Skip to content
  • Hjem
  • Seneste
  • Etiketter
  • Populære
  • Verden
  • Bruger
  • Grupper
Temaer
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Kollaps
FARVEL BIG TECH
  1. Forside
  2. Ikke-kategoriseret
  3. IDK what DSM is but I know some of you nerds like hacking Synology stuff.

IDK what DSM is but I know some of you nerds like hacking Synology stuff.

Planlagt Fastgjort Låst Flyttet Ikke-kategoriseret
19 Indlæg 7 Posters 2 Visninger
  • Ældste til nyeste
  • Nyeste til ældste
  • Most Votes
Svar
  • Svar som emne
Login for at svare
Denne tråd er blevet slettet. Kun brugere med emne behandlings privilegier kan se den.
  • cr0w@infosec.exchangeC cr0w@infosec.exchange

    IDK what DSM is but I know some of you nerds like hacking Synology stuff.

    https://www.synology.com/en-global/security/advisory/Synology_SA_26_13

    nerdpr0f@infosec.exchangeN This user is from outside of this forum
    nerdpr0f@infosec.exchangeN This user is from outside of this forum
    nerdpr0f@infosec.exchange
    wrote sidst redigeret af
    #4

    @cR0w Distributed Silliness Module

    1 Reply Last reply
    0
    • cr0w@infosec.exchangeC cr0w@infosec.exchange

      IDK what DSM is but I know some of you nerds like hacking Synology stuff.

      https://www.synology.com/en-global/security/advisory/Synology_SA_26_13

      christopherkunz@chaos.socialC This user is from outside of this forum
      christopherkunz@chaos.socialC This user is from outside of this forum
      christopherkunz@chaos.social
      wrote sidst redigeret af
      #5

      @cR0w Synology's Linux flavor for their NAS boxes. Much GUI, very shell and CGI wrapper, wow!

      1 Reply Last reply
      0
      • cr0w@infosec.exchangeC cr0w@infosec.exchange

        IDK what DSM is but I know some of you nerds like hacking Synology stuff.

        https://www.synology.com/en-global/security/advisory/Synology_SA_26_13

        wdormann@infosec.exchangeW This user is from outside of this forum
        wdormann@infosec.exchangeW This user is from outside of this forum
        wdormann@infosec.exchange
        wrote sidst redigeret af
        #6

        @cR0w
        Synology on September 18:

        Upgrade to 7.4-90075 or above.

        Also Synology on July 24:
        We've released Synology DSM 7.4.1-90080

        cr0w@infosec.exchangeC 1 Reply Last reply
        1
        0
        • cr0w@infosec.exchangeC cr0w@infosec.exchange

          IDK what DSM is but I know some of you nerds like hacking Synology stuff.

          https://www.synology.com/en-global/security/advisory/Synology_SA_26_13

          christopherkunz@chaos.socialC This user is from outside of this forum
          christopherkunz@chaos.socialC This user is from outside of this forum
          christopherkunz@chaos.social
          wrote sidst redigeret af
          #7

          @cR0w What. *squints* The first one allows _unauthenticated_ attackers to read arbitrary files on a NAS?
          I errmm... have questions.

          cr0w@infosec.exchangeC fuzzyfuzzyfungus@cyberplace.socialF 2 Replies Last reply
          0
          • wdormann@infosec.exchangeW wdormann@infosec.exchange

            @cR0w
            Synology on September 18:

            Upgrade to 7.4-90075 or above.

            Also Synology on July 24:
            We've released Synology DSM 7.4.1-90080

            cr0w@infosec.exchangeC This user is from outside of this forum
            cr0w@infosec.exchangeC This user is from outside of this forum
            cr0w@infosec.exchange
            wrote sidst redigeret af
            #8

            @wdormann

            checks date on calendar

            checks again

            sigh

            wdormann@infosec.exchangeW 1 Reply Last reply
            0
            • christopherkunz@chaos.socialC christopherkunz@chaos.social

              @cR0w What. *squints* The first one allows _unauthenticated_ attackers to read arbitrary files on a NAS?
              I errmm... have questions.

              cr0w@infosec.exchangeC This user is from outside of this forum
              cr0w@infosec.exchangeC This user is from outside of this forum
              cr0w@infosec.exchange
              wrote sidst redigeret af
              #9

              @christopherkunz The S in NAS stands for security.

