Skip to content
  • Hjem
  • Seneste
  • Etiketter
  • Populære
  • Verden
  • Bruger
  • Grupper
Temaer
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Kollaps
FARVEL BIG TECH
  1. Forside
  2. Ikke-kategoriseret
  3. IDK what DSM is but I know some of you nerds like hacking Synology stuff.

IDK what DSM is but I know some of you nerds like hacking Synology stuff.

Planlagt Fastgjort Låst Flyttet Ikke-kategoriseret
19 Indlæg 7 Posters 2 Visninger
  • Ældste til nyeste
  • Nyeste til ældste
  • Most Votes
Svar
  • Svar som emne
Login for at svare
Denne tråd er blevet slettet. Kun brugere med emne behandlings privilegier kan se den.
  • cr0w@infosec.exchangeC cr0w@infosec.exchange

    IDK what DSM is but I know some of you nerds like hacking Synology stuff.

    https://www.synology.com/en-global/security/advisory/Synology_SA_26_13

    christopherkunz@chaos.socialC This user is from outside of this forum
    christopherkunz@chaos.socialC This user is from outside of this forum
    christopherkunz@chaos.social
    wrote sidst redigeret af
    #5

    @cR0w Synology's Linux flavor for their NAS boxes. Much GUI, very shell and CGI wrapper, wow!

    1 Reply Last reply
    0
    • cr0w@infosec.exchangeC cr0w@infosec.exchange

      IDK what DSM is but I know some of you nerds like hacking Synology stuff.

      https://www.synology.com/en-global/security/advisory/Synology_SA_26_13

      wdormann@infosec.exchangeW This user is from outside of this forum
      wdormann@infosec.exchangeW This user is from outside of this forum
      wdormann@infosec.exchange
      wrote sidst redigeret af
      #6

      @cR0w
      Synology on September 18:

      Upgrade to 7.4-90075 or above.

      Also Synology on July 24:
      We've released Synology DSM 7.4.1-90080

      cr0w@infosec.exchangeC 1 Reply Last reply
      1
      0
      • cr0w@infosec.exchangeC cr0w@infosec.exchange

        IDK what DSM is but I know some of you nerds like hacking Synology stuff.

        https://www.synology.com/en-global/security/advisory/Synology_SA_26_13

        christopherkunz@chaos.socialC This user is from outside of this forum
        christopherkunz@chaos.socialC This user is from outside of this forum
        christopherkunz@chaos.social
        wrote sidst redigeret af
        #7

        @cR0w What. *squints* The first one allows _unauthenticated_ attackers to read arbitrary files on a NAS?
        I errmm... have questions.

        cr0w@infosec.exchangeC fuzzyfuzzyfungus@cyberplace.socialF 2 Replies Last reply
        0
        • wdormann@infosec.exchangeW wdormann@infosec.exchange

          @cR0w
          Synology on September 18:

          Upgrade to 7.4-90075 or above.

          Also Synology on July 24:
          We've released Synology DSM 7.4.1-90080

          cr0w@infosec.exchangeC This user is from outside of this forum
          cr0w@infosec.exchangeC This user is from outside of this forum
          cr0w@infosec.exchange
          wrote sidst redigeret af
          #8

          @wdormann

          checks date on calendar

          checks again

          sigh

          wdormann@infosec.exchangeW 1 Reply Last reply
          0
          • christopherkunz@chaos.socialC christopherkunz@chaos.social

            @cR0w What. *squints* The first one allows _unauthenticated_ attackers to read arbitrary files on a NAS?
            I errmm... have questions.

            cr0w@infosec.exchangeC This user is from outside of this forum
            cr0w@infosec.exchangeC This user is from outside of this forum
            cr0w@infosec.exchange
            wrote sidst redigeret af
            #9

            @christopherkunz The S in NAS stands for security.

            Wait, there is an S in NAS. Dammit. Well, it certainly doesn't stand for security.

            huronbikes@cyberplace.socialH christopherkunz@chaos.socialC 2 Replies Last reply
            0
            • cr0w@infosec.exchangeC cr0w@infosec.exchange

              @christopherkunz The S in NAS stands for security.

              Wait, there is an S in NAS. Dammit. Well, it certainly doesn't stand for security.

              huronbikes@cyberplace.socialH This user is from outside of this forum
              huronbikes@cyberplace.socialH This user is from outside of this forum
              huronbikes@cyberplace.social
              wrote sidst redigeret af
              #10

              @cR0w @christopherkunz "it's not like anyone will attach this storage to a network."

              1 Reply Last reply
              0
              • christopherkunz@chaos.socialC christopherkunz@chaos.social

                @cR0w What. *squints* The first one allows _unauthenticated_ attackers to read arbitrary files on a NAS?
                I errmm... have questions.

                fuzzyfuzzyfungus@cyberplace.socialF This user is from outside of this forum
                fuzzyfuzzyfungus@cyberplace.socialF This user is from outside of this forum
                fuzzyfuzzyfungus@cyberplace.social
                wrote sidst redigeret af
                #11

                @christopherkunz @cR0w Unauth reads mean that you get 200% credit for 'availability' and can construct the 'AIA triad'.

                And if there are any unauth writes it's 300% credit, you construct the 'AAA' triad and shiftily try to blame DNS. Doesn't work in IPv6 only environments; but what are the odds?

                cr0w@infosec.exchangeC 1 Reply Last reply
                0
                • fuzzyfuzzyfungus@cyberplace.socialF fuzzyfuzzyfungus@cyberplace.social

                  @christopherkunz @cR0w Unauth reads mean that you get 200% credit for 'availability' and can construct the 'AIA triad'.

