Skip to content
  • Hjem
  • Seneste
  • Etiketter
  • Populære
  • Verden
  • Bruger
  • Grupper
Temaer
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Kollaps
FARVEL BIG TECH
  1. Forside
  2. Ikke-kategoriseret
  3. IDK what DSM is but I know some of you nerds like hacking Synology stuff.

IDK what DSM is but I know some of you nerds like hacking Synology stuff.

Planlagt Fastgjort Låst Flyttet Ikke-kategoriseret
19 Indlæg 7 Posters 2 Visninger
  • Ældste til nyeste
  • Nyeste til ældste
  • Most Votes
Svar
  • Svar som emne
Login for at svare
Denne tråd er blevet slettet. Kun brugere med emne behandlings privilegier kan se den.
  • cr0w@infosec.exchangeC This user is from outside of this forum
    cr0w@infosec.exchangeC This user is from outside of this forum
    cr0w@infosec.exchange
    wrote sidst redigeret af
    #1

    IDK what DSM is but I know some of you nerds like hacking Synology stuff.

    https://www.synology.com/en-global/security/advisory/Synology_SA_26_13

    hrbrmstr@mastodon.socialH nerdpr0f@infosec.exchangeN christopherkunz@chaos.socialC wdormann@infosec.exchangeW 5 Replies Last reply
    0
    • cr0w@infosec.exchangeC cr0w@infosec.exchange

      IDK what DSM is but I know some of you nerds like hacking Synology stuff.

      https://www.synology.com/en-global/security/advisory/Synology_SA_26_13

      hrbrmstr@mastodon.socialH This user is from outside of this forum
      hrbrmstr@mastodon.socialH This user is from outside of this forum
      hrbrmstr@mastodon.social
      wrote sidst redigeret af
      #2

      @cR0w thought for a second you accidentally left out the B 🙃

      cr0w@infosec.exchangeC 1 Reply Last reply
      0
      • hrbrmstr@mastodon.socialH hrbrmstr@mastodon.social

        @cR0w thought for a second you accidentally left out the B 🙃

        cr0w@infosec.exchangeC This user is from outside of this forum
        cr0w@infosec.exchangeC This user is from outside of this forum
        cr0w@infosec.exchange
        wrote sidst redigeret af
        #3

        @hrbrmstr That's when it gets added to the KEV. 🫦

        1 Reply Last reply
        0
        • cr0w@infosec.exchangeC cr0w@infosec.exchange

          IDK what DSM is but I know some of you nerds like hacking Synology stuff.

          https://www.synology.com/en-global/security/advisory/Synology_SA_26_13

          nerdpr0f@infosec.exchangeN This user is from outside of this forum
          nerdpr0f@infosec.exchangeN This user is from outside of this forum
          nerdpr0f@infosec.exchange
          wrote sidst redigeret af
          #4

          @cR0w Distributed Silliness Module

          1 Reply Last reply
          0
          • cr0w@infosec.exchangeC cr0w@infosec.exchange

            IDK what DSM is but I know some of you nerds like hacking Synology stuff.

            https://www.synology.com/en-global/security/advisory/Synology_SA_26_13

            christopherkunz@chaos.socialC This user is from outside of this forum
            christopherkunz@chaos.socialC This user is from outside of this forum
            christopherkunz@chaos.social
            wrote sidst redigeret af
            #5

            @cR0w Synology's Linux flavor for their NAS boxes. Much GUI, very shell and CGI wrapper, wow!

            1 Reply Last reply
            0
            • cr0w@infosec.exchangeC cr0w@infosec.exchange

              IDK what DSM is but I know some of you nerds like hacking Synology stuff.

              https://www.synology.com/en-global/security/advisory/Synology_SA_26_13

              wdormann@infosec.exchangeW This user is from outside of this forum
              wdormann@infosec.exchangeW This user is from outside of this forum
              wdormann@infosec.exchange
              wrote sidst redigeret af
              #6

              @cR0w
              Synology on September 18:

              Upgrade to 7.4-90075 or above.

              Also Synology on July 24:
              We've released Synology DSM 7.4.1-90080

              cr0w@infosec.exchangeC 1 Reply Last reply
              1
              0
              • cr0w@infosec.exchangeC cr0w@infosec.exchange

                IDK what DSM is but I know some of you nerds like hacking Synology stuff.

                https://www.synology.com/en-global/security/advisory/Synology_SA_26_13

                christopherkunz@chaos.socialC This user is from outside of this forum
                christopherkunz@chaos.socialC This user is from outside of this forum
                christopherkunz@chaos.social
                wrote sidst redigeret af
                #7

                @cR0w What. *squints* The first one allows _unauthenticated_ attackers to read arbitrary files on a NAS?
                I errmm... have questions.

                cr0w@infosec.exchangeC fuzzyfuzzyfungus@cyberplace.socialF 2 Replies Last reply
                0
                • wdormann@infosec.exchangeW wdormann@infosec.exchange

                  @cR0w
                  Synology on September 18:

                  Upgrade to 7.4-90075 or above.