              Wait, there is an S in NAS. Dammit. Well, it certainly doesn't stand for security.

              huronbikes@cyberplace.socialH christopherkunz@chaos.socialC 2 Replies Last reply
              0
              • cr0w@infosec.exchangeC cr0w@infosec.exchange

                @christopherkunz The S in NAS stands for security.

                Wait, there is an S in NAS. Dammit. Well, it certainly doesn't stand for security.

                huronbikes@cyberplace.socialH This user is from outside of this forum
                huronbikes@cyberplace.socialH This user is from outside of this forum
                huronbikes@cyberplace.social
                wrote sidst redigeret af
                #10

                @cR0w @christopherkunz "it's not like anyone will attach this storage to a network."

                1 Reply Last reply
                0
                • christopherkunz@chaos.socialC christopherkunz@chaos.social

                  @cR0w What. *squints* The first one allows _unauthenticated_ attackers to read arbitrary files on a NAS?
                  I errmm... have questions.

                  fuzzyfuzzyfungus@cyberplace.socialF This user is from outside of this forum
                  fuzzyfuzzyfungus@cyberplace.socialF This user is from outside of this forum
                  fuzzyfuzzyfungus@cyberplace.social
                  wrote sidst redigeret af
                  #11

                  @christopherkunz @cR0w Unauth reads mean that you get 200% credit for 'availability' and can construct the 'AIA triad'.

                  And if there are any unauth writes it's 300% credit, you construct the 'AAA' triad and shiftily try to blame DNS. Doesn't work in IPv6 only environments; but what are the odds?

                  cr0w@infosec.exchangeC 1 Reply Last reply
                  0
                  • fuzzyfuzzyfungus@cyberplace.socialF fuzzyfuzzyfungus@cyberplace.social

                    @christopherkunz @cR0w Unauth reads mean that you get 200% credit for 'availability' and can construct the 'AIA triad'.

                    And if there are any unauth writes it's 300% credit, you construct the 'AAA' triad and shiftily try to blame DNS. Doesn't work in IPv6 only environments; but what are the odds?

                    cr0w@infosec.exchangeC This user is from outside of this forum
                    cr0w@infosec.exchangeC This user is from outside of this forum
                    cr0w@infosec.exchange
                    wrote sidst redigeret af
                    #12

                    @fuzzyfuzzyfungus @christopherkunz I believe you mean "AITA" since you're talking about Synology.

                    fuzzyfuzzyfungus@cyberplace.socialF 1 Reply Last reply
                    0
                    • cr0w@infosec.exchangeC cr0w@infosec.exchange

                      @christopherkunz The S in NAS stands for security.

                      Wait, there is an S in NAS. Dammit. Well, it certainly doesn't stand for security.

                      christopherkunz@chaos.socialC This user is from outside of this forum
                      christopherkunz@chaos.socialC This user is from outside of this forum
                      christopherkunz@chaos.social
                      wrote sidst redigeret af
                      #13

                      @cR0w The "H" in Synology stands for "Hardened".

                      1 Reply Last reply
                      0
                      • cr0w@infosec.exchangeC cr0w@infosec.exchange

                        @wdormann

                        checks date on calendar

                        checks again

                        sigh

                        wdormann@infosec.exchangeW This user is from outside of this forum
                        wdormann@infosec.exchangeW This user is from outside of this forum
                        wdormann@infosec.exchange
                        wrote sidst redigeret af
                        #14

                        @cR0w
                        I can only assume that this is a case of "roll out the update and wait long enough for the masses to install it before telling anyone about the vulnerabilities it fixes" ? 🤷‍♂️

                        cr0w@infosec.exchangeC 1 Reply Last reply
                        0
                        • wdormann@infosec.exchangeW wdormann@infosec.exchange

                          @cR0w
                          I can only assume that this is a case of "roll out the update and wait long enough for the masses to install it before telling anyone about the vulnerabilities it fixes" ? 🤷‍♂️

                          cr0w@infosec.exchangeC This user is from outside of this forum
                          cr0w@infosec.exchangeC This user is from outside of this forum
                          cr0w@infosec.exchange
                          wrote sidst redigeret af
                          #15

                          @wdormann I'm glad that's not as common as it used to be but it still frustrates me when vendors do that.

