Massive Botnet Attacking Synology - how to protect your NAS

97,571
0
Published 2024-05-29
Get 20% off DeleteMe US consumer plans when you go to joindeleteme.com/REX and use promo code REX at checkout. Thanks to DeleteMe for sponsoring this video!

In this video, we are going to be discussing a botnet of devices that have been trying to hack in to Synology NAS's. I will be going over how this works, the threat to your system, and how to protect yourself.

Hire Me! yarboroughtechnologies.com/contact/?utm_source=You…
Post on the Forums! forums.spacerex.co/

Links mentioned:
Video on firewall rules:    • How to Set up Firewall on Synology NA...  
Video on security Setup:    • How to Secure your Synology NAS | 4K ...  

Synology Recommendations*:
Hard drives I recommend: amzn.to/3RA3udS
Starter NAS: amzn.to/46hrRS7
Great all around NAS: amzn.to/46egNVP
More powerful NAS (great for larger/mid sized businesses): amzn.to/3YwRziM

#synology #nas #ransomware

TOC:
00:00 Introduction
00:52 What is a botnet?
02:49 Thanks to DeleteMe for sponsoring this section of the video!
04:10 How the botnet gets into your NAS
07:59 How to protect yourself
08:48 Deactivate admin account
10:00 Auto Block
10:45 Account Protection
13:07 Adaptive MFA
14:11 2-Factor Authentication
15:02 Change Port Number
17:12 Geo-blocking
21:33 Quickconnect
23:12 Conclusion

*These are affiliate links, which means that if you purchase a product through one of them, I will receive a small commission (at no additional cost to you). Thank you for supporting my channel!

All Comments (21)
  • @Vicvines
    Will last September when I got my 923+ I went through your setup videos on security when setting up mine, basically word for word. I paused after you mentioned changing a setting, changed it myself, and then continued on the video. Your help is better than the Synology's official help which is usually the case with a hardware company.
  • @avotius
    Thanks so much for your videos. I recently got a nas after doing some research and your videos convinced me that Synology was the way to go for me because of how comprehensive DSM is. Your setup and security tutorials have been invaluable for me!
  • Something to consider is that all of this really only applies if the attackers can reach your NAS. My advice is to use Tailscale and make it so only devices on the tail net which need access can reach it.
  • @mar4kl
    Good, comprehensive information - thanks. For my NAS clients, I keep remote NAS access disabled, largely for this reason. I only have one client that requires remote access to anything on the NAS, so I have them set up so they have to connect to their office LAN via VPN first, and only then can they access the NAS. This works fine for them largely because they're a small office that doesn't share data directly with anyone else. (And, of course, I keep my NAS clients comprehensively backed up because, well, bad stuff happens...)
  • @NeilBradleyMS
    Thanks for this great video, I've since enabled Account Protection on both my NAS's as the other options I'd already got enabled. I now feel extra confident my data is secure from attack. It was also interesting to learn how the attacks take place with the multiple IP Addresses etc. I don't comment much, but I've been a subscriber back in the day when you had about 25k,subs so it's really really nice to see you channel growing and doing well. All the best - Neil (UK)
  • @nospamevereh
    Used many of these easier methods on two NASs. One fw 7.2 the other fw 6.2. Virtually no issues on 7.2 from the start but tons of attacks on the 6.2 unit. admin and guest were disabled from the start and the autoblock helped me sleep at night but I had logs of multiple RSYNC attacks from the same IP and then cycling to other worldwide IPs with China and Russia topping lists. The addition of firewall and account protection caused the attacks to cease completely for the past 11 days. Looking at swapping out the remote 6.2 unit for a 7 series soon to further bolster security but for now, all looks quiet. Excellent information much of which I had put into practice already but relatively simple to implement and works very well!
  • I'm really glad I found this video. I just watched your maintenance video posted yesterday and through that found out I had a botnet attack on my system 2 months ago. I was a little concerned to say the least. I was also confident my system and data were safe. I long ago put all security measures in place that you recommend along with snap shots to save my ass if they did get through and encrypted stuff. Sometimes I forget that DS920+ is even there chugging away in the closet because it's always just "there" when I need it. Every single time. Thing never fails.
  • Thanks. reminders on good security anre always appreciated. I especially loved the simple firewall suggestions. Adopted. I accidentally typed 196.168 instead of 192.168 and the NAS would not apply the rules because it woul block the computer making the rule change! Quite impressed.
  • @cookie13spike
    You had me worried for a moment! Checked my logs and no drama :) As always great content and I had already done most of the things you suggested from previous tips from you!
  • @Norman_Mitchell
    Brilliant video. You covered a lot of ground with just the right amount of detail. Excellent.
  • @wesc6755
    I'd also point out Synology's Active Insight might be helpful here. That's how I was notified about the ongoing attacks. We got that exact attack from around the beginning of the month. SSH attempts happen fairly often, but this was the first time I saw DSM targetted on that scale. I set aggressive permanent IP blocking, and they all only ever tried the "admin" account. It has been several weeks with no more attempts.
  • @Saintel
    OMG watched this video to learn about the Botnet attack. While watching saw that I had used these same firewall rules mention to block access for countries outside the US. No wonder my apps were not working when I traveled. Thanks for the indirect help! You are man!
  • @agentsmithone
    Excellent tips. I've been on Synology NAS models for 13 years. Very to see I'm doing the right things to security harden.
  • @AaAa-je5eo
    More incredible content, thanks Will. And the SpaceRex team is hurtling towards 100k subscribers, getting very close now! I wonder how AI will affect their attempts at 'brute focing' thing, or really just tactics for approaching what they are trying to do. As with everything AI supercharges, you'd think it would also be of benefit to them too in some way...
  • @blcjck8121
    There's one more thing to consider. Reverse proxy, is a great way to limit your exposure down to just one port. This is great if you have multiple services running. Also if you choose a specific LAN interface to configure, instead of all, you have the option to just switch interfaces should you be unlucky enough to lock yourself out playing with the firewall rules.
  • @napynap
    So timely for me right now. Thank you for this!
  • @DavidM2002
    This made me go through all of the protections that I have set and, I'm happy to say that, other than Account Protection, I had everything setup correctly. ( I also had the geo-block setup on my Synology router.) I hadn't realized that Synology had automatically enabled Adaptive MFA at some point so I was a bit shocked one day when I got the email alert. This has been a great exercise and one that we all need to review periodically. As a slight aside, even though I am mucking about in the Control Panel fairly often, I can easily forget what settings that I've changed, when, and why. So, I have gotten into the habit of keeping an Excel spreadsheet on all of this stuff for all of my devices. A bit anal, yes, but very effective. But it keeps things consistent around my network. It would be so nice if some of these devices would allow the export of all of their settings into something like a CSV file. May thanks again Will.
  • @Pattot818
    Realy helpful appreciate your work, thank!
  • I am still running an old Synology NAS but I am definitely considering upgrading in the next year. That said I really like your channel Will, it's helping be better informed and more aware of what's going on in the NAS space. So I just want to say thanks.