<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:creativeCommons="http://backend.userland.com/creativeCommonsRssModule"
	>
<channel>
	<title>Comments on: Multiple Vulnerabilities in ALL Synology Products</title>
	<atom:link href="http://isisblogs.poly.edu/2008/04/04/multiple-vulnerabilities-in-all-synology-products/feed/" rel="self" type="application/rss+xml" />
	<link>http://isisblogs.poly.edu/2008/04/04/multiple-vulnerabilities-in-all-synology-products/</link>
	<description>Information Systems and Internet Security</description>
	<lastBuildDate>Sat, 26 Sep 2009 11:11:21 -0400</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.5</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Johan</title>
		<link>http://isisblogs.poly.edu/2008/04/04/multiple-vulnerabilities-in-all-synology-products/comment-page-1/#comment-3494</link>
		<dc:creator>Johan</dc:creator>
		<pubDate>Sat, 26 Sep 2009 11:11:21 +0000</pubDate>
		<guid isPermaLink="false">http://isisblogs.poly.edu/?p=81#comment-3494</guid>
		<description>Thanks you so much for this great article. I have since then changed to QNAP and bought a QNAP TS-239 Pro Turbo NAS and they are much much faster than Synology and their build quality is much better as well, e.g. QNAP uses metal casings, Synology uses plastic!</description>
		<content:encoded><![CDATA[<p>Thanks you so much for this great article. I have since then changed to QNAP and bought a QNAP TS-239 Pro Turbo NAS and they are much much faster than Synology and their build quality is much better as well, e.g. QNAP uses metal casings, Synology uses plastic!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: NAS</title>
		<link>http://isisblogs.poly.edu/2008/04/04/multiple-vulnerabilities-in-all-synology-products/comment-page-1/#comment-3362</link>
		<dc:creator>NAS</dc:creator>
		<pubDate>Sat, 13 Jun 2009 01:01:11 +0000</pubDate>
		<guid isPermaLink="false">http://isisblogs.poly.edu/?p=81#comment-3362</guid>
		<description>Hi,

What happened in the end?, did they fix the security issues you mentioned? I&#039;m interested in getting a Synology NAS they seem to have the perfect feature set for my needs, but am not so sure now having read this article...

Thanks</description>
		<content:encoded><![CDATA[<p>Hi,</p>
<p>What happened in the end?, did they fix the security issues you mentioned? I&#8217;m interested in getting a Synology NAS they seem to have the perfect feature set for my needs, but am not so sure now having read this article&#8230;</p>
<p>Thanks</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Simon</title>
		<link>http://isisblogs.poly.edu/2008/04/04/multiple-vulnerabilities-in-all-synology-products/comment-page-1/#comment-3348</link>
		<dc:creator>Simon</dc:creator>
		<pubDate>Thu, 14 May 2009 12:35:15 +0000</pubDate>
		<guid isPermaLink="false">http://isisblogs.poly.edu/?p=81#comment-3348</guid>
		<description>I am also looking to get the CS407 and was wondering whether the recent firmware released has resolved all these vulnerabilities you raised?</description>
		<content:encoded><![CDATA[<p>I am also looking to get the CS407 and was wondering whether the recent firmware released has resolved all these vulnerabilities you raised?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mike</title>
		<link>http://isisblogs.poly.edu/2008/04/04/multiple-vulnerabilities-in-all-synology-products/comment-page-1/#comment-3332</link>
		<dc:creator>Mike</dc:creator>
		<pubDate>Mon, 02 Mar 2009 03:13:45 +0000</pubDate>
		<guid isPermaLink="false">http://isisblogs.poly.edu/?p=81#comment-3332</guid>
		<description>Hi there, 