                  Also Synology on July 24:
                  We've released Synology DSM 7.4.1-90080

                  cr0w@infosec.exchangeC This user is from outside of this forum
                  cr0w@infosec.exchangeC This user is from outside of this forum
                  cr0w@infosec.exchange
                  wrote sidst redigeret af
                  #8

                  @wdormann

                  checks date on calendar

                  checks again

                  sigh

                  wdormann@infosec.exchangeW 1 Reply Last reply
                  0
                  • christopherkunz@chaos.socialC christopherkunz@chaos.social

                    @cR0w What. *squints* The first one allows _unauthenticated_ attackers to read arbitrary files on a NAS?
                    I errmm... have questions.

                    cr0w@infosec.exchangeC This user is from outside of this forum
                    cr0w@infosec.exchangeC This user is from outside of this forum
                    cr0w@infosec.exchange
                    wrote sidst redigeret af
                    #9

                    @christopherkunz The S in NAS stands for security.

                    Wait, there is an S in NAS. Dammit. Well, it certainly doesn't stand for security.

                    huronbikes@cyberplace.socialH christopherkunz@chaos.socialC 2 Replies Last reply
                    0
                    • cr0w@infosec.exchangeC cr0w@infosec.exchange

                      @christopherkunz The S in NAS stands for security.

                      Wait, there is an S in NAS. Dammit. Well, it certainly doesn't stand for security.

                      huronbikes@cyberplace.socialH This user is from outside of this forum
                      huronbikes@cyberplace.socialH This user is from outside of this forum
                      huronbikes@cyberplace.social
                      wrote sidst redigeret af
                      #10

                      @cR0w @christopherkunz "it's not like anyone will attach this storage to a network."

                      1 Reply Last reply
                      0
                      • christopherkunz@chaos.socialC christopherkunz@chaos.social

                        @cR0w What. *squints* The first one allows _unauthenticated_ attackers to read arbitrary files on a NAS?
                        I errmm... have questions.

                        fuzzyfuzzyfungus@cyberplace.socialF This user is from outside of this forum
                        fuzzyfuzzyfungus@cyberplace.socialF This user is from outside of this forum
                        fuzzyfuzzyfungus@cyberplace.social
                        wrote sidst redigeret af
                        #11

                        @christopherkunz @cR0w Unauth reads mean that you get 200% credit for 'availability' and can construct the 'AIA triad'.

                        And if there are any unauth writes it's 300% credit, you construct the 'AAA' triad and shiftily try to blame DNS. Doesn't work in IPv6 only environments; but what are the odds?

                        cr0w@infosec.exchangeC 1 Reply Last reply
                        0
                        • fuzzyfuzzyfungus@cyberplace.socialF fuzzyfuzzyfungus@cyberplace.social

                          @christopherkunz @cR0w Unauth reads mean that you get 200% credit for 'availability' and can construct the 'AIA triad'.

                          And if there are any unauth writes it's 300% credit, you construct the 'AAA' triad and shiftily try to blame DNS. Doesn't work in IPv6 only environments; but what are the odds?

                          cr0w@infosec.exchangeC This user is from outside of this forum
                          cr0w@infosec.exchangeC This user is from outside of this forum
                          cr0w@infosec.exchange
                          wrote sidst redigeret af
                          #12

                          @fuzzyfuzzyfungus @christopherkunz I believe you mean "AITA" since you're talking about Synology.

                          fuzzyfuzzyfungus@cyberplace.socialF 1 Reply Last reply
                          0
                          • cr0w@infosec.exchangeC cr0w@infosec.exchange

                            @christopherkunz The S in NAS stands for security.

                            Wait, there is an S in NAS. Dammit. Well, it certainly doesn't stand for security.

                            christopherkunz@chaos.socialC This user is from outside of this forum
                            christopherkunz@chaos.socialC This user is from outside of this forum
                            christopherkunz@chaos.social
                            wrote sidst redigeret af
                            #13

                            @cR0w The "H" in Synology stands for "Hardened".