                          1 Reply Last reply
                          0
                          • cr0w@infosec.exchangeC cr0w@infosec.exchange

                            @fuzzyfuzzyfungus @christopherkunz I believe you mean "AITA" since you're talking about Synology.

                            fuzzyfuzzyfungus@cyberplace.socialF This user is from outside of this forum
                            fuzzyfuzzyfungus@cyberplace.socialF This user is from outside of this forum
                            fuzzyfuzzyfungus@cyberplace.social
                            wrote sidst redigeret af
                            #16

                            @cR0w @christopherkunz Once they started with the drive-locking nonsense that was no longer a question.

                            Yeah guys, sell dodgy SMB toys; try to play enterprise SAN pricing games. Hell no.

                            cr0w@infosec.exchangeC 1 Reply Last reply
                            0
                            • fuzzyfuzzyfungus@cyberplace.socialF fuzzyfuzzyfungus@cyberplace.social

                              @cR0w @christopherkunz Once they started with the drive-locking nonsense that was no longer a question.

                              Yeah guys, sell dodgy SMB toys; try to play enterprise SAN pricing games. Hell no.

                              cr0w@infosec.exchangeC This user is from outside of this forum
                              cr0w@infosec.exchangeC This user is from outside of this forum
                              cr0w@infosec.exchange
                              wrote sidst redigeret af
                              #17

                              @fuzzyfuzzyfungus @christopherkunz I don't know much about them but I hear people talk about using them all the time and I occasionally find a random one on a network for what I am sure is totally legit purposes.

                              christopherkunz@chaos.socialC 1 Reply Last reply
                              0
                              • cr0w@infosec.exchangeC cr0w@infosec.exchange

                                @fuzzyfuzzyfungus @christopherkunz I don't know much about them but I hear people talk about using them all the time and I occasionally find a random one on a network for what I am sure is totally legit purposes.

                                christopherkunz@chaos.socialC This user is from outside of this forum
                                christopherkunz@chaos.socialC This user is from outside of this forum
                                christopherkunz@chaos.social
                                wrote sidst redigeret af
                                #18

                                @cR0w @fuzzyfuzzyfungus This whole toot could be about a NAS or a Cobalt Strike beacon.

                                cr0w@infosec.exchangeC 1 Reply Last reply
                                0
                                • christopherkunz@chaos.socialC christopherkunz@chaos.social

                                  @cR0w @fuzzyfuzzyfungus This whole toot could be about a NAS or a Cobalt Strike beacon.

                                  cr0w@infosec.exchangeC This user is from outside of this forum
                                  cr0w@infosec.exchangeC This user is from outside of this forum
                                  cr0w@infosec.exchange
                                  wrote sidst redigeret af
                                  #19

                                  @christopherkunz @fuzzyfuzzyfungus OMG you're right.

                                  1 Reply Last reply
                                  0
                                  • kramse@helvede.netK kramse@helvede.net shared this topic
                                  Svar
                                  • Svar som emne
                                  Login for at svare
                                  • Ældste til nyeste
                                  • Nyeste til ældste
                                  • Most Votes


                                  • Log ind

                                  • Login or register to search.
                                  Powered by NodeBB Contributors
                                  Graciously hosted by data.coop
                                  • First post
                                    Last post
                                  0
                                  • Hjem
                                  • Seneste
                                  • Etiketter
                                  • Populære
                                  • Verden
                                  • Bruger
                                  • Grupper