I have recently been looking at buying a synology ds. 
I had personally wondered what the security to be like, however I did expect it to be ok being a commercial product.  
I found your not so recent post in the forums. It was interesting to find some possible issues. 
I don’t think the post had the correct outcome. I didn’t like the way it was compared to everyday risked. 
I’m still debating whether I should buy one or not. I have very limited knowledge of UNIX, however one thing I am warned against is running things as root unless required. 
I’m not educated enough to know how bad all the flaws are;  do these really hold a real world risk? Statically I think bot systems may have issues? But if it came under a direct attack then maybe things could be worse? I don’t know!?!?! Realistically how bad are these faults?
I think it has made me rethink how I’d used such a device; I need to remote access option. However I think the security I would take it to put no personal information on the device. I would use remote access for pdf files, music access and a web server. 
I  used to run a full linux webserver with php/mySQL. I wonder how many faults I had in the system, as I’m not too informed!
Would Windows Home Server be better  

What’s the latest progress?</description>
		<content:encoded><![CDATA[<p>Hi there, </p>
<p>I have recently been looking at buying a synology ds.<br />
I had personally wondered what the security to be like, however I did expect it to be ok being a commercial product.<br />
I found your not so recent post in the forums. It was interesting to find some possible issues.<br />
I don’t think the post had the correct outcome. I didn’t like the way it was compared to everyday risked.<br />
I’m still debating whether I should buy one or not. I have very limited knowledge of UNIX, however one thing I am warned against is running things as root unless required.<br />
I’m not educated enough to know how bad all the flaws are;  do these really hold a real world risk? Statically I think bot systems may have issues? But if it came under a direct attack then maybe things could be worse? I don’t know!?!?! Realistically how bad are these faults?<br />
I think it has made me rethink how I’d used such a device; I need to remote access option. However I think the security I would take it to put no personal information on the device. I would use remote access for pdf files, music access and a web server.<br />
I  used to run a full linux webserver with php/mySQL. I wonder how many faults I had in the system, as I’m not too informed!<br />
Would Windows Home Server be better  </p>
<p>What’s the latest progress?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Marco Aicardi</title>
		<link>http://isisblogs.poly.edu/2008/04/04/multiple-vulnerabilities-in-all-synology-products/comment-page-1/#comment-397</link>
		<dc:creator>Marco Aicardi</dc:creator>
		<pubDate>Thu, 07 Aug 2008 15:16:54 +0000</pubDate>
		<guid isPermaLink="false">http://isisblogs.poly.edu/?p=81#comment-397</guid>
		<description>Great, great, great work!

Thank you VERY much!

Marco</description>
		<content:encoded><![CDATA[<p>Great, great, great work!</p>
<p>Thank you VERY much!</p>
<p>Marco</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jeroen</title>
		<link>http://isisblogs.poly.edu/2008/04/04/multiple-vulnerabilities-in-all-synology-products/comment-page-1/#comment-381</link>
		<dc:creator>Jeroen</dc:creator>
		<pubDate>Mon, 21 Jul 2008 12:31:41 +0000</pubDate>
		<guid isPermaLink="false">http://isisblogs.poly.edu/?p=81#comment-381</guid>
		<description>Hi Dan,

I pretty much came to the same conclusion as you did, but by different (more subjective) means. It is very difficult to implement this much functionality in such a short amount of time. This way I got suspicious and found your post. I do not believe Synology to turn things around any time soon. You did me and many people out there a BIG BIG favour. Thanks!

Speaking on the issue, I have just purchased a Readynas and hope Netgear  (or should I say Infant) have taken more time to make a proper NAS instead of a feature box. Now my question towards you is:

Could you make a wiki (or perhaps just a how-to) that describes to people how you have assessed the Synology. I could get pretty far on my own but the more people involved, the better. And yes, you may poke around my Readynas as much as you like. It needs proper testing before deployment anyway:-). Still, it would be useful for many user to be able to do an audit themselves.
Most reviewers out there don&#039;t even scrape the surface of a security audit, praising products like Synology. Now THAT pisses me off:-)

