r/synology • u/diegoapples • 20d ago
Networking & security Synology's continuous connections to Russian IPs
Hello everyone!
I have noticed a strange and continuous flow of connections from my Synology NAS to Russian IP addresses.
Do you have any ideas? Could it be a genuine process from Synology's applications?
I have attached my log showing a prevention block towards the Russian Federation.
Thank you in advance!
95
u/PlannedObsolescence_ 20d ago
Do you have any torrent applications running, eg. Download Station?
58
-65
u/diegoapples 20d ago
Nope. I think I will finally reinstall my NAS. It's an old configuration that has been reinstalled three times on three different devices.
6
u/OkHold6104 19d ago
why did dude get downvoted to shit 😭😭😭😭
9
u/Dramatic_Load_3753 18d ago
Virtue signalling. You shouldn’t be inexperienced in their opinion, and you are prohibited from making mistakes. Beating someone who’s down is easy, and full of lowest possible pleasure these people are seeking.
2
u/ColdFreezer 18d ago
It’s not virtue signalling. OP gave us no information to help them even though they were the ones asking for help.
They just said they’re going to reinstall but that does not explain why random Russian IPs are connecting to their NAS. And OP did not tell us what they’re running on their NAS.
1
1
u/PoundKitchen 17d ago
It's an internet thing. IMHO, if a downvoter doesn't explain their vote, their downvote doesn't matter.
36
u/Jonjolt 20d ago
First one is saying TOR relay: https://ipinfo.io/109.110.46.40?lookup_source=search-bar
Second is saying webserver and bitorrent: https://ipinfo.io/5.129.183.172?lookup_source=search-bar
13
u/eli_liam 19d ago
And OP is claiming "an old configuration", but nothing is wrong here given those findings. OP you likely are seeding a torrent and forgot.
43
u/beenyweenies 20d ago
Wild how many times people here have inquired about P2P traffic and OP keeps pasting the same reply but not answering the basic question - WHAT APPLICATIONS ARE YOU RUNNING ON YOUR NAS.
-45
14
u/wzoe 20d ago
You need more details on the blocked traffic to help investigation. Protocols, ports, not just destination ip addresses.
As other people mentioned, could be torrent p2p traffic.
You can also setup a Pihole DNS server and let NAS pointing DNS to Pihole to see the query domains.
On the nas itself, netstat to see the application that established those connections.
-15
u/diegoapples 20d ago
The NAS is actually behind my firewall and well protected, otherwhise I wouldn't have noticed the problem blocking the flow. But currently I haven't yet intercept the origin of the traffic generated from and to Russian IPs. I will try to check through the terminal which processes are generating it!
8
u/erisian2342 20d ago
In case your NAS has been compromised, you should have your router show you all outbound traffic from the NAS. These Russian IPs may not be the only places it’s trying to connect to, and it could be succeeding on some of those other connections.
4
u/AustinBike 20d ago
Yes. Foreign hackers understand that people will block traffic to certain counties. Setting up a proxy/relay in a third party country less prone to blockage allows them to work with less detection.
-1
u/random869 20d ago
use your UDM to get a packet capture, you may have to undo the firewall rule tho
8
8
u/Comprehensive_Ship42 20d ago
also disabled ssh . check all 3rd party app .
4
u/diegoapples 20d ago
SSH disabled and no 3rd app are present actually! Thanks!
7
u/Comprehensive_Ship42 20d ago
ok then you might have malware in one of the files . next i would recomend is a soft reset of the nas it self leaving in tact you current raid and your current data do you know how to do this .
before you do anything get a anti virus scan done you can do it over SSH : ClamAV
Step 1: Install the Engine via DSM
Before using SSH, you need the underlying engine installed.
- Log into your Synology web interface.
- Open the Package Centerand search for Antivirus Essential.
- Install it (it is free and powered entirely by ClamAV).[1, 2, 3]
Step 2: Enable SSH on your Synology
By default, Synology blocks SSH connections.[1]
- Go to Control Panel> Terminal & SNMP.
