Welcome Guest ( Log In | Register )

Outline · [ Standard ] · Linear+

 NAS hacked

views
     
TSnate_nightroad
post Aug 3 2021, 03:32 PM, updated 5y ago

Endless numbered days...
*******
Senior Member
3,639 posts

Joined: Mar 2007


Just an awareness post. last weekend i suffered a massive data loss, over 1 tb of files and folders deleted. I investigated the issue and found out, some random IPs were scanning my IP ports and found an opening on my synology NAS.

needless to say, they login to my Synology through brute force and managed to randomly deleted my files and folders.

My advise is, if you are using synology and have quickconnect turned on. if you are not using the feature, turn it off. quickconnect allows you to connect to the NAS even if you are outside of your network. Eg, if you are at work using mobile, you can connect to the NAS through quickconnect.

If you need quickconnect, turn on 2-factor authentication. Even with brute force entry, they cant brute force the 6 digit authentication code. please refer to this site for a more thorough walk through: https://kb.synology.com/en-us/DSM/tutorial/...ur_Synology_NAS

Stay safe digitally guys.
TSnate_nightroad
post Aug 3 2021, 03:35 PM

Endless numbered days...
*******
Senior Member
3,639 posts

Joined: Mar 2007


I am looking for a reliable data recovery expert, if you have any recommendation - please let me know

thank you
TSnate_nightroad
post Aug 3 2021, 03:44 PM

Endless numbered days...
*******
Senior Member
3,639 posts

Joined: Mar 2007


QUOTE(Lurker @ Aug 3 2021, 03:40 PM)
how do you check if your NAS is being scanned?
*
from the my firewall log.. for example:

[LAN access from remote] from 99.253.XXX.XX:XXXXX to 192.168.X.X:XXXXX, Tuesday, Aug 03,2021 14:30:15
TSnate_nightroad
post Aug 3 2021, 03:45 PM

Endless numbered days...
*******
Senior Member
3,639 posts

Joined: Mar 2007


QUOTE(matiko95 @ Aug 3 2021, 03:42 PM)
in synology nas have detailed log for scanned / request activity
*
Yes, you can install log activity app from the store to have a more detailed report
TSnate_nightroad
post Aug 3 2021, 03:52 PM

Endless numbered days...
*******
Senior Member
3,639 posts

Joined: Mar 2007


Yes.. allow me to share my corrective and preventive actions:

1. Install DS finder and turn on notification on synology - therefore any funny stuff, you get notified immediately

2. ALWAYS do back up, depending on the importance of the files, do it daily, weekly, monthly, quarterly, half yearly or yearly

3. do a security audit from time to time

4. change any default ports, these are frequently scanned by hackers or malware

5. use cloud back up and back up the cloud data too from time to time
TSnate_nightroad
post Aug 3 2021, 03:53 PM

Endless numbered days...
*******
Senior Member
3,639 posts

Joined: Mar 2007


QUOTE(Lurker @ Aug 3 2021, 03:46 PM)
security advisor >login analysis?
*
Yes, but the one i shared is from my personal firewall…so i have 2 firewalls - one on the NAS and another is from the router end
TSnate_nightroad
post Aug 3 2021, 03:54 PM

Endless numbered days...
*******
Senior Member
3,639 posts

Joined: Mar 2007


QUOTE(ifourtos @ Aug 3 2021, 03:46 PM)
https://undelete360.com/
honestly.

with the speed of Internet today.
why using Local Storage? instead of Cloud?

honesly, extreme important data better be on cloud. or Double cloud.
*
have you use undelete before? i was thinking about https://www.mydatarecovery.my
TSnate_nightroad
post Aug 3 2021, 04:10 PM

Endless numbered days...
*******
Senior Member
3,639 posts

Joined: Mar 2007


QUOTE(ifourtos @ Aug 3 2021, 03:59 PM)
go youtube educate yourself.

i using undelete since MSDOS era.
Delete is not Delete in filesystem.

Wipe is Delete.

Delete is only remove the file entry data on file system registry.

all the sector contain the data is untouched.

as long as the free space after delete is "UNTOUCHED"
undelete is possible.
but when the sector is re-written by new data. another story.

dont use Malaysia tech lah.. or malaysia software.
*
i know this buddy.. and synology format is linux and my harddrive is ext4..i can install driver to read the drive but i cant be sure if undelete could scan and recover
TSnate_nightroad
post Aug 3 2021, 04:10 PM

Endless numbered days...
*******
Senior Member
3,639 posts

Joined: Mar 2007


QUOTE(Saitama @ Aug 3 2021, 03:58 PM)
used their services b4. good service. fair charging rate.
*
you mean mydatarecovery is good?
TSnate_nightroad
post Aug 3 2021, 06:21 PM

Endless numbered days...
*******
Senior Member
3,639 posts

Joined: Mar 2007


QUOTE(megahertz @ Aug 3 2021, 04:17 PM)
u didnt set limit on brute force trial ? im using synology for years. i think around 7-8 years.
so far only few times got notified some login failure by some brute force bot. btw please disable default admin as well. use diff username
*
Unfortunately i did not get it
TSnate_nightroad
post Aug 3 2021, 07:37 PM

Endless numbered days...
*******
Senior Member
3,639 posts

Joined: Mar 2007


QUOTE(driftmeister @ Aug 3 2021, 06:57 PM)
have tried using UFS file explorer?
*
No. Any good? You tried?
TSnate_nightroad
post Aug 4 2021, 01:25 AM

Endless numbered days...
*******
Senior Member
3,639 posts

Joined: Mar 2007


QUOTE(driftmeister @ Aug 3 2021, 09:49 PM)
yup. my syn nas was corrupted couple of years back and i manage to recover the files.
*
Question: when you recover the files, are they in correct file names and correct directories?

I tried running one before but the file names are not in the original and no folder structure which is a big pain.
TSnate_nightroad
post Aug 4 2021, 11:23 AM

Endless numbered days...
*******
Senior Member
3,639 posts

Joined: Mar 2007


QUOTE(ktek @ Aug 4 2021, 10:50 AM)
from where do we change quickconnect port numbers
*
Attached Image

It’s under https and http. Change both

This post has been edited by nate_nightroad: Aug 4 2021, 11:49 AM
TSnate_nightroad
post Aug 4 2021, 12:37 PM

Endless numbered days...
*******
Senior Member
3,639 posts

Joined: Mar 2007


So i have updated DMS 7, it's more secure.. I recommend it!
TSnate_nightroad
post Aug 5 2021, 04:15 PM

Endless numbered days...
*******
Senior Member
3,639 posts

Joined: Mar 2007


QUOTE(ktek @ Aug 5 2021, 03:50 PM)
another fren kena same thing. i told him jaga & not sure his damage

[8/5 15:53] 吃饱太得空
[8/5 16:14] As on 3/8 a lot of file missing
[8/5 16:15] Cb, kena hack
*
please turn of 2FA, and change the quickconnect default port

take care everyone

 

Change to:
| Lo-Fi Version
0.0251sec    0.45    7 queries    GZIP Disabled
Time is now: 27th November 2025 - 09:47 PM