Your NAS is not my BOT - Charles Li, Still Hsu

Image Not Showing Possible Reasons
  • The image file may be corrupted
  • The server hosting the image is unavailable
  • The image path is incorrect
  • The image format is not supported
Learn More →
大會廣播
Image Not Showing Possible Reasons
  • The image file may be corrupted
  • The server hosting the image is unavailable
  • The image path is incorrect
  • The image format is not supported
Learn More →

  • 歡迎大家多填寫共筆!登入 hackmd 後即可填寫。

歡迎來到 HITCON PEACE 2022 共筆
共筆入口:https://hackmd.io/@HITCON/2022-note

從這開始

Intro

open NAS to WAN as small server
Attack related to NAS, such as ransomware or crypto-minor
SN Generation,

Detecting compromised NAS devices

Anomaly NAS - VPS

Exp and Validation

collect subdomain worldwide

Filter

host on VPS

Real world case study

Case 1: SLIME40

Case 2: APT41

Case 3: Goushe

Conclusion

hard to verify from NAS if traced back, just like botnet

tags: HITCON2022,HITCON
Select a repo