Jump to content
XPEnology Community

Security: brute force attacks


BeberGold

Recommended Posts

Good morning,

 

I started using synology 3-4 months ago.

 

After reviewing the logs, I noticed my NAS is under permanent brute force attacks.

 

Initially, I started blocking IPs manually (by adding one by one in the firewall with a 'deny' rule), but then I noticed that IPs kept changing as I blocked them. It does not look like a good use of my time.

 

The synology servicedesk is not very helpful:

- blocking countries is not working: still getting brute force from one of the three countries I allow,

- multi factor authentication: does not work on FTP. FTP transfers are much faster than the web interface.

- Brute force is only conducted on SSH. The service desk advised to disable SSH, but even when I disable SSH the box is still processing SSH login requests! (Bruteforce via SSH continues with SSH disabled.)

 

The next step is to block SSH on the firewall of the NAS.

Any other idea?

Link to comment
Share on other sites

On 6/23/2023 at 8:42 AM, BeberGold said:

Good morning,

 

I started using synology 3-4 months ago.

 

After reviewing the logs, I noticed my NAS is under permanent brute force attacks.

 

Initially, I started blocking IPs manually (by adding one by one in the firewall with a 'deny' rule), but then I noticed that IPs kept changing as I blocked them. It does not look like a good use of my time.

 

The synology servicedesk is not very helpful:

- blocking countries is not working: still getting brute force from one of the three countries I allow,

- multi factor authentication: does not work on FTP. FTP transfers are much faster than the web interface.

- Brute force is only conducted on SSH. The service desk advised to disable SSH, but even when I disable SSH the box is still processing SSH login requests! (Bruteforce via SSH continues with SSH disabled.)

 

The next step is to block SSH on the firewall of the NAS.

Any other idea?

A more advanced approach is to use Cloudflare zero trust and apply security measures...

Link to comment
Share on other sites

Apologies for not replying earlier.
The vendor (Synology) does not sound like improving security features will be possible in the near future.

I have had to configure strict firewall rules.

The nonsense has now stopped.

Thank you all for replying.

The situation is now resolved.

Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Restore formatting

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

×
×
  • Create New...