PPRuNe Forums - View Single Post - How come? - FTP brute force attack
View Single Post
Old 9th October 2009 | 09:41
  #41 (permalink)  
The late XV105
20 Anniversary
 
Joined: Feb 2006
Posts: 594
Likes: 0
From: UK
Time to move on

Hi Guys,

A courtesy post to say a final thank you.
  1. UPnP proven as the cause
  2. UPnP disabled on both router and NAS (I don't need media streaming internally - it's a backup device)
  3. Manually initiated Shields Up attack on my own external I.P. address revealed no weaknesses
  4. Both disks in the NAS "reformatted" to destroy all data (albeit by switching from RAID 1 to RAID 0 and back to RAID 1)
  5. Wire Shark installed and which confirms nothing trying to report back to base or any other kind of suspicious network activity
  6. MioNet remote access service now disabled (Not the cause of my troubles but a potential future weak link removed)
  7. NAS loaded with non-personal files and left running all night; this morning it was in standby mode and the logs show no activity overnight (they can be scrubbed, yes, but given the above I trust them)

So, other than a small number of files (I reacted quickly) which *may* have escaped from my network and which there is no point worrying about (all files were in a private secure area that would have needed hacking in to, it's too late now, and I don't know if the hack actually did anything anyway) I don't think any damage was done.

Time to move on.
Fresh backup to NAS running as I write this.

"Cheers Guys"

Last edited by The late XV105; 9th October 2009 at 09:46. Reason: Clarification
The late XV105 is offline  
Reply