regards,

Jeroen</description>
		<content:encoded><![CDATA[<p>Hi Dan,</p>
<p>I pretty much came to the same conclusion as you did, but by different (more subjective) means. It is very difficult to implement this much functionality in such a short amount of time. This way I got suspicious and found your post. I do not believe Synology to turn things around any time soon. You did me and many people out there a BIG BIG favour. Thanks!</p>
<p>Speaking on the issue, I have just purchased a Readynas and hope Netgear  (or should I say Infant) have taken more time to make a proper NAS instead of a feature box. Now my question towards you is:</p>
<p>Could you make a wiki (or perhaps just a how-to) that describes to people how you have assessed the Synology. I could get pretty far on my own but the more people involved, the better. And yes, you may poke around my Readynas as much as you like. It needs proper testing before deployment anyway:-). Still, it would be useful for many user to be able to do an audit themselves.<br />
Most reviewers out there don&#8217;t even scrape the surface of a security audit, praising products like Synology. Now THAT pisses me off:-)</p>
<p>regards,</p>
<p>Jeroen</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: neeeko</title>
		<link>http://isisblogs.poly.edu/2008/04/04/multiple-vulnerabilities-in-all-synology-products/comment-page-1/#comment-347</link>
		<dc:creator>neeeko</dc:creator>
		<pubDate>Wed, 04 Jun 2008 11:10:11 +0000</pubDate>
		<guid isPermaLink="false">http://isisblogs.poly.edu/?p=81#comment-347</guid>
		<description>It&#039;s always funny to see a forum full of synology products addicted people who became suddenly blind by staring to much at them in their living room/bedroom/office...
Makes me think of people drinking and swallowing the news on mass media channels..without wondering anything about the truth and the purpose behind it. 

Hard to wake up people nowadays...keep on sleeping peeps...

You have my full support and deserved way better than that on their smelly moderated forum...

Keep up the good work.</description>
		<content:encoded><![CDATA[<p>It&#8217;s always funny to see a forum full of synology products addicted people who became suddenly blind by staring to much at them in their living room/bedroom/office&#8230;<br />
Makes me think of people drinking and swallowing the news on mass media channels..without wondering anything about the truth and the purpose behind it. </p>
<p>Hard to wake up people nowadays&#8230;keep on sleeping peeps&#8230;</p>
<p>You have my full support and deserved way better than that on their smelly moderated forum&#8230;</p>
<p>Keep up the good work.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: AliasMarlowe</title>
		<link>http://isisblogs.poly.edu/2008/04/04/multiple-vulnerabilities-in-all-synology-products/comment-page-1/#comment-345</link>
		<dc:creator>AliasMarlowe</dc:creator>
		<pubDate>Fri, 23 May 2008 19:36:21 +0000</pubDate>
		<guid isPermaLink="false">http://isisblogs.poly.edu/?p=81#comment-345</guid>
		<description>I have a DS-207, and it works nicely enough on our home LAN. It&#039;s behind a firewall, and the firewall has rules explicitly preventing any connection from WAN to Synology (I don&#039;t trust the security of anything I can&#039;t configure) or from Synology to WAN (I don&#039;t like boxes calling home without my permission). So it&#039;s used as a local file server, and as a local web server for home - not internet accessible.</description>
		<content:encoded><![CDATA[<p>I have a DS-207, and it works nicely enough on our home LAN. It&#8217;s behind a firewall, and the firewall has rules explicitly preventing any connection from WAN to Synology (I don&#8217;t trust the security of anything I can&#8217;t configure) or from Synology to WAN (I don&#8217;t like boxes calling home without my permission). So it&#8217;s used as a local file server, and as a local web server for home &#8211; not internet accessible.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: wlof</title>
		<link>http://isisblogs.poly.edu/2008/04/04/multiple-vulnerabilities-in-all-synology-products/comment-page-1/#comment-344</link>
		<dc:creator>wlof</dc:creator>
		<pubDate>Fri, 23 May 2008 17:50:59 +0000</pubDate>
		<guid isPermaLink="false">http://isisblogs.poly.edu/?p=81#comment-344</guid>
		<description>Hi,

I stumbled upon your blog while looking if it was possible to use dm-crypt with Synology products. I just wanted to tell you that I, too, am now delaying buying a CS407. Also, the way those two &quot;honorary moderators&quot; and fanboys treated you is definitely not good publicity for Synology, IMO.

