Page 1 of 1

Private NAS still listed in search results

Posted: Sun Feb 14, 2021 1:21 am
by conte0815
Hi,
I set access control in myQNAPcloud to "Private", but searching for the name of my NAS still works with the info that I set my NAS to Private.
What gives?
According to User Manual, FAQ and Help from QNap setting access control to private should prevent everyone from finding the NAS at all:
The access modes control who can find your device by searching your device name and view the published services. There are three modes:
1) Public -- Everyone with or without signing in with a myQNAPcloud account
2) Customized -- Only the list of permitted myQNAPcloud accounts
3) Private -- Only yourself.
If you would like to allow other people to use myQNAPcloud Link for accessing your device, please configure Customized mode and add them to your permission list.
https://support.myqnapcloud.com/faq/_fa ... an?lang=en

Re: Private NAS still listed in search results

Posted: Sun Feb 14, 2021 6:21 am
by Mousetick
Yep. Good find. You can also find valid devices by trying https://qlink.to/random-name URLs, even if you're not signed in to myQNAPcloud.
conte0815 wrote:
Sun Feb 14, 2021 1:21 am
What gives?
Well, it's QNAP's idea of security and privacy for ya. :wink:

On my first try looking into this big nice hole, I stumbled upon one NAS whose owner is publishing the QTS UI to the whole world. :roll:

Re: Private NAS still listed in search results

Posted: Fri Mar 05, 2021 11:31 pm
by conte0815
Mousetick wrote:
Sun Feb 14, 2021 6:21 am
Well, it's QNAP's idea of security and privacy for ya. :wink:
:roll:
Mousetick wrote:
Sun Feb 14, 2021 6:21 am
On my first try looking into this big nice hole, I stumbled upon one NAS whose owner is publishing the QTS UI to the whole world. :roll:
You might as well if the name is known. I was wondering about the regular, seemingly targeted, brute force attacks, because I foolishly thought the NAS is hidden and they didn't orignate from port scans.
Sorry for the late answer and thank you for taking the time to reply.