Geekzone: technology news, blogs, forums
Guest
Welcome Guest.
You haven't logged in yet. If you don't have an account you can register now.


stuzz

352 posts

Ultimate Geek
+1 received by user: 24

ID Verified
Trusted

#153622 3-Oct-2014 07:37
Send private message

I have noticed numerous and ongoing attempts by overseas ip addresses to login to my NAS. 
They fail and are blocked after two repeated attempts, but wonder if this is me specific or do others notice this activitiy?



Filter this topic showing only the reply marked as answer Create new topic
johnr
19282 posts

Uber Geek
+1 received by user: 2526
Inactive user


  #1146261 3-Oct-2014 08:19
Send private message

Setup a honey pot and see what they are trying to do



linw
2893 posts

Uber Geek
+1 received by user: 1205


  #1146270 3-Oct-2014 08:30
Send private message

Turned remote access off on my WD Mybooklive because of the shellshock threat.

timmmay
20858 posts

Uber Geek
+1 received by user: 5350

Trusted
Lifetime subscriber

  #1146272 3-Oct-2014 08:34
Send private message

It's expected that every machine on the internet will be probed or attacked more or less constantly. Your options are:
 - Make sure to keep it up to date with the latest software, and use a strong username and password. I would be surprised if there were no vulnerabilities in the software though.
 - Disable remote access.



stuzz

352 posts

Ultimate Geek
+1 received by user: 24

ID Verified
Trusted

  #1146273 3-Oct-2014 08:35
Send private message

linw: Turned remote access off on my WD Mybooklive because of the shellshock threat.


I've done the same with sftp now.

The people I share with can just use Plex. 




stuzz

352 posts

Ultimate Geek
+1 received by user: 24

ID Verified
Trusted

  #1146276 3-Oct-2014 08:42
Send private message

timmmay: It's expected that every machine on the internet will be probed or attacked more or less constantly. Your options are:
 - Make sure to keep it up to date with the latest software, and use a strong username and password. I would be surprised if there were no vulnerabilities in the software though.
 - Disable remote access.


A trusted friend had ftp access to it, but after reading about Shellshock and NAS exploit possibilities, I checked the logs as was surprised what I saw. No one has gained access, but just more aware now. 

chevrolux
4962 posts

Uber Geek
+1 received by user: 2638
Inactive user


  #1146278 3-Oct-2014 08:45
Send private message

Why do you have SSH exposed?!

I can understand SFTP but with that surely SSH isn't required.

 
 
 

Shop now on AliExpress (affiliate link).
stuzz

352 posts

Ultimate Geek
+1 received by user: 24

ID Verified
Trusted

  #1146288 3-Oct-2014 09:14
Send private message

chevrolux: Why do you have SSH exposed?!

I can understand SFTP but with that surely SSH isn't required.


We just turned on the sftp. There was no setting  re ssh other than it advising it used the same port as it would. 

Have turned it off as it is a little beyond me at this stage. 

BTR

BTR
1527 posts

Uber Geek
+1 received by user: 449


  #1146312 3-Oct-2014 09:39
Send private message

I would have as little as possible available externally if I was you, I have all external access to my servers disabled. If I want access I will use VPN.



ubergeeknz
3344 posts

Uber Geek
+1 received by user: 1041

Trusted
Vocus

  #1146335 3-Oct-2014 09:55
Send private message

If you must expose a service externally, use a high port (something over 10000) which should help you avoid the bulk of scanning.  This of course does not obviate the need for strong password/cert authentication, keeping things up to date etc.

muppet
2642 posts

Uber Geek
+1 received by user: 1660

Trusted

  #1146340 3-Oct-2014 09:59
Send private message

This is as normal as normal can get.  If you're on the Internet with a public IP and NOT getting random bots trying to login to every common public service, something's wrong with your Internet connection.




Audiophiles are such twits! They buy such pointless stuff: Gold plated cables, $2000 power cords. Idiots.

 

OOOHHHH HYPERFIBRE!


Filter this topic showing only the reply marked as answer Create new topic








Geekzone Live »

Try automatic live updates from Geekzone directly in your browser, without refreshing the page, with Geekzone Live now.



Are you subscribed to our RSS feed? You can download the latest headlines and summaries from our stories directly to your computer or smartphone by using a feed reader.