1.9 KiB
[2026-09-04] esh-nas SMB account for the AudioGridder box — and the NAS is effectively open to the whole LAN
10.0.50.50 is CT 103 on esh-pve-nas, a hand-rolled Debian NAS (not a Synology). Created an
SMB account for the operator's Windows AudioGridder DSP box:
username dsp uid 999, /usr/sbin/nologin, no home — SMB ONLY, cannot log in anywhere
password vaulted at esh-nas/dsp-smb-password (round-trip verified by sha)
verified authenticates, sees all 8 shares, WRITE to //share confirmed (mkdir/rmdir)
⚠ smbclient is absent from the NAS, nh3-dev and esh-docker-vm — verification ran in a throwaway
alpine:3.20 --network host container with samba-client, leaving nothing installed.
Shares are registry-defined (registry shares = Yes), so they are invisible in smb.conf — use
testparm -s, not grep, or you will conclude there are no shares.
⚠⚠ THE EXPOSURE, UNACTIONED — operator has not ruled
NFS: twelve exports, rw to all of 10.0.0.0/8, sec=sys, no authentication.
/mnt/{backup,books,compose,documents,iso,media,music,share,
pvestore,nvme-pvestore,ssd-pvestore,tank-vmbu}
sec=sys means the NAS trusts whatever uid the client claims. Every VLAN at ESH — IoT,
cameras, guest — can mount the NAS read-write today. /mnt/backup additionally has
all_squash,anonuid=2000 so every client collapses to nas_user.
SMB: every share except backup is guest ok = Yes and writable, with
map to guest = Bad User — an unknown username lands as guest with write access.
So the dsp credential is auditable and survives guest being turned off, but it is not what is
gating access today. Hardening (narrow exports to 10.0.50.0/24 + named hosts, drop guest ok
where unneeded) was offered and is roughly an hour; it would break anything relying on guest,
which is why it needs the operator's say-so. Not actioned. No tracking surface beyond this entry.