                            1 Reply Last reply
                            0
                            • cr0w@infosec.exchangeC cr0w@infosec.exchange

                              @wdormann

                              checks date on calendar

                              checks again

                              sigh

                              wdormann@infosec.exchangeW This user is from outside of this forum
                              wdormann@infosec.exchangeW This user is from outside of this forum
                              wdormann@infosec.exchange
                              wrote sidst redigeret af
                              #14

                              @cR0w
                              I can only assume that this is a case of "roll out the update and wait long enough for the masses to install it before telling anyone about the vulnerabilities it fixes" ? 🤷‍♂️

                              cr0w@infosec.exchangeC 1 Reply Last reply
                              0
                              • wdormann@infosec.exchangeW wdormann@infosec.exchange

                                @cR0w
                                I can only assume that this is a case of "roll out the update and wait long enough for the masses to install it before telling anyone about the vulnerabilities it fixes" ? 🤷‍♂️

                                cr0w@infosec.exchangeC This user is from outside of this forum
                                cr0w@infosec.exchangeC This user is from outside of this forum
                                cr0w@infosec.exchange
                                wrote sidst redigeret af
                                #15

                                @wdormann I'm glad that's not as common as it used to be but it still frustrates me when vendors do that.

                                1 Reply Last reply
                                0
                                • cr0w@infosec.exchangeC cr0w@infosec.exchange

                                  @fuzzyfuzzyfungus @christopherkunz I believe you mean "AITA" since you're talking about Synology.

                                  fuzzyfuzzyfungus@cyberplace.socialF This user is from outside of this forum
                                  fuzzyfuzzyfungus@cyberplace.socialF This user is from outside of this forum
                                  fuzzyfuzzyfungus@cyberplace.social
                                  wrote sidst redigeret af
                                  #16

                                  @cR0w @christopherkunz Once they started with the drive-locking nonsense that was no longer a question.

                                  Yeah guys, sell dodgy SMB toys; try to play enterprise SAN pricing games. Hell no.

                                  cr0w@infosec.exchangeC 1 Reply Last reply
                                  0
                                  • fuzzyfuzzyfungus@cyberplace.socialF fuzzyfuzzyfungus@cyberplace.social

                                    @cR0w @christopherkunz Once they started with the drive-locking nonsense that was no longer a question.

                                    Yeah guys, sell dodgy SMB toys; try to play enterprise SAN pricing games. Hell no.

                                    cr0w@infosec.exchangeC This user is from outside of this forum
                                    cr0w@infosec.exchangeC This user is from outside of this forum
                                    cr0w@infosec.exchange
                                    wrote sidst redigeret af
                                    #17

                                    @fuzzyfuzzyfungus @christopherkunz I don't know much about them but I hear people talk about using them all the time and I occasionally find a random one on a network for what I am sure is totally legit purposes.

                                    christopherkunz@chaos.socialC 1 Reply Last reply
                                    0
                                    • cr0w@infosec.exchangeC cr0w@infosec.exchange

                                      @fuzzyfuzzyfungus @christopherkunz I don't know much about them but I hear people talk about using them all the time and I occasionally find a random one on a network for what I am sure is totally legit purposes.

                                      christopherkunz@chaos.socialC This user is from outside of this forum
                                      christopherkunz@chaos.socialC This user is from outside of this forum
                                      christopherkunz@chaos.social
                                      wrote sidst redigeret af
                                      #18

                                      @cR0w @fuzzyfuzzyfungus This whole toot could be about a NAS or a Cobalt Strike beacon.

                                      cr0w@infosec.exchangeC 1 Reply Last reply
                                      0
                                      • christopherkunz@chaos.socialC christopherkunz@chaos.social

                                        @cR0w @fuzzyfuzzyfungus This whole toot could be about a NAS or a Cobalt Strike beacon.

                                        cr0w@infosec.exchangeC This user is from outside of this forum
                                        cr0w@infosec.exchangeC This user is from outside of this forum
                                        cr0w@infosec.exchange
                                        wrote sidst redigeret af
                                        #19

                                        @christopherkunz @fuzzyfuzzyfungus OMG you're right.

                                        1 Reply Last reply
                                        0
                                        • kramse@helvede.netK kramse@helvede.net shared this topic
                                        Svar
                                        • Svar som emne
                                        Login for at svare
                                        • Ældste til nyeste
                                        • Nyeste til ældste
                                        • Most Votes


                                        • Log ind

                                        • Login or register to search.
                                        Powered by NodeBB Contributors
                                        Graciously hosted by data.coop
                                        • First post
                                          Last post
                                        0
                                        • Hjem
                                        • Seneste
                                        • Etiketter
                                        • Populære
                                        • Verden
                                        • Bruger
                                        • Grupper