NAS - Tagged - Security Boulevard The Home of the Security Bloggers Network Tue, 26 Nov 2024 15:00:42 +0000 en-US hourly 1 https://wordpress.org/?v=6.7.1 https://securityboulevard.com/wp-content/uploads/2021/10/android-chrome-256x256-1-32x32.png NAS - Tagged - Security Boulevard 32 32 133346385 QNAP’s Buggy Security Fix Causes Chaos https://securityboulevard.com/2024/11/qnap-bad-patch-richixbw/ Tue, 26 Nov 2024 14:54:57 +0000 https://securityboulevard.com/?p=2037597 Three tiny people cleaning the inside of a hard drive

RAID FAIL: NAS Maker does a CrowdStrike—cleanup on /dev/dsk/c1t2d3s4 please

The post QNAP’s Buggy Security Fix Causes Chaos appeared first on Security Boulevard.

]]>
2037597
These 20 D-Link Devices Have Critical RCE Bug — but NO Patch NEVER https://securityboulevard.com/2024/11/d-link-nas-wont-fix-richixbw/ Wed, 13 Nov 2024 17:22:08 +0000 https://securityboulevard.com/?p=2036204 xkcd.com/327 — “Exploits of a Mom”

‘Bobby’ flaw flagged WONTFIX: Company doesn’t make storage devices now; has zero interest in fixing this catastrophic vulnerability.

The post These 20 D-Link Devices Have Critical RCE Bug — but NO Patch NEVER appeared first on Security Boulevard.

]]>
2036204
LinkedIn Data Leak, Western Digital NAS Attacks, STIR/SHAKEN Deadline https://securityboulevard.com/2021/07/linkedin-data-leak-western-digital-nas-attacks-stir-shaken-deadline/ Mon, 05 Jul 2021 04:00:11 +0000 https://sharedsecurity.net/?p=100715 Was there another LinkedIn “data leak” or is this just the same data anyone with a LinkedIn account can access? Western Digital Network-Attached Storage (NAS) devices under attack, and details on the STIR/SHAKEN deadline which is supposed to help stop robocalls. ** Links mentioned on the show ** New LinkedIn Data Leak Leaves 700 Million […]

The post LinkedIn Data Leak, Western Digital NAS Attacks, STIR/SHAKEN Deadline appeared first on The Shared Security Show.

The post LinkedIn Data Leak, Western Digital NAS Attacks, STIR/SHAKEN Deadline appeared first on Security Boulevard.

]]>
1886837
Did your WD My Book NAS get Wiped? Put a Brave Face on It https://securityboulevard.com/2021/06/did-your-wd-my-book-nas-get-wiped-put-a-brave-face-on-it/ Mon, 28 Jun 2021 16:20:29 +0000 https://securityboulevard.com/?p=1885980

A 2019 vulnerability is being exploited to remotely wipe WD My Book Live NAS devices, by Eastern-European malefactors.

The post Did your WD My Book NAS get Wiped? Put a Brave Face on It appeared first on Security Boulevard.

]]>
1885980
5 Essentials to Consider When Backing up Your Data https://securityboulevard.com/2019/03/5-essentials-to-consider-when-backing-up-your-data/ Wed, 27 Mar 2019 07:00:42 +0000 https://securityboulevard.com/?p=1803467 Essentials to Consider When Backing up Data

Data backup is very crucial for any business. It’s been said that a company is as good as the quality of its data backup plan. In a perfect world, if you have the best backup solution, your need for insurance is significantly reduced—a reliable backup plan ensures your data is safe even when the systems..

The post 5 Essentials to Consider When Backing up Your Data appeared first on Security Boulevard.

]]>
1803467
French Government Open Sources Secure Operating System https://securityboulevard.com/2018/09/french-government-open-sources-secure-operating-system/ Fri, 21 Sep 2018 12:00:07 +0000 https://securityboulevard.com/?p=1785169 Skype End-to-End Encryption

The French government’s national cybersecurity agency has released an operating system built using open source components internally over the course of more than 10 years for use by the French administration. Dubbed CLIP OS, the operating system is based on the open source Linux kernel, but focuses on security hardening and provides partitioning mechanisms that..

The post French Government Open Sources Secure Operating System appeared first on Security Boulevard.