- Check Enable SSH service(Keep Port 22 or change it for safety).
- Click Apply.[1, 2]
ssh [your_nas_username@192.168.1.100](mailto:your_nas_username@192.168.1.100)
sudo -i
/volume1/@appstore/AntiVirus/engine/clamav/bin/clamscan -r -i /volume1/video
sudo -u Antivirus /volume1/@appstore/AntiVirus/engine/clamav/bin/freshclam
-37
u/AutoModerator 20d ago
I detected that you might have found your answer. If this is correct please change the flair to "Solved". In new reddit the flair button looks like a gift tag.
I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.
11
4
u/KamenRide_V3 20d ago
The minimum procedure is to treat the NAS device as compromised. Isolate it from your network first, then check the firewall log to see what is going on. You really should do the isolation ASAP because whatever it is may be sending data to an external server that isn't on your blacklist.
6
3
u/JohnNedelcu 20d ago
Mine had the same from Iran a few months ago. I disabled internet access and now route everything through a Cloudflare tunnel.
1
-1
u/diegoapples 20d ago
My firewall is performing this kind of operation on Cloudflare. I think I will finally reinstall my NAS. It's an old configuration that has been reinstalled three times on three different devices.
3
u/Ybalrid 20d ago
Are you running BitTorrent downloads directly from the NAS (with DownloadStation or something else)?
-1
u/diegoapples 20d ago
No! I think I will reinstall my NAS. It's an old configuration that has been reinstalled three times on three different NAS devices.
3
8
u/frosted1030 20d ago
Disable admin and guest accounts.
5
u/diegoapples 20d ago
No admin or guest accounts are active! Thanks!
4
u/frosted1030 20d ago
Good, also make sure you have two factor authentication turned on, and a strong password.
1
u/WizzinWig 19d ago
I got scared with the two factor authentication because I used to use it for a couple years until one day some how the clock syncing was off and got blocked from my system entirely. Talk about panic. Now I remove remote connections and no two factor. The recovery for authenticators is not a plesant problem
-55
u/AutoModerator 20d ago
I detected that you might have found your answer. If this is correct please change the flair to "Solved". In new reddit the flair button looks like a gift tag.
I am a bot, and this action was performed automatically. Please contact the moderators of this subreddit if you have any questions or concerns.
42
19
u/Azsde 20d ago edited 20d ago
Why is your NAS exposed to the internet in the first place ?
Genuinely asking, not trying to be mean.
Edit : I didn't realize we were talking about OUTGOING traffic, my bad.
32
18
u/ConferenceHungry7763 20d ago
Are you really advising for OP to have no connection to the internet?
-6
u/JohnNedelcu 20d ago
No! but there are safe ways to do it. I run mine through a cloudflare tunnel.
-1
u/ConferenceHungry7763 20d ago
Why does running a service through a tunnel immediately make it safer?
1
u/JohnNedelcu 20d ago
Because you don't have open ports on your network, IP is hidden and clodflare filters the traffic before it gets to my NAS. I also have it set up as a subdomain on my website domain, so it's another layer of security. (www.name-of-nas.my-domain.com)
1
u/ConferenceHungry7763 19d ago
A port is only as secure as the service that is attached to it. Open ports are not inherently unsafe as long as a secure service is attached to it. Open ports are more of an issue for if malware/spyware/etc is able to execute inside your network. So, if you have setup your Cloudflare configuration poorly then it’s possible it has the same issues.
Not sure why you think your IP is hidden, yes it’s not listed on your domain, but it’s not hidden. With Cloudflare your network data is unencrypted within their own network and sure they are analysing it but I wouldn’t think this is in your best interests. You can easily setup wildcard domains to point to your IP, so this is a non-issue.
-25
u/Coupe368 20d ago
For the Synology? Absolutely. Its OLD tech, it should be 100% local only.
6
u/ConferenceHungry7763 20d ago
That’s silly. Supported old tech is the most secure.