                  And if there are any unauth writes it's 300% credit, you construct the 'AAA' triad and shiftily try to blame DNS. Doesn't work in IPv6 only environments; but what are the odds?

                  cr0w@infosec.exchangeC This user is from outside of this forum
                  cr0w@infosec.exchangeC This user is from outside of this forum
                  cr0w@infosec.exchange
                  wrote sidst redigeret af
                  #12

                  @fuzzyfuzzyfungus @christopherkunz I believe you mean "AITA" since you're talking about Synology.

                  fuzzyfuzzyfungus@cyberplace.socialF 1 Reply Last reply
                  0
                  • cr0w@infosec.exchangeC cr0w@infosec.exchange

                    @christopherkunz The S in NAS stands for security.

                    Wait, there is an S in NAS. Dammit. Well, it certainly doesn't stand for security.

                    christopherkunz@chaos.socialC This user is from outside of this forum
                    christopherkunz@chaos.socialC This user is from outside of this forum
                    christopherkunz@chaos.social
                    wrote sidst redigeret af
                    #13

                    @cR0w The "H" in Synology stands for "Hardened".

                    1 Reply Last reply
                    0
                    • cr0w@infosec.exchangeC cr0w@infosec.exchange

                      @wdormann

                      checks date on calendar

                      checks again

                      sigh

                      wdormann@infosec.exchangeW This user is from outside of this forum
                      wdormann@infosec.exchangeW This user is from outside of this forum
                      wdormann@infosec.exchange
                      wrote sidst redigeret af
                      #14

                      @cR0w
                      I can only assume that this is a case of "roll out the update and wait long enough for the masses to install it before telling anyone about the vulnerabilities it fixes" ? 🤷‍♂️

                      cr0w@infosec.exchangeC 1 Reply Last reply
                      0
                      • wdormann@infosec.exchangeW wdormann@infosec.exchange

                        @cR0w
                        I can only assume that this is a case of "roll out the update and wait long enough for the masses to install it before telling anyone about the vulnerabilities it fixes" ? 🤷‍♂️

                        cr0w@infosec.exchangeC This user is from outside of this forum
                        cr0w@infosec.exchangeC This user is from outside of this forum
                        cr0w@infosec.exchange
                        wrote sidst redigeret af
                        #15

                        @wdormann I'm glad that's not as common as it used to be but it still frustrates me when vendors do that.

                        1 Reply Last reply
                        0
                        • cr0w@infosec.exchangeC cr0w@infosec.exchange

                          @fuzzyfuzzyfungus @christopherkunz I believe you mean "AITA" since you're talking about Synology.

                          fuzzyfuzzyfungus@cyberplace.socialF This user is from outside of this forum
                          fuzzyfuzzyfungus@cyberplace.socialF This user is from outside of this forum
                          fuzzyfuzzyfungus@cyberplace.social
                          wrote sidst redigeret af
                          #16

                          @cR0w @christopherkunz Once they started with the drive-locking nonsense that was no longer a question.

                          Yeah guys, sell dodgy SMB toys; try to play enterprise SAN pricing games. Hell no.

                          cr0w@infosec.exchangeC 1 Reply Last reply
                          0
                          • fuzzyfuzzyfungus@cyberplace.socialF fuzzyfuzzyfungus@cyberplace.social

                            @cR0w @christopherkunz Once they started with the drive-locking nonsense that was no longer a question.

                            Yeah guys, sell dodgy SMB toys; try to play enterprise SAN pricing games. Hell no.

                            cr0w@infosec.exchangeC This user is from outside of this forum
                            cr0w@infosec.exchangeC This user is from outside of this forum
                            cr0w@infosec.exchange
                            wrote sidst redigeret af
                            #17

                            @fuzzyfuzzyfungus @christopherkunz I don't know much about them but I hear people talk about using them all the time and I occasionally find a random one on a network for what I am sure is totally legit purposes.

                            christopherkunz@chaos.socialC 1 Reply Last reply
                            0
                            • cr0w@infosec.exchangeC cr0w@infosec.exchange

                              @fuzzyfuzzyfungus @christopherkunz I don't know much about them but I hear people talk about using them all the time and I occasionally find a random one on a network for what I am sure is totally legit purposes.

                              christopherkunz@chaos.socialC This user is from outside of this forum
                              christopherkunz@chaos.socialC This user is from outside of this forum
                              christopherkunz@chaos.social
                              wrote sidst redigeret af
                              #18

                              @cR0w @fuzzyfuzzyfungus This whole toot could be about a NAS or a Cobalt Strike beacon.

                              cr0w@infosec.exchangeC 1 Reply Last reply
                              0
                              • christopherkunz@chaos.socialC christopherkunz@chaos.social

                                @cR0w @fuzzyfuzzyfungus This whole toot could be about a NAS or a Cobalt Strike beacon.

                                cr0w@infosec.exchangeC This user is from outside of this forum
                                cr0w@infosec.exchangeC This user is from outside of this forum
                                cr0w@infosec.exchange
                                wrote sidst redigeret af
                                #19

                                @christopherkunz @fuzzyfuzzyfungus OMG you're right.

                                1 Reply Last reply
                                0
                                • kramse@helvede.netK kramse@helvede.net shared this topic
                                Svar
                                • Svar som emne
                                Login for at svare
                                • Ældste til nyeste
                                • Nyeste til ældste
                                • Most Votes


                                • Log ind

                                • Login or register to search.
                                Powered by NodeBB Contributors
                                Graciously hosted by data.coop
                                • First post
                                  Last post
                                0
                                • Hjem
                                • Seneste
                                • Etiketter
                                • Populære
                                • Verden
                                • Bruger
                                • Grupper