NETGEAR is aware of a growing number of phone and online scams. To learn how to stay safe click here.

Forum Discussion

Tangoman's avatar
Tangoman
Aspirant
Sep 24, 2013

Security how on earth does it work

System Netgear Readynas NV+ V2

I'm at a complete loss here.
I'm not unintelligent, but I simply cannot get the security on this box to work.

I have a single share.
I am running the following services: SMB, UPnP, FTP, HTTP, HTTPS

At present I have the admin account and a single user "ReadOnly" setup
Note - if I go into Users/Groups, I do not see the admin user listed, however I am able to connect to the box from windows using this account.

I have the Share configured as follows:

Only SMB is enabled.
In the Share Access I have ReadOnly ticked for Everyone (group), and nothing ticked for users, and ReadOnly - these inherit the Readonly property from Everyone.

Allow anonymous access is unticked.

Under protocol specific settings I have the Creation rights all set to ReadOnly
Unser Files and Folders I have Folder Owner and Group set to nobody, the Rights are all set to Readonly

Despite all of this, I can still connect to the box from windows without even presenting a username/pw and make any changes I like.

How is this resolvable?

4 Replies

Replies have been turned off for this discussion
  • StephenB's avatar
    StephenB
    Guru - Experienced User
    Does the windows logon/password match up with any of the NAS accounts (including admin)???

    What firmware are you running?
  • The windows account on the Pc that is able to access without any pw, has no pw - the username matches an account which WAS on the device, but has been deleted.
  • StephenB's avatar
    StephenB
    Guru - Experienced User
    Tangoman wrote:
    The windows account on the Pc that is able to access without any pw, has no pw - the username matches an account which WAS on the device, but has been deleted.
    By default, Windows will present the windows logon/password to the NAS.

    This behavior can be modified in the Windows Credential's Manager (in control panel). So the next step is to look there, and see if there is an entry that specifies credentials for the NAS.

NETGEAR Academy

Boost your skills with the Netgear Academy - Get trained, certified and stay ahead with the latest Netgear technology! 

Join Us!

ProSupport for Business

Comprehensive support plans for maximum network uptime and business peace of mind.

 

Learn More