- 2,774
- 519
- NAS
- DS 718+, 2x-DS 720+
- Router
- RT2600ac
- Operating system
- Windows
- Mobile operating system
- iOS
Follow along with the video below to see how to install our site as a web app on your home screen.
Note: This feature may not be available in some browsers.
A guy used to work with who was very good at breaking into and exploiting other people's complex networks & systems, nicking data without leaving evidence etc. Regular computer networks are kinda beneath him but he was a useful set of eyes and he is always interested in such stuff.How did you find the person who did the review for you? Small business or independent?
The report didn't mention, but I assume your TVs are on your IoT VLAN (that's how I set things up in my house) so that they are separated from your personal devices (NAS, phones, laptops, etc.).
follow my short research:
45 588 Syno NASes accessible from WAN by standard HTTP (5000) port
54% of them have opened UPnP
7% of them have opened FTP
and people are crazy with SMB1, look here
check your IP and what “they” know about you at Shodan.io
Our mission here is providing a knowledge how to avoid such issues. More you can find in the Security part of this forum
Prompted by this thread I had my SOHO network looked at by a fresh set of eyes. Very rough and sanitised version of the observations below - specific to me but no doubt others will be similar.
The Good:
Code:- Capable IPv4/IPv6 firewall with ‘reasonable’ settings and a well-understood and managed configuration - No basic form of UPnP used - service deleted in toto - WAN via PPPoE tunnel with hardline direct to backhaul / ISP router - ISP selected for privacy / security - ISP provides IP ‘machine name’ linked to them alone - All ports in 'stealth' mode - No DNS leaks - Good L2 / L3 management - Capable and fully mapped wifi system, robust settings, guest and IoT VLAN segregation - Monitored full-home SDN, reserved IPs by MAC, very limited use of DHCP IPs - Very limited exposure to IoT systems and all using HomeKit and/or Thread - Only using Apple TVs for streaming services - Only 2 x 24/7 servers - macOS and Synology - Main Synology NAS only exposed to external access (eg DDNS) when specifically required for a task - Secondary servers are LAN only and only powered during specific tasks (eg weekly backups) - Only use macOS, iOS and Linux to avoid issues provided by the Windows and ‘droid attack surfaces - Internal DNS, DNS cache / forwarder with DNSSEC to 2 external ‘trusted’ providers - Internal Stratum 1 NTP server, available to LAN clients, secondary NTP server and via DHCP Option 42 - No use of ‘services’ that deliberately bypass security settings (eg Google Chrome, some cloud services, Microsoft etc) - Full use of Apple tracking prevention - Own domain points at US provider only, rather than my own static IP - Small and trusted UK company used for web and email hosting, using my own domain - Firmware and software up-to-date with managed upgrades - Accurate database of all networked equipment and relevant security policies - All obsolete or depreciated protocols disabled - No use of Facebook, WhatsApp, whatever, where the commodity traded is the user - Password management system - Digital hygiene on personal information
The Bad:
Code:- Modem maintained ‘blind’ by a 3rd party (Openreach) (but mitigated somewhat by PPPoE tunnel) - WAN provided over G.fast that went into limited support faster than it was rolled-out and finally halted - Router has UPnP2 enabled (albeit monitored and configured in Secure Mode only) - Using own static IP for day to day use - No Secure SNI (??) - Single Windows server (rarely powered-up and cleansed of all bloat & telemetry) but Windows is a security issue in its own right - No full DNS encryption (either DoT or the horrid DoH) - No use of Synology NAS’s internal firewall - One device that bypasses some internal security (SkyHD box) but constrained to an untrusted VLAN - One device that seems to be becoming less trustworthy (2019 LG OLED), needing further constraint - One device (client) with RJ45 capability connected via wifi instead (hey, that’s just 1 single client!) - Plex server available for remote access 24/7 via somewhat randomised UPnP2 secured ports - WoL enabled on servers that are typically switched-off 24/7 - No ACLs or locks enabled on switchports (does anyone do that?) - No full disk encryption on NASes (Synology…) - Servers without dedicated management interfaces (Synology…) - Have a daughter
I think I understood nearly all of it, at least when it was being explained. The formal document is much more wordy!
I have some screenshots of the open source web tools used for the 'gross error' checks, if anyone is interested. Not sure of their value.
[edit] I should add that I did enable DNSSEC just before this, with this thread being the final prompt to sort it out.
️
What is DNSSEC. I've been using 9.9.9.9 and now Cloudflare via DoH. Is that the same thing and as good? I have a 6600 router, and it has the option of running my own DNS server should I?
I tried several of the DNS services. Google was the worst exposing 6 servers. 9.9.9.9 was in the middle exposing 3 or 4. And cloud flare leaks only 2.
I would like to get the leaks down to zero but not sure how.
use “nmap” from remote site, because 99% of the paid tools use “nmap”Other than GRC, is there any other trusted site I could go to to be remotely scanned to be tested for problems?
We use essential cookies to make this site work, and optional cookies to enhance your experience.