HomeSecurityQNAP: Shuts down server after brute-force attack

QNAP: Shuts down server after brute-force attack

QNAP has disabled a malicious server used in widespread “brute-force” attacks carried out on devices exposed to the internet, with weak passwords.

See also: QNAP: Warns of Linux Sudo vulnerability in NAS devices
QNAP

The Taiwanese hardware manufacturer detected the attacks on the afternoon of October 14th and, with the help of Digital Ocean, disabled the control server (used to control a botnet of hundreds of infected systems) within two days.

QNAP’s Product Security Incident Response Team (QNAP PSIRT) immediately blocked hundreds of zombie network IP addresses via QuFirewall within 7 hours, effectively protecting many QNAP NAS devices exposed to the internet ,” the company said

QNAP encourages its customers to secure their devices by changing the default access port number, disabling port forwarding on their router and UPnP on the NAS, using secure passwords for their accounts, implementing password policies, and disabling the administrator account targeted for attacks.

It also provides detailed instructions on how to implement defensive measures in its security guide:

  • Disable the “ admin ” account .
  • Set strong passwords for all user accounts and avoid using weak passwords.
  • Update firmware and applications to the latest versions.
  • Install and activate the QuFirewall.
  • Use myQNAPcloud Link 's relay service to prevent your network attached storage (NAS) from being exposed to the internet. If there are bandwidth requirements or specific applications that require port forwarding, avoid using the default ports 8080 and 443.

See also: QNAP fixes critical vulnerability affecting NAS devices

The company regularly warns its customers to be cautious about brute-force attacks against QNAP NAS devices exposed online, as these attacks often lead to ransomware.

brute force

Cybercriminals often attack NAS devices, aiming to steal or encrypt valuable documents or install information. These devices are often used to copy secure files and share sensitive files, making them valuable targets for malicious actors.

Recent attacks targeting QNAP devices include the DeadBolt, Checkmate , and eCh0raix, which abused security vulnerabilities to encrypt data on NAS devices accessible over the internet.

Synology , another Taiwanese NAS manufacturer, also warned its customers in August 2021 that their network storage devices were being targeted by the StealthWorker botnet in ongoing brute-force attacks that could lead to ransomware infections.

See also: QNAP fixes zero-day bug used by DeadBolt ransomware

In general, brute-force attacks are an attempt to breach a digital domain by trying all possible passwords until the correct one is found. They directly attack the weakest point of any digital shield: human error and incompetence. 

It is a common misconception that brute-force attacks are simply an attack method used by less skilled hackers. On the contrary, these attacks pose a very crucial threat to maintaining the security of digital systems, as they can be implemented with acumen, determination and patience, which makes them extremely dangerous. 

How is a brute-force attack carried out? 

As already mentioned, a brute-force attack aims to find the correct password that grants access to a system. This computational algorithm creates arbitrary sequences of character strings, attempting to match them with the secret password, through a process of iteration and exhaustive checking. 

The success of the attack depends largely on two important factors: the weakness of the password and the strength of the attacker's computing equipment.

The most common passwords that people use are easy and convenient and are ideal targets for a brute-force attack. In addition, a major advance in the power of modern computing equipment has significantly increased the scope of brute-force attacks.

Source: bleepingcomputer

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr
Being your self, in a world that constantly tries to change you, is your greatest achievement

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS