Seems it's sort of related to cgi-bin or backdoor of Synology's admin account.

-Basically it's getting system admin privilege -> Download script which encrypt all files + modifying the landing page

-So it's not related to your network speed (file encryption is done locally)

Possible workaround as PREVENTION:
Router Side:
-Setting ACL Rules: Deny NAS Outbound Connection (So scripts cannot be crawled)
-Disable Port 5000 redirection (If you still wished to access NAS, there's alternative way)

NAS Side:
-Strong Password
-Don't use admin again (Best Practice: Admin is Admin, User is User, for daily file access, use user account only)
-Network Configuration: Set DNS server to an invalid one, e.g. 192.168.254.254 (Most people won't set up network like this)
-Enable Network Recycle Bin, maybe find an external harddisk for that


***How to access NAS webpage in the safest way?
You may actually use
-VPN (but PPTP is proved to be unsafe)
-SSH Tunneling

Actually you may enable SSH, and set it to a strange port (e.g. 32122, not easy to guess, ah huh)
Do port forwarding in your router
When you're outside, you just Putty back to home - with port 32122, and add SSH tunneling to NAS IP (e.g. 192.168.1.1:5000) to port 5000
then you can access to the NAS at localhost:5000 when your SSH is connected and logged in.

http://howto.ccs.neu.edu/howto/w ... nneling-with-putty/

TOP

昨日都諗起呢樣野,想停一停左佢個ddns

TOP

弱弱的問句  
驚俾人撞密碼 login 嘅,點解唔用2步驗證?
咁係咪簡單得黎又安全啲?

via HKEPC Reade ...
C_K 發表於 2014-8-5 11:22



    根據大家回覆,HACKER 係經SSH or telnet 下手,不適用2步驗證

另有本人意見
1.改PORT (HACKER 應從PORT 5000 得知 SERVER 是否 S' NAS, 再經SSH or telnet 下手)
2.AUTO BLOCK (不用解釋)
3.有回覆說SET 防火牆為HONG KONG access only (HACKER 可能看到此POST後用VPN 扮係HK)
4.SSH or telnet 最好關掉,不過SET做內聯網也可以
5.改admin password / disable admin AC
6.如發現被HACK 而且在被加密途中,應立即關機並取出HARD DISK,把HARD DISK於其他電腦(有SYSTEM的)存取並BACKUP

TOP

我受害者   我想講我有set auto block ,ssh冇開的,怛我覺好大會係sSynology ddna 出問題
因為我本身用開自己的domain,早一個星期 先屎忽痕用myds.me 到怍日出事了

TOP

Try to search your ddns name in google
if >5, you have a great chance being hacked.

e.g. search jason.myds.me
https://www.google.com.hk/?gws_r ... amp;q=jason.myds.me

People will base on the information to hack in.

TOP

我受害者   我想講我有set auto block ,ssh冇開的,怛我覺好大會係sSynology ddna 出問題
因為我本身用 ...
glan 發表於 2014-8-5 14:16



    port 5000?

TOP

回覆 322# 某人兄

係隻NAS enable SSH? 係街入SSH去NAS再做SSH tunneling去NAS port 5000?
放NAS SSH出街, 咁咪仲危險. 係咁比人撞password.

TOP

其實到而家為止,似乎所有受害者都行緊唔Update未patch Heartbleed嘅DSM,又唔update DSM,又亂咁開port 5000俾人撞.... well...

TOP

回覆 327# tongziv


    YES

TOP

最危險係個web interface 有不知名漏洞比人bypass 咗個login機制再直接執行shell command, 再自己download一堆code行完自動encrypt HDD file, 所有咩auto block 都冇用,帷一係country block有小小用,呢隻似係world wide hacker所為, 盡量隔得幾多得幾多, 希望取易不取難,要先用HK IP再hack你部NAS比直接來得方便

TOP