It&#039;s too bad they don&#039;t allow alternative firmwares, kinda like OpenWrt for wifi routers. That would really allow to get the best of both worlds, a cool piece of hardware with open-source, up-to-date software...

Anyway, I still think I&#039;m going to buy a CS407 (performance and feature-wise, it&#039;s still the best thing in its budget category) but only after they release a new firmware. Thanks a lot for the warning, more people should know about this!

(Sorry if I made any English mistakes, I&#039;m not a native speaker.)

wlof</description>
		<content:encoded><![CDATA[<p>Hi,</p>
<p>I stumbled upon your blog while looking if it was possible to use dm-crypt with Synology products. I just wanted to tell you that I, too, am now delaying buying a CS407. Also, the way those two &#8220;honorary moderators&#8221; and fanboys treated you is definitely not good publicity for Synology, IMO.</p>
<p>It&#8217;s too bad they don&#8217;t allow alternative firmwares, kinda like OpenWrt for wifi routers. That would really allow to get the best of both worlds, a cool piece of hardware with open-source, up-to-date software&#8230;</p>
<p>Anyway, I still think I&#8217;m going to buy a CS407 (performance and feature-wise, it&#8217;s still the best thing in its budget category) but only after they release a new firmware. Thanks a lot for the warning, more people should know about this!</p>
<p>(Sorry if I made any English mistakes, I&#8217;m not a native speaker.)</p>
<p>wlof</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Joachim</title>
		<link>http://isisblogs.poly.edu/2008/04/04/multiple-vulnerabilities-in-all-synology-products/comment-page-1/#comment-342</link>
		<dc:creator>Joachim</dc:creator>
		<pubDate>Thu, 22 May 2008 13:53:40 +0000</pubDate>
		<guid isPermaLink="false">http://isisblogs.poly.edu/?p=81#comment-342</guid>
		<description>Thanx for your research.

I bought some Diststations as file server and backup media. I find it quite frustrating that Synology is not updating their samba version to &quot;recent&quot; releases.

For me the big feature of those boxes is not the included services/applications, it&#039;s the power consumption to price to performance balance. I&#039;ll stick to my DSs (and will probably buy some more) - but they are not and will never be on the internet. In fact, in our network they live in their own security zone (Juniper/Netscreen) and run an updated version of samba (ipkg).

To me it was surprising from the very beginning, that somebody serious would put such a box &quot;on the internet&quot;. But then again, that&#039;s what they are advertised for. In my opinion anything that runs a webserver with PHP (or any other form of cgi) is a timebomb in the hands of normal user.

I dont really share your fears about compiled CGIs (in general). Compiled or not isn&#039;t more or less secure per se. In my eyes, the biggest problem with the compiled CGIs is that one can&#039;t verify the source.

Regards,
Joachim</description>
		<content:encoded><![CDATA[<p>Thanx for your research.</p>
<p>I bought some Diststations as file server and backup media. I find it quite frustrating that Synology is not updating their samba version to &#8220;recent&#8221; releases.</p>
<p>For me the big feature of those boxes is not the included services/applications, it&#8217;s the power consumption to price to performance balance. I&#8217;ll stick to my DSs (and will probably buy some more) &#8211; but they are not and will never be on the internet. In fact, in our network they live in their own security zone (Juniper/Netscreen) and run an updated version of samba (ipkg).</p>
<p>To me it was surprising from the very beginning, that somebody serious would put such a box &#8220;on the internet&#8221;. But then again, that&#8217;s what they are advertised for. In my opinion anything that runs a webserver with PHP (or any other form of cgi) is a timebomb in the hands of normal user.</p>
<p>I dont really share your fears about compiled CGIs (in general). Compiled or not isn&#8217;t more or less secure per se. In my eyes, the biggest problem with the compiled CGIs is that one can&#8217;t verify the source.</p>
<p>Regards,<br />
Joachim</p>
]]></content:encoded>
	</item>
</channel>
</rss>
