F4-210 TOS 4.2.20
I have a major security issue with user shares to external USB devices.
On LAN users have no access and that part of ‘Permissions’ I can’t adjust.
Only ‘admin’ users can access USB devices.
This is when things are very broken in my opinion…
I have users that connect via SFTP and they have full access to USB shares and they shouldn’t be able to do that.
This is a MAJOR FAIL and needs to be addressed by Terramaster Techs ASAP. If they don’t then it seriously degrades your product and the integrity of Terramaster that claims to have security as a priority in all its products.
I found this serious flaw in your product just by using it as a first user of a Terramaster NAS, and I can’t believe you at Terramaster HQ are not aware of it.
I know that the SFTP side is broken and I am sure the boffins at Terramaster HQ should have the capability to make sure all protocols of connecting to their devices are tested before any updated TOS is released.
If it was a plane in the air that fell to the ground then it would be classed as a ‘Catastrophic Failure’
My data is important to me, the safe as other users, and a Terramaster NAS is an extension to that.
Please address this very serious issue ASAP as it is a ‘Catastrophic Failure’ when it comes to data security.
Until then your products are NOT SECURE.
I would prefer a direct response from Terramaster to my contact email address and that to be reflected in this forum.
Major Security Issue In USB Shares
Re: Major Security Issue In USB Shares
You need to post your thread to "New features wanted", in TOS 5, you will be able to manage USB permissions.
To contact our team, please send email to following addresses, remember to replace (at) with @:
Support team: support(at)terra-master.com (for technical support only)
Service team: service(at)terra-master.com (for purchasing, return, replacement, RMA service)
Support team: support(at)terra-master.com (for technical support only)
Service team: service(at)terra-master.com (for purchasing, return, replacement, RMA service)
- sianderson
- Posts: 293
- Joined: 02 Aug 2020, 03:42
Re: Major Security Issue In USB Shares
wow i see what you mean, TM can you deal with this as a Bug not a request
this screen shot says this user should be denied access to the usb, so how come logged in with SFTP this user can access it !!
the user is part of the allusers group and is not an admin so why can a user access it?
this screen shot says this user should be denied access to the usb, so how come logged in with SFTP this user can access it !!
the user is part of the allusers group and is not an admin so why can a user access it?
F2-210
4.2.43
4.2.43
Re: Major Security Issue In USB Shares
{L_BUTTON_AT}sianderson
For your infomation.
I sent an email to support@ and their reply says they have confirmed the issue and are working on it. I have a feeling that was the better cause of action as this serious issue wasn't being highlighted in this forum.
Thank you for your assistance and for also proving the issue can be recreated.