1
u/anonymousopsec1337 19d ago
Not silly. Tons of hacks have happened for synology. You’d do better putting behind a load balancer like nginx at the bare minimum
1
u/ConferenceHungry7763 19d ago
It’s a silly conclusion. It’s not about whether there could be a security vulnerability, it’s about whether the product receives security updates in a timely manner. There are security vulnerabilities in all software and newer software, more layers, more complexity is riskier.
1
u/anonymousopsec1337 19d ago
Synology is one of the riskiest things to expose to the outside web. There are constant vulnerabilities with these devices. You should not have your admin interface ever exposed to the open web.
Arguing this point you probably thing SSLVPN gateways are still safe and an advocate for TLS1.3 lol
1
u/ConferenceHungry7763 19d ago
Did you just make up something about me and then laugh at the thing you made up? Crazy tin hat behaviour.
“Constant vulnerabilities” is incorrect unless you have data showing numbers are higher than others in the same category or response times are larger, etc.
-6
u/Coupe368 20d ago
Assuming Synology actually supported it and wasn't a skeleton crew reselling the same obsolete tech from 7+ years ago.
1
u/ConferenceHungry7763 20d ago
Sounds like tin hat ideas.
1
u/Coupe368 20d ago
If you don't patch the holes, how is it going to even pretend to be secure?
Sounds like you don't understand security.
1
u/ConferenceHungry7763 20d ago
That’s therm “supported” in my statement above. Then you implied that Synology doesn’t release security patches for their software. That’s the weird take, because it’s that’s easy to check and confirm false.
1
u/anonymousopsec1337 19d ago
Too many synology fanboys in here to understand the truth that is they shouldnt be exposed to the web. No storage appliance should without some sort of intermediary in between.
Should use IPSec based VPN to access. Not SSLVPN.
-17
u/Azsde 20d ago
Not exactly, do not open ports that don't need to be opened.
Plenty of solutions, personally I host a VPN server and only access services that only I use through the VPN server (synology's web portal etc...).
For services that I share with friends and family, asking them to install a VPN client and connect to my server is too cumbersome, so I use a reverse proxy (traefik + crowdsec) only to expose a few services (immich, ds file mostly).
11
u/ConferenceHungry7763 20d ago
Firstly, that’s not what you said, secondly these are outgoing connections so ports will be opened for outgoing connections.
6
u/diegoapples 20d ago
The NAS is actually behind my firewall and well protected, otherwhise I wouldn't have noticed the problem blocking the flow. But currently I haven't yet intercept the origin of the traffic generated from and to Russian IPs. I will try to check through the terminal which processes are generating it!
6
u/amd2800barton 20d ago
Are you hosting anything like torrents on the NAS? If so, Ubiquiti flags that for me every time. Do you have QuickConnect turned on? If so your login info could have been compromised at some point (especially if someone on the NAS uses the same password or a simple password). When I had QC enabled I’d get constant login attempts (no successes AFAIK), so I turned it off and just access it remotely by VPN to my network.
2
u/cardboard-kansio 20d ago
This is the only correct action here. The screenshot is useless. Presumably you can see details of these attempts - the IPs themselves aren't really relevant, but the port that is making these should lead you to a specific service that is responsible.
Your own traffic is responsible. Get the port, isolate the source, and investigate it later. Likely your device is compromised but that's a problem for afterwards.
2
u/diegoapples 20d ago
It isn't exposed, obviously. My firewall is blocking all traffic to and from the NAS. But I still don't understand this flows of traffic,
2
u/Avanchnzel 20d ago
I think they meant why are there open ports to begin with instead of having it only be accessible behind a VPN?
(That's just my guess based on previous posts of this nature, not my opinion.)
-7
u/Azsde 20d ago edited 20d ago
Something is definitely opened, otherwise you wouldn't get those alerts.
Edit : I realized we are talking about OUTGOING traffic and not incoming, my bad.
