Seems it's sort of related to cgi-bin or backdoor of Synology's admin account.
-Basically it's getting system admin privilege -> Download script which encrypt all files + modifying the landing page
-So it's not related to your network speed (file encryption is done locally)
Possible workaround as PREVENTION:
Router Side:
-Setting ACL Rules: Deny NAS Outbound Connection (So scripts cannot be crawled)
-Disable Port 5000 redirection (If you still wished to access NAS, there's alternative way)
NAS Side:
-Strong Password
-Don't use admin again (Best Practice: Admin is Admin, User is User, for daily file access, use user account only)
-Network Configuration: Set DNS server to an invalid one, e.g. 192.168.254.254 (Most people won't set up network like this)
-Enable Network Recycle Bin, maybe find an external harddisk for that
***How to access NAS webpage in the safest way?
You may actually use
-VPN (but PPTP is proved to be unsafe)
-SSH Tunneling
Actually you may enable SSH, and set it to a strange port (e.g. 32122, not easy to guess, ah huh)
Do port forwarding in your router
When you're outside, you just Putty back to home - with port 32122, and add SSH tunneling to NAS IP (e.g. 192.168.1.1:5000) to port 5000
then you can access to the NAS at localhost:5000 when your SSH is connected and logged in.
http://howto.ccs.neu.edu/howto/w ... nneling-with-putty/ |