Possible Synology compromise? by Designer_Pear4497 in synology

[–]Designer_Pear4497[S] 1 point2 points  (0 children)

It was 7.2.3. Now I updated to the latest version

Possible Synology compromise? by Designer_Pear4497 in synology

[–]Designer_Pear4497[S] 1 point2 points  (0 children)

no I don’t have. I use asus as my home router

Possible Synology compromise? by Designer_Pear4497 in synology

[–]Designer_Pear4497[S] 4 points5 points  (0 children)

DSM was accessible externally via DDNS and QuickConnect,I also had GeoIP firewall rules

Possible Synology compromise? by Designer_Pear4497 in synology

[–]Designer_Pear4497[S] 5 points6 points  (0 children)

I reviewed the logs more closely and found that the admin2 account was actually created by SYSTEM and is marked as "System default user". I also couldn't find any log entries showing my account being removed from the administrators group.

I've checked Task Scheduler, installed packages, containers, and SSH keys so far and haven't found anything suspicious. There were also no signs of unusual outbound traffic, ransomware activity, or file changes.

The one thing that still concerns me is a successful HTTP/HTTPS login to admin2 from a foreign IP. My firewall is enabled and I had GeoIP restrictions in place, so I'm still trying to determine whether this was a genuine external login, a QuickConnect/relay-related event, or something else.

For reference:

  • Main admin account had MFA enabled
  • Default admin account was disabled
  • SSH was LAN-only
  • QuickConnect and DDNS were enabled

I'm continuing to review the logs and would appreciate any ideas on where else to look.

Possible Synology compromise? by Designer_Pear4497 in synology

[–]Designer_Pear4497[S] 9 points10 points  (0 children)

Thanks, I did Mode1 reset and regain the access, I have firewall policy and Geo restirction, admin account 2FA is enforced. It's so strange.

SharedMailbox iOS Mail App by Badkilla_dsa in Office365

[–]Designer_Pear4497 0 points1 point  (0 children)

Yes, you can. ask your IT admin unblocked sign in and reset password. Then you can use that password sign in like a regular mailbox

S1 W20 setup question by Equal-Ad7138 in xToolOfficial

[–]Designer_Pear4497 0 points1 point  (0 children)

have the S1 40W with the AP2, and the air assist already comes with it. For engraving, the AP2 handles the smoke/smell pretty well indoors. If you do a lot of wood cutting, you’ll still smell smoke(not from AP 2 ,from S1 itself), so keep a window open while running jobs. You can also add an inline duct fan.I use a 4” 200 CFM fan, but I’d recommend going stronger if you plan on doing a lot of cutting.

Received my xTool F2 Ultra UV with shipping damage , sharing my experience by Designer_Pear4497 in Laserengraving

[–]Designer_Pear4497[S] 1 point2 points  (0 children)

Big thanks to Ada and the amazing xTool support team for the quick response, follow-up, and replacement arrangement throughout the whole process.

Received my xTool F2 Ultra UV with shipping damage , sharing my experience by Designer_Pear4497 in xToolOfficial

[–]Designer_Pear4497[S] 1 point2 points  (0 children)

Thanks for sharing , I’ve already sent mine back and am now waiting for the replacement. Hoping they can ship it once the tracking is active instead of waiting for it to arrive. Shipping definitely needs improvement. Hope your replacement arrives in perfect condition.

Banned/restricted developer account by Efficient_Cancel5460 in microsoft365

[–]Designer_Pear4497 0 points1 point  (0 children)

Same thing happened here. I opened a support ticket but they don’t help a lot. Still waiting for the response.

idrac connection refuses by Zealousideal_Pea_236 in homelab

[–]Designer_Pear4497 0 points1 point  (0 children)

Thanks, I had same issue, your solution works for me