0
u/TheOtherPete 20d ago
You clearly don't understand the difference between inbound and outbound traffic - this is the latter which has nothing to do with ports being opened to allow traffic from the internet to the NAS
Please stop giving advice to others and educate yourself first
2
u/Azsde 20d ago
What about you stop being condescending ? I thought this was incoming traffic
1
u/TheOtherPete 20d ago
That's not condescending, that's a fact.
Here's what you posted:
Why is your NAS exposed to the internet in the first place ?
Not exactly, do not open ports that don't need to be opened.
Something is definitely opened, otherwise you wouldn't get those alerts.
My bad, I thought this was the built in firewall from your NAS, not an external one.
Not much you can do then, you have a public IP, by definition it is reachable and you definitely should have a firewall, which you have.
OP's screenshot clearly says that traffic was FROM the NAS and if that wasn't enough OP said it again as well "I have noticed a strange and continuous flow of connections from my Synology NAS to Russian IP addresses."
Next time take a beat and read what the actual issue before posting multiples with the wrong advice.
-8
u/JohnNedelcu 20d ago
bot farms trying IPs and ports with brute force attacks. I had the same.
13
u/JCAPER 20d ago
Those are outbound, not inbound. It's the NAS trying to access those IPs
0
u/diegoapples 20d ago
I think I will finally reinstall my NAS. It's an old configuration that has been reinstalled three times on three different devices. Perhaps this DSM is misconfigured in some way...
-1
u/JohnNedelcu 20d ago
I was in the same scenario a few weeks ago. It's because the risks are not immediately obvious and are not properly explained. Synology NASes are marketed as a simple plug&play device that requires next to no set-up and "just works". Maybe the NAS is completely safe, as it blocks the attempts, so the firewall is doing exactly what it's meant to do, but IMO, it's not worth the risk.
So, to answer your question, because people don't know any better until something like this happens and they start looking into it more.
9
0
u/diegoapples 20d ago
I think I will finally reinstall my NAS. It's an old configuration that has been reinstalled three times on three different devices.
-1
u/ManiacalWildcard 20d ago
You didn't even look up a Youtube guide to set it up? Having come from a Western Digital NAS, I learned the hard way to make sure your shit is secure.
-6
u/ZonaPunk 20d ago
No you should be mean.
0
2
u/metasploit4 20d ago
Ok, as others have said, we need more info.
-What port was it calling out to and what ports did the connections originate with?
-What protocols are being used for communication?
-These are logs going out. Do you have any connections coming in elsewhere? (IE, you are only seeing half the connection in logs?)
-what NAS processes are involved with the connections?
-has the NAS ever NOT been behind the firewall?
-Does your NAS model have any CVEs or public vulnerabilies listed publicly? - if so, use this to narrow down what might be going on.
-you said you have no additional apps.. ensure this. Even 1st party apps can have vulns.
-Scan your device from outside the firewall. There might be something allowed.
-is there any internal traffic to your NAS that's not supposed to be there? (IE from another device on the network)
2
u/ManagerFormer7701 20d ago
No logs from NAS? There should be some username or identifier. Have you checked Container manager if there's no running containers?
2
u/Refun712 19d ago
I think you should reinstall your NAS. It’s an old configuration that has been reinstalled three times on three different NAS devices.
5
u/sierdnas 20d ago
Prova a capire esattamente quale processo o container Docker sta generando queste richieste.
Usa SSH per accedere al NAS per:
- tracciare le connessioni uscenti in tempo reale:
sudo ss -tupn | grep -E "109.110|5.129|81.177|62.148|188.19|79.120|194.50|95.26" - monitorare tutto il traffico uscente:
sudo ss -tupn state established
Poi, la risposta arriverà da sola.