]]>
1785169
Recovering data from an old encrypted Time Machine backup https://securityboulevard.com/2018/07/recovering-data-from-an-old-encrypted-time-machine-backup/ Sat, 21 Jul 2018 13:42:00 +0000 http://securityboulevard.com/?guid=706ad85fb7c7f4029fb3ddece6ee6cfe Recovering data from a backup should be an easy thing to do. At least this is what you expect. Yesterday I had a problem which should have been easy to solve, but it was not. I hope this blog post can help others who face the same problem.

The problem

1. I had an encrypted Time Machine backup which was not used for months
2. This backup was not on an official Apple Time Capsule or on a USB HDD, but on a WD MyCloud NAS
3. I needed files from this backup
4. After running out of time I only had SSH access to the macOS, no GUI

The struggle

By default, Time Machine is one of the best and easiest backup solution I have seen. As long as you stick to the default use case, where you have one active backup disk, life is pink and happy. But this was not my case.

As always, I started to Google what shall I do. One of the first options recommended that I add the backup disk to Time Machine, and it will automagically show the backup snapshots from the old backup. Instead of this, it did not show the old snapshots but started to create a new backup. Panic button has been pressed, backup canceled, back to Google.

Other tutorials recommend to click on the Time Machine icon and pressing alt (Option) key, where I can choose "Browse other backup disks". But this did not list the old Time Machine backup. It did list the backup when selecting disks in Time Machine preferences, but I already tried and failed that way.

YAT (yet another tutorial) recommended to SSH into the NAS, and browse the backup disk, as it is just a simple directory where I can see all the files. But all the files inside where just a bunch of nonsense, no real directory structure.

YAT (yet another tutorial) recommended that I can just easily browse the content of the backup from the Finder by double-clicking on the sparse bundle file. After clicking on it, I can see the disk image on the left part of the Finder, attached as a new disk.
Well, this is true, but because of some bug, when you connect to the Time Capsule, you don't see the sparse bundle file. And I got inconsistent results, for the WD NAS, double-clicking on the sparse bundle did nothing. For the Time Capsule, it did work.
At this point, I had to leave the location where the backup was present, and I only had remote SSH access. You know, if you can't solve a problem, let's complicate things by restrict yourself in solutions.

Finally, I tried to check out some data forensics blogs, and besides some expensive tools, I could find the solution.

The solution

Finally, a blog post provided the real solution - hdiutil.
The best part of hdiutil is that you can provide the read-only flag to it. This can be very awesome when it comes to forensics acquisition.

To mount any NAS via SMB:

mount_smbfs afp://<username>@<NAS_IP>/<Share_for_backup> /<mountpoint>

To mount a Time Capsule share via AFP:

mount_afp afp://any_username:password@<Time_Capsule_IP>/<Share_for_backup> /<mountpoint>

And finally this command should do the job:

hdiutil attach test.sparsebundle -readonly

It is nice that you can provide read-only parameter.

If the backup was encrypted and you don't want to provide the password in a password prompt, use the following:

printf '%s' 'CorrectHorseBatteryStaple' | hdiutil attach test.sparsebundle -stdinpass -readonly

Note: if you receive the error "resource temporarily unavailable", probably another machine is backing up to the device

And now, you can find your backup disk under /Volumes. Happy restoring!

Probably it would have been quicker to either enable the remote GUI, or to physically travel to the system and login locally, but that would spoil the fun.

The post Recovering data from an old encrypted Time Machine backup appeared first on Security Boulevard.

]]>
1778237
Malware hits 500k IoT devices, Talos reports https://securityboulevard.com/2018/06/malware-hits-500k-iot-devices-talos-reports/ Fri, 01 Jun 2018 20:00:39 +0000 http://healthsecuritysolutions.bypronto.com/?p=13184 Malware hits 500k IoT devices, Talos reports

A week ago, leading cyber threat intelligence team Cisco Talos reported that no less than 500,000 IoT devices in up to 54 countries were infected by new malware called VPNFilter. An earlier version, believed to be launched by a nation-state, targeted Ukraine.

The post Malware hits 500k IoT devices, Talos reports appeared first on Health Security Solutions.

The post Malware hits 500k IoT devices, Talos reports appeared first on Security Boulevard.

]]>
1773411
Dome9 Package for Synology NAS https://securityboulevard.com/2014/06/dome9-package-for-synology-nas/ Fri, 13 Jun 2014 15:51:03 +0000 http://www.securitygeneration.com/?p=4800 I own a Synology DS413j NAS,

The post Dome9 Package for Synology NAS appeared first on Security Boulevard.

]]>
1952060