Difference between revisions of "Synology"

From wiki
Jump to navigation Jump to search
Line 31: Line 31:
 
.exit
 
.exit
 
</syntaxhighlight>
 
</syntaxhighlight>
 +
On DSM 6 the record looks like "IP|RecordTime|ExpireTime|Deny|IPStd|Type|Meta"

Revision as of 15:16, 25 August 2018

Hardening

The certificates are stored in /usr/syno/etc/certificate/_archive. The INFO file defines what applications the certificates are used for. The certificates are in subdirectories with a yet unknown naming convention.


This page has some good hardening tips.

Some of the things I did:

  • 2 factor authentication on the web interface
  • Moved ssh to a high port on my router (NAT xxxx -> synology:22) (and disabled from the internet when not needed)
  • Disable HTTP access
  • Installed another webserver as frontend as I doubt synology publishes all security updates in time.
  • Set home directory protection from 755 to 700
  • Disabled admin account


Autoblock

The autoblock feature blocks access from IPaddreses from which too many failed login attempt are done. If the GUI is not available the blocked IPs can be managed from sqllite3

sqlite3 /etc/synoautoblock.db
.header on
select * from AutoBlockIP;
sqlite> select * from AutoBlockIP;

IP|RecordTime|ExpireTime|Deny|IPStd
<ip>|<epoch>|<0=never>|<[01]>|<IPv6>

sqlite> delete from AutoBlockIP where IP = “xxx.xxx.xxx.xxx”;
.exit

On DSM 6 the record looks like "IP|RecordTime|ExpireTime|Deny|IPStd|Type|Meta"