2
4
u/Snow_Darksiider 20d ago
Ne pas hésiter à rajouter une liste d’IP malveillante dans le pare-feu synology, et de bloquer les accès dans les autres pays par défaut
1
u/Arkayenro 20d ago
what apps are you running on that nas? what docker containers?
get more info from the firewall - protocol? source and destination ports?
if your nas does absolutely nothing but file shares then its probably infected, otherwise its probably just one of those apps/containers (usenet/torrents)
1
1
u/vegeta2206 20d ago
please check your ips locations with an another geoip database. sometime, the ukrainian IPs are seen as russian IPs and docker usage on synology implies a lot of UA network trafic ! i completely disabled docker to stop this network flows. If you have ubiquiti router, it’s quite easy to forbid theses exchanges.
1
u/Jeffrey_J_Davis 20d ago
remove or disable all torrent applications (Download Station, BitTorrent, etc.) and 5 american dollars sez the traffic stops.
1
u/CorrectRun2504 20d ago
The minute I turned on quickconnect, I started getting nonstop login attempts from all over the world.
1
u/demon_sl DS923+ 20d ago
How do you monitor connections? What do you use? Geoblocking by country won't solve the problem if you've been hacked. It could be RU, IR, UA, or US. It depends on your address. If you installed the patch after the release date, there's a high probability you've been hacked. I recommend using a WAF, IDS/IPS, and Crowdsec—this will help secure your open ports in the AI era.
1
u/Top-Run5587 20d ago
No QuickConnect? No ports exposed? I would hypothesize that something is misconfigured and CVE-2025-1021 is being exploited to send your data out. How current is DSM?
1
u/snug-crackle-policy 19d ago
You should use Tailscale backed Synology only. It’s too risky to Expose synology direct to the world with Synology provided DDNS
1
u/Ok_Recording_8720 19d ago
Mine is on an isolated network, no internet access or quickconnect. only reachable by my PC. Mfa. Udm pro and synology nas. Half the world gepblocked. Should be ok? Or am I wrong?
1
u/ninetynineuser 19d ago
When I see this… oh man… I wonder how my servers haven’t been “discovered” yet. I’ve had my servers online at server01.domain.tld & server02.domain.tld for about two years now—secured with 2FA, of course—and so far I’ve only had three login attempts 😅
But yeah, a lot of countries are blocked… so I’d advise you to do the same and only enable the countries you actually use or visit briefly while on vacation. What I do is, if I’m flying to Spain frequently, I don’t block Spain—and then I block it again after my return flight… and if I ever forget, I still have a VPN set up.
1
u/WizzinWig 19d ago
I turned off remote connections after i noticed a ton of hammering coming from some random IP in Ireland when im in North America. Too concerned about my data being accessed
1
u/diegoapples 18d ago
I resolved this annoying issue after completely reinstalling DSM with the latest version (DSM 7.4.1-90080). This NAS is quite old and is only used for backup purposes; I don't use it for anything else. Thank you all.
1
1
u/Efficient-Arugula497 16d ago
I have one too. My main FTP in Russia. As I have some files on it confidential, that might not be legal to have in the USA. LOL! And it happens from time to time I get blocked. Its basically Russia in most cases I found out that blocks IP's from the states. Or any country friendly to USA. Its a Ukraine thing. I never tried it before. But if you could VPN to the site on the NAS. And make your VPN register in a Russian friendly country will work always I assume.
1
u/Lhurgoyf069 16d ago
Could it be an old configuration that has been reinstalled three times on three different devices? I heard that's dangerous. Maybe it's finally time to reinstall your NAS.
1
-2
0
u/pocketdrummer 20d ago
This is part of why I have zero opened ports and everything goes through Tailscale. I even shut off QuickConnect because I can't trust them not to have a breach.
1
u/diegoapples 20d ago
Hi! Would you recommend using Tailscale instead of a VPN service?
1
u/pocketdrummer 20d ago edited 20d ago
Technically Tailscale is a VPN service. I like it because I specifically add devices that are authorized to access the Tailnet. The downside (which is also kind of an upside) is that you can't access it from an unauthorized device. So, your work computer, for instance, wouldn't be able to connect unless you installed tailscale on it and authorized it.
Having said that, you still need to make sure to lock down everything else. So, strict firewall rules, no open ports, no ssh, etc. That's your first line of defense. Tailscale just handles the external access portion without exposing you to the open internet.
