Massive malware attack on QNAP

Tony if you have backups I would not pay, if you don’t then it’s not a hard decision as memories are hard to replicate.
Many of these hacking groups have a decent reputation for good service (sounds bizarre to even write it).

1 Like

Sad to say that I didn’t backup my NAS… cause I think the NAS was used to do backup … so iconic…
And the hack group with decent reputation… more iconic… :sweat:

Anyway I will try to get the files back and do backup of backups… :sob:

To be clear - his is backup, but not archivization.

No, it’s not backup by any accepted definition. As anyone who did not have backups in this situation will attest.

It is NOT backup - RAID is availability… (ironically - once it’s hacked, it’s not…)

1 Like

Backup is not the same as data archiving.
Every backup ought to be periodically achieved - even into two different physical places!

Not mine, the accepted definition.

In information technology, a backup, or data backup is a copy of computer data taken and stored elsewhere so that it may be used to restore the original after a data loss event.
Backups can be used to recover data after its loss from data deletion or corruption, or to recover data from an earlier time.
Backup - Wikipedia

My emphasis. Both these are not satisfied by RAID. R stands for redundant, not Backup.

But we understand that backup does not protect against data loss …

Nobody was suggesting otherwise.

Also, please don’t materially edit your post so that my answer to it doesn’t quite make sense.

“You’ve replied 3 times to @anon55914447 in this particular topic”

“Big Brother” is watching

I think I finally understand …
I thought you meant that external RAID dump is not a backup.

So why announce that local RAID is not backup - it’s obvious.

1 Like

Lonek obvious to some of us, but a lot of people consider that they don’t need backup if they have RAID.
It’s a costly learning experience for some as they never expect to get hit with something like that on their own network.

I am sure you have multiple backup solutions in different places, but most people do not have this in place.

Yes it’s simultaneously mad while making perfect sense. They see themselves as operating a ‘business’. If they don’t make good on their promise to provide the passwords then word gets around and nobody pays. Crackers!

I know it’s another chunk of money, but a worthy backup solution if you have NAS storage greater than 15TB or so. QNAP has a DAS unit (direct attached storage) for $219 plus cost of the drives you install: https://store.qnap.com/catalog/product/view/id/1023. Fast, single USB connection to the NAS. Four bays for up to 64TB of backup, though that would be hugely expensive with four 16TB drives. I started with two 14TB to cover my 28TB NAS (which is 2/3’s full). I’ll add more drives when needed.

1 Like

Yes exactly, difficult to put the two thing’s together, and hopefully offering at least a bit of comfort to the many QNAP customers who would otherwise have lost everything.

It’s still annoying as hell, but companies like QNAP need to get their ■■■■ together and make their systems more secure. Default’s should be secure and serious warnings should be given when you change these settings.

Should be but QNAP have been driven by their marketing department for too long. Not sure the leopard will change its spots even after this.

I’ve owned one for 6 years but they test your patience. I’d think long and hard before buying another. What’s worse is you want to patch early, but they have such shonky firmware releases you need to wait a good couple of weeks to check for dumpster fires on the forums from people who installed the latest and bricked their systems!

3 Likes

That’s a drag. I use that app. Hopefully the have updated it with a fix. I’ll have to check on that.

…pause…

Yes! Improper Authorization Vulnerability in HBS 3 Hybrid Backup Sync - Security Advisory | QNAP (US)

Meanwhile, following the security advice above along with disabling the default admin account: What to do if there are constant unauthorized attempts to access the NAS using the “admin” user? | QNAP (US).

1 Like

Pete is your set-up still safe and secure?

Yes, IP access protection is another ‘must enable’, buried away in the menus and off by default. QNAPls.

1 Like

I came close to buying one a few of year’s ago, when upgrading my Synology. They had a hack at the time and I was not impressed with their response and bought another Synology.
At this point unless Synology completely mess up (though there are challenges with DSM 7) they have me as a customer for the next upgrade at least)
I no longer run Roon on mine but I run Plex and share my library with a large number of friends. I also use Plex Amp outside of the house.