My syslog shows a few people have accessed my NAS this month.
This is worrying.
My syslog shows a few people have accessed my NAS this month.
This is worrying.
Don't do that.
You say it was "behind your router" but I think you've specifically opened ports to your NAS (or you have some sort of NAT and the NAS has done it)
Restrict access (if you must open it to the internet, open to only specific IP addresses) or better yet disable it, and use an ssh port-forward if you really have to get to it.
Is it really to much to ask to use the Internet as it was intended? We should consider these products broken.
(Edit) Or it might've been checking for updates, got redirected elsewhere via a DNS hijack, downloaded something funny, didn't bother to check if it's authentic and installed it.
1) Weak passcode. 2) Security exploit in DSM.
The fixes are easy; better passcode, and turn off remote access to the device until whatever flaw(s) can be patched.
Also, wasn't there a remote root exploit for samba4 patched just days ago?
However, there's really no reason to expose samba shares to the Internet. There are much better and more secure methods. As to the unfortunate victim, there's most likely no way anyone will be able to retrieve what has been locked by the remote attacker - except the remote attacker.