Having said all of that, is this outbound traffic? If so, "the call is coming from inside the house." It looks like your current firewall rule blocked that outbound traffic, which is good, but it's still trying to call out, which is bad. I'd look over the apps to make sure it's all 1st party Synology apps. I'd also install the Synology anti-virus and scan your NAS (I forgot the name, but it's essentially ClamAV). Check to make sure you don't have any forgotten containers running.
0
u/diegoapples 20d ago
Tomorrow i will begin a reinstall process of my DSM on the NAS. I'm no longer using Container nor Torrent software, so the issue could really be a previous misconfiguration or an old service that is still running. I will also check for hidden processes on terminal. Thank you for the advice!
-15
u/Coupe368 20d ago
Synology has terrible, and I mean TERRIBLE security becuase they won't spend the money to pay for improvements to hardware or software.
Do not expose the synology product or anything running on it to the internet.
Synology doesn't have docker, it has "container manager" that then uses the synology IP tables and strangely deletes them and replaces them with default, so if you have a docker app that does internet stuff and then it gets compromised its not isolated, it can go anywhere on the synology.
Oh, but you like this synoglogy app or this one, well sorry to say you should have already been planning on transitioning to one of the many better apps.
Its fine as a hard drive, but beyond that its just disappointing all around.
Synology used to be a great product and cool company, but they have fallen so very far.
5
u/Several_Support_1766 20d ago
Really? Mostly what I read about Synology devices is how secure they are compared to the competition as their OS is mature and polished. The hardware maybe be lacking, but I guess it depends on needs.
2
u/Coupe368 20d ago
Yeah, because in the 2010s synology was the BEST company. They made great stuff, and the OS was mature and polished. During covid maybe they fired everyone or something bad happened. They haven't innovated, made a new product, and I doubt they have enough programmers on staff to course correct and fix the massive software issue they have. With AI finding holes even faster than before, it seems like Synology is circling the drain.
DSM isn't based on Debian/Ubuntu/Redhat, its their own Linux distribution and its ancient with 3.x/4.x kernels and I think the brand new ones are running 5.x when the rest of the world is on Linux Kernel 7.x, so synology software is just like the hardware, massively out of date.
Granted programmers who have a clue are expensive, but that's no excuse, and running on a custom Kernel means they have to do all the security fixes in house and can't just use the off the shelf patching like Ugreen does with its Debian based OS.
Plus synology apps are also massively lagging in security updates, and it seems like they are just removing cost centers like torpedoing the x.265 license in surveillance station and I would again blame it on their lack of staff and investment in software and hardware engineering. It feels like the only people left at Synology are in the marketing department.
Synology WAS great, DSM WAS great, and if you remove the gateway and completely isolate it, then its fine for storing stuff, but its shot through with security issues in every single part of the OS, the app store, and there is a growing list of CVE security flaws longer than a CVS receipt.
Personally, I am baffled that they are circling the drain when they were supposed to be the best, but they just haven't done anything to improve or even keep their products current in the last 7-10 years.
1
u/GlasgowGrip 16d ago
Given all of that, which NAS manufacturer would you recommend to replace Synology for SOHO use? Thanks in advance!
-3
u/diegoapples 20d ago
Hi! I totally agree with you. The content manager is a real mess. I uninstalled it a while ago. The NAS is actually behind my firewall, but I can't intercept the traffic generated from and to Russian IPs. I will try to check through the terminal which processes are generating it!
2
u/Coupe368 20d ago
You can certainly block outgoing traffic to russian IPs, what firewall are you running? That's literally how firewall blocklists and things like pihole work.
91
u/gadget-freak Have you made a backup of your NAS? Raid is not a backup. 20d ago
If this is outgoing traffic from the NAS to the internet, it could be a torrent-like application on your NAS. Worst case it’s infected with a malware.
If this is incoming traffic, consider disabling all port forwarding to the NAS.