Install the app
How to install the app on iOS

Follow along with the video below to see how to install our site as a web app on your home screen.

Note: This feature may not be available in some browsers.

Info Security and your DSM setup

That's kind of like what I asked..... If someone did this sort of thing
 
Last edited:
How did you find the person who did the review for you? Small business or independent?
A guy used to work with who was very good at breaking into and exploiting other people's complex networks & systems, nicking data without leaving evidence etc. Regular computer networks are kinda beneath him but he was a useful set of eyes and he is always interested in such stuff.

This arrived in my inbox yesterday, just to remind me that Synology is always on the ball though and nothing gets past them...

 2022-01-29 at 16.57.45.png

2/10 - must try harder

☕
 
The report didn't mention, but I assume your TVs are on your IoT VLAN (that's how I set things up in my house) so that they are separated from your personal devices (NAS, phones, laptops, etc.).

Yes, my TVs are outside my 'trusted' network as for other than external connectivity for updates they don't need to have access to anything. I certainly would not use any of the applications available on a TV.

My less trusted network (IoT) is called 'Lothlorien' - a TV and Harmony Hub are highlighted below:

 2022-01-29 at 18.05.33.webp


☕
 
What?! I totally trust Lothlorien! Wait are you a dwarf!? 🙂
 
Galadriel looks after all in Lothlorien.

As for me, well with Mirkwood on our west boundary, The Shires on the east and overlooking Hobbit Cottage to the immediate north and with a cast iron Smaug on our oak door, I guess we have to be hobbits rather than dwarves.
 
This topic probably never gets old.

Currently, they are available for a "resistance testing" up to 1.2M Synology hosts, which are directly open to the Internet.

They could already put the label right there "Welcome and enjoy".

Or just wait for such message:

1733071541456.webp
 
follow my short research:
45 588 Syno NASes accessible from WAN by standard HTTP (5000) port
54% of them have opened UPnP
7% of them have opened FTP

and people are crazy with SMB1, look here

check your IP and what “they” know about you at Shodan.io

Our mission here is providing a knowledge how to avoid such issues. More you can find in the Security part of this forum

What should we set UPnP to? Is this a setting on DSM and on SRM?
 
not here:
No ports open: router or NAS.
UPnp disabled.
All NAS & router on oddball port(s).
Only one NAS uses ftp, and that points to custom range within LAN only.
And all NAS are behind router.
 
Last edited:
Prompted by this thread I had my SOHO network looked at by a fresh set of eyes. Very rough and sanitised version of the observations below - specific to me but no doubt others will be similar.

The Good:

Code:
- Capable IPv4/IPv6 firewall with ‘reasonable’ settings and a well-understood and managed configuration
- No basic form of UPnP used - service deleted in toto
- WAN via PPPoE tunnel with hardline direct to backhaul / ISP router
- ISP selected for privacy / security
- ISP provides IP ‘machine name’ linked to them alone
- All ports in 'stealth' mode
- No DNS leaks
- Good L2 / L3 management
- Capable and fully mapped wifi system, robust settings, guest and IoT VLAN segregation
- Monitored full-home SDN, reserved IPs by MAC, very limited use of DHCP IPs
- Very limited exposure to IoT systems and all using HomeKit and/or Thread
- Only using Apple TVs for streaming services
- Only 2 x 24/7 servers - macOS and Synology
- Main Synology NAS only exposed to external access (eg DDNS) when specifically required for a task
- Secondary servers are LAN only and only powered during specific tasks (eg weekly backups)
- Only use macOS, iOS and Linux to avoid issues provided by the Windows and ‘droid attack surfaces
- Internal DNS, DNS cache / forwarder with DNSSEC to 2 external ‘trusted’ providers
- Internal Stratum 1 NTP server, available to LAN clients, secondary NTP server and via DHCP Option 42
- No use of ‘services’ that deliberately bypass security settings (eg Google Chrome, some cloud services, Microsoft etc)
- Full use of Apple tracking prevention
- Own domain points at US provider only, rather than my own static IP
- Small and trusted UK company used for web and email hosting, using my own domain
- Firmware and software up-to-date with managed upgrades
- Accurate database of all networked equipment and relevant security policies
- All obsolete or depreciated protocols disabled
- No use of Facebook, WhatsApp, whatever, where the commodity traded is the user
- Password management system
- Digital hygiene on personal information

The Bad:

Code:
- Modem maintained ‘blind’ by a 3rd party (Openreach) (but mitigated somewhat by PPPoE tunnel)
- WAN provided over G.fast that went into limited support faster than it was rolled-out and finally halted
- Router has UPnP2 enabled (albeit monitored and configured in Secure Mode only)
- Using own static IP for day to day use
- No Secure SNI (??)
- Single Windows server (rarely powered-up and cleansed of all bloat & telemetry) but Windows is a security issue in its own right
- No full DNS encryption (either DoT or the horrid DoH)
- No use of Synology NAS’s internal firewall
- One device that bypasses some internal security (SkyHD box) but constrained to an untrusted VLAN
- One device that seems to be becoming less trustworthy (2019 LG OLED), needing further constraint
- One device (client) with RJ45 capability connected via wifi instead (hey, that’s just 1 single client!)
- Plex server available for remote access 24/7 via somewhat randomised UPnP2 secured ports
- WoL enabled on servers that are typically switched-off 24/7
- No ACLs or locks enabled on switchports (does anyone do that?)
- No full disk encryption on NASes (Synology…)
- Servers without dedicated management interfaces (Synology…)
- Have a daughter

I think I understood nearly all of it, at least when it was being explained. The formal document is much more wordy!

I have some screenshots of the open source web tools used for the 'gross error' checks, if anyone is interested. Not sure of their value.

[edit] I should add that I did enable DNSSEC just before this, with this thread being the final prompt to sort it out.

☕

What is DNSSEC. I've been using 9.9.9.9 and now Cloudflare via DoH. Is that the same thing and as good? I have a 6600 router, and it has the option of running my own DNS server should I?

I tried several of the DNS services. Google was the worst exposing 6 servers. 9.9.9.9 was in the middle exposing 3 or 4. And cloud flare leaks only 2.

I would like to get the leaks down to zero but not sure how.
 
Other than GRC, is there any other trusted site I could go to to be remotely scanned to be tested for problems?
 
What is DNSSEC. I've been using 9.9.9.9 and now Cloudflare via DoH. Is that the same thing and as good? I have a 6600 router, and it has the option of running my own DNS server should I?

I tried several of the DNS services. Google was the worst exposing 6 servers. 9.9.9.9 was in the middle exposing 3 or 4. And cloud flare leaks only 2.

I would like to get the leaks down to zero but not sure how.
 
Other than GRC, is there any other trusted site I could go to to be remotely scanned to be tested for problems?
use “nmap” from remote site, because 99% of the paid tools use “nmap”
or use shodan.io
unless you're already in their DB
 

Create an account or login to comment

You must be a member in order to leave a comment

Create account

Create an account on our community. It's easy!

Log in

Already have an account? Log in here.

Popular tags from this forum

Similar threads

Any available port. For example, should you change the port 5001 to 8647, then you will need to change the...
Replies
5
Views
239
Thank you for your answer. I've been buisy and I did not have the opportunity to reply erlier. I'm not...
Replies
2
Views
216
Ah yes, I missed that you had put the source port as anything but ‘all’. Unless it’s a specific service...
Replies
5
Views
395

Thread Tags

Welcome to SynoForum.com!

SynoForum.com is an unofficial Synology forum for NAS owners and enthusiasts.

Registration is free, easy and fast!

Trending content in this forum

Back
Top