

Joined: Mar 2007


QUOTE(driftmeister @ Aug 3 2021, 06:57 PM)
have tried using UFS file explorer?
*
No. Any good? You tried?
driftmeister
post Aug 3 2021, 09:49 PM

Penggadai Rakyat®
*******
Senior Member
4,133 posts

Joined: Jan 2003
From: Cameron Highlands Rank: Amateur
QUOTE(nate_nightroad @ Aug 3 2021, 07:37 PM)
No. Any good? You tried?
*
yup. my syn nas was corrupted couple of years back and i manage to recover the files.
TSnate_nightroad
post Aug 4 2021, 01:25 AM

Endless numbered days...
*******
Senior Member
3,639 posts

Joined: Mar 2007


QUOTE(driftmeister @ Aug 3 2021, 09:49 PM)
yup. my syn nas was corrupted couple of years back and i manage to recover the files.
*
Question: when you recover the files, are they in correct file names and correct directories?

I tried running one before but the file names are not in the original and no folder structure which is a big pain.
driftmeister
post Aug 4 2021, 09:10 AM

Penggadai Rakyat®
*******
Senior Member
4,133 posts

Joined: Jan 2003
From: Cameron Highlands Rank: Amateur
QUOTE(nate_nightroad @ Aug 4 2021, 01:25 AM)
Question: when you recover the files, are they in correct file names and correct directories?

I tried running one before but the file names are not in the original and no folder structure which is a big pain.
*
don't think i encountered that. just that it recovered some of the deleted files as well.
ktek
post Aug 4 2021, 10:39 AM

小喇叭
********
All Stars
13,187 posts

Joined: Jul 2006
no wonder syn keep asking me to disable admin acc.
i just did hopefully safe
ktek
post Aug 4 2021, 10:50 AM

小喇叭
********
All Stars
13,187 posts

Joined: Jul 2006
from where do we change quickconnect port numbers
TSnate_nightroad
post Aug 4 2021, 11:23 AM

Endless numbered days...
*******
Senior Member
3,639 posts

Joined: Mar 2007


QUOTE(ktek @ Aug 4 2021, 10:50 AM)
from where do we change quickconnect port numbers
*
Attached Image

It’s under https and http. Change both

This post has been edited by nate_nightroad: Aug 4 2021, 11:49 AM
ktek
post Aug 4 2021, 12:36 PM

小喇叭
********
All Stars
13,187 posts

Joined: Jul 2006
QUOTE(nate_nightroad @ Aug 4 2021, 11:23 AM)
Attached Image

It’s under https and http. Change both
*
saved
TSnate_nightroad
post Aug 4 2021, 12:37 PM

Endless numbered days...
*******
Senior Member
3,639 posts

Joined: Mar 2007


So i have updated DMS 7, it's more secure.. I recommend it!
ktek
post Aug 4 2021, 01:56 PM

小喇叭
********
All Stars
13,187 posts

Joined: Jul 2006
just found dsm7 version as well. i will research a bit b4 click
rx330
post Aug 5 2021, 09:34 AM

10k Club
********
All Stars
11,808 posts

Joined: Jun 2006
thanks to Kevin for the headsup

scary ler, better do 2FA

is there any dedicated thread on Synology users here? sometimes I damn headache even after years of using
ktek
post Aug 5 2021, 03:50 PM

小喇叭
********
All Stars
13,187 posts

Joined: Jul 2006
another fren kena same thing. i told him jaga & not sure his damage

[8/5 15:53] 吃饱太得空
[8/5 16:14] As on 3/8 a lot of file missing
[8/5 16:15] Cb, kena hack
TSnate_nightroad
post Aug 5 2021, 04:15 PM

Endless numbered days...
*******
Senior Member
3,639 posts

Joined: Mar 2007


QUOTE(ktek @ Aug 5 2021, 03:50 PM)
another fren kena same thing. i told him jaga & not sure his damage

[8/5 15:53] 吃饱太得空
[8/5 16:14] As on 3/8 a lot of file missing
[8/5 16:15] Cb, kena hack
*
please turn of 2FA, and change the quickconnect default port

take care everyone

 

Change to:
| Lo-Fi Version
0.0344sec    0.27    6 queries    GZIP Disabled
Time is now: 29th November 2025 - 03:01 AM