What's new
  • SNBForums Code of Conduct

    SNBForums is a community for everyone, no matter what their level of experience.

    Please be tolerant and patient of others, especially newcomers. We are all here to share and learn!

    The rules are simple: Be patient, be nice, be helpful or be gone!

Security -- Beating to Quarters on DSM 7

JoeHz

Occasional Visitor
I just got a mega bleep ton of login attempts alerted to me this morning. Someone from Lausanne Switzerland 179.43.145.42, but it appears to be a VPN originating from privatelayer.com.

Check your login attempts folks. And disable the default accounts.
 
This has always been a thing. Login attempts to any device on a nerwork happen so often it becomes just "background noise".
 
Yeah, I see router attacks all the time, and I don't even know if Windows Popup messages are a thing anymore but they were pervasive, but Synology aimed attacks seem to be new (at least for me). This is the first time in opening that port 18 months ago that I've gotten an automated login bot aimed at it.

What's the standard obfuscation method for this one? Move off of port 5000? Two Factor? I do have remote users so it needs to be open.
 
Yeah, I see router attacks all the time, and I don't even know if Windows Popup messages are a thing anymore but they were pervasive, but Synology aimed attacks seem to be new (at least for me). This is the first time in opening that port 18 months ago that I've gotten an automated login bot aimed at it.

What's the standard obfuscation method for this one? Move off of port 5000? Two Factor? I do have remote users so it needs to be open.
Changing ports will mitigate, but only until someone latches onto the new port.
I run everything behind a VPN, and even then I randomly change that to a random port.
 
What's the standard obfuscation method for this one? Move off of port 5000? Two Factor? I do have remote users so it needs to be open.

Don't expose your NAS directly to the internet nowadays would be my advice.
An appropriately configured Tailscale network (don't know how trusted your remote users are so can't advise specifics) is another option you could look into...
 
Aye mate. But, beating to quarters after the attack is too late...
 
An appropriately configured Tailscale network (don't know how trusted your remote users are so can't advise specifics) is another option you could look into...

Yes - Tailscale is supported as a first party app by QNAP and Synology DSM7

Screenshot 2025-07-04 at 4.59.33 PM.png
Screenshot 2025-07-04 at 4.58.03 PM.png
 
Yeah, I think a VPN for the people who need it is appropriate. The fact it's only happened once is a pretty good indicator of it not being low hanging fruit. I figured I'd have found out immediately if it was a problem but it actually took over 18 months.
 

Support SNBForums w/ Amazon

If you'd like to support SNBForums, just use this link and buy anything on Amazon. Thanks!

Sign Up For SNBForums Daily Digest

Get an update of what's new every day delivered to your mailbox. Sign up here!
Back
Top