QNAP issues ransomware warning to users: secure your devices or disconnect unprotected NAS

A hot potato: QNAP issued a security statement urging their NAS users to take immediate action and secure their data against ongoing ransomware and brute force attacks. While the responsible parties have not been identified, the widespread attacks appear to target any vulnerable network devices. The company has provided security setting instructions and mitigation actions that any QNAP NAS users should implement immediately.

A security statement released by the storage appliance provider on Friday issued very clear instruction to QNAP NAS users: take immediate action to secure your network appliances or take them offline. The attacks, which appear to indiscriminately target any network device exposed to the Internet, pose the most risk to devices with internet connectivity but little to no protection in place.

QNAP users with the ability to access and secure their devices can verify whether their device is exposed to the internet using the QNAP Security Counselor. According to the company’s statement, the user’s NAS is exposed and at high risk if the Security Counselor console displays a result stating, “The System Administration service can be directly accessible from an external IP address…”

In the event that a user’s NAS is exposed to the Internet, QNAP’s security statement provides instructions to determine which ports are exposed as well as how to disable port forwarding on the user’s router and UPnP on the NAS device.

Port forwarding, also known as port mapping, redirects requests from the original address and port to another address and port. Some users and administrators no longer view port forwarding as a major risk, as software firewalls packaged with most modern operating systems are capable of providing adequate protection when properly configured.

However, QNAP has specifically stated that enabling port forwarding, UPnP, or demilitarized zone (DMZ) functionality can result in the NAS connecting directly to the internet, making the device vulnerable to attack. The recommended preference is for the NAS to remain behind a user’s router and firewall with no public IP address.

NAS users without access to or familiarity with the Security Counselor console still have one last nuclear option–simply disconnect the device, terminating any potential connectivity to the outside world. While it may seem drastic, the fact remains that attackers scanning for vulnerable targets can’t hit what they can’t see.

Image credit: Michael Geiger

Note: This article have been indexed to our site. We do not claim legitimacy, ownership or copyright of any of the content above. To see the article at original source Click Here

Related Posts
Detienen al artista Abel Lescay a la salida del ISA en La Habana thumbnail

Detienen al artista Abel Lescay a la salida del ISA en La Habana

El estudiante de música y activista cubano Abel González Lescay fue arrestado este miércoles a la salida de Instituto Superior de Arte (ISA) cuando se dirigía con unos amigos hacia la playa."Acaba de ser arrestado Abel Lescay a la salida del ISA. Solo caminaba con su guitarra y unos amigos. Nos dirigíamos a la playa. Cuando lo arrestaron…
Read More
Mortgage Rates for April 4, 2023: Rates Fall thumbnail

Mortgage Rates for April 4, 2023: Rates Fall

A variety of key mortgage rates sank over the last seven days. The average interest rates for both 15-year fixed and 30-year fixed mortgages fell, the latter more sharply. At the same time, average rates for 5/1 adjustable-rate mortgages increased very slightly. The Federal Reserve announced a 25-basis point increase to its benchmark short-term interest
Read More
Next Wave: Japan is invested in exporting its resources to Africa thumbnail

Next Wave: Japan is invested in exporting its resources to Africa

1993 and 2024 tell very different histories of Japan’s growing investment in Africa. After the Second World War, in which Japan was both defeated and economically devastated, the Asian country capitalised on a weakening yen to provide cheap goods for both export and consumption. In the years that followed, Japan pioneered the Tokyo International Conference
Read More
Noctua announces thermal paste guard for AMD AM5 processors thumbnail

Noctua announces thermal paste guard for AMD AM5 processors

In a nutshell: Noctua's thermal paste guard mounts around the IHS of AM5 CPUs to prevent thermal paste from accumulating in the small cutouts. This should make it easier to clean the processor when remounting or replacing the CPU cooler. Noctua just unveiled its new thermal paste guard for AMD AM5 processors. The NA-TPG1 is
Read More
Index Of News
Total
0
Share