Ä³ÍøÂç×°±¸¹©Ó¦ÉÌRoonServerȨÏÞÈÏÖ¤Îó²îÓëÏÂÁî×¢ÈëÎó²îÔ¤¾¯

Ðû²¼Ê±¼ä 2021-06-11

2021Äê5ÔÂ9ÈÕ£¬£¬Æ¾Ö¤CNCERTÎïÁªÍøÍþвÇ鱨Êý¾Ýƽ̨µÄ¼à²âÏßË÷£¬£¬ÈËÉú¾ÍÊDz©¼¯ÍŽð¾¦Çå¾²Ñо¿ÍŶÓÁªºÏCNCERTÎïÁªÍøÇå¾²Ñо¿ÍŶӷ¢Ã÷2ÏîÁãÈÕÎó²îµÄÔÚҰʹÓÃÐÐΪ¡£¡£


¾­È·ÈÏ£¬£¬Õâ2ÏîÁãÈÕÎó²î¾ù±£´æÓÚÍþÁªÍ¨£¨QNAP£©²úÆ·µÄRoonServerÓ¦ÓÃÖУ¬£¬»®·ÖÊÇȨÏÞÈÏÖ¤Îó²îÓëÏÂÁî×¢ÈëÎó²î£¬£¬¹¥»÷Õß¿ÉÒÔ½«Õâ2¸öÎó²î×éºÏÆðÀ´Ê¹Ó㬣¬ÒÔµÖ´ïδÊÚȨԶ³ÌÖ´ÐÐí§ÒâÏÂÁîµÄÄ¿µÄ¡£¡£


ÎÒÃǽ«Ïà¹ØµÄÎó²îÆÊÎö¡¢¸´ÏÖ±¨¸æÊµÊ±±¨Ë͸ø³§ÉÌQNAP£¬£¬ÏÖÔÚ£¬£¬QNAPÒÑÐÞ¸´¸ÃÎó²î£¬£¬²¢Éý¼¶Ó¦ÓÃÈí¼þ¡£¡£


Îó²îÆÊÎö


ÍþÁªÍ¨¿Æ¼¼£¬£¬¼ò³ÆÍþÁªÍ¨£¬£¬Ó¢ÓïÒëÃûô߯·ÅÆÃû³ÆÎªQNAP£¬£¬ÎªÒ»¼ä×ܲ¿Î»ÓÚÖйų́ÍåµÄ¿Æ¼¼¹«Ë¾¡£¡£Æä²úÆ·°üÀ¨ÍøÂ總¼Ó´æ´¢×°±¸¡¢ÊÓÆµ¼à¿ØÂ¼Ïñ×°±¸¡¢ÍøÂç½»Á÷»ú¡¢ÎÞÏß·ÓÉÆ÷¡¢ÎÞÏß/ÓÐÏßÍø¿¨ºÍÊÓÆµ¾Û»á×°±¸µÈ¡£¡£


Îó²îÔ­Àí


¡ôȨÏÞÈÆ¹ýÎó²î£¨CVE-2021-28810£©


ÓÉÓÚÓ¦ÓöԵǼȨÏÞµÄÑéÖ¤±£´æÎó²î£¬£¬Ö»ÒªÄ³²ÎÊý±£´æÇÒÆäÖµ·Ç¿Õ£¬£¬¼´¿ÉÈÆ¹ýµÇ¼ÑéÖ¤¡£¡£¹¥»÷Õß¿É×ÔÐÐ½á¹¹ÌØÊâµÄÇëÇó¾ÙÐÐÈÆ¹ý¡£¡£


1.png


¡ôÏÂÁî×¢ÈëÎó²î£¨CVE-2021-28811£©


µ±urlÖÐÖ¸¶¨µÄactionÎªÌØ¶¨ÖµÊ±£¬£¬Ó¦ÓûáÎüÊÕÁíÒ»¸ö²ÎÊýµÄÖµ£¬£¬¾­ÓɼòÆÓµÄÈ¥³ý±êÇ©´¦Öóͷ£ºó£¬£¬´«Èëset_db_pathº¯Êý¡£¡£¸ú×Ùset_db_pathº¯Êý£¬£¬¿ÉÒÔ¿´µ½´Ëº¯Êý½«Æä²ÎÊýÖ±½ÓÆ´½Óµ½ÁËshell_execº¯ÊýÖÐÖ´ÐУ¬£¬Ã»ÓÐÔÙ¾ÙÐÐÈκιýÂË¡£¡£


2.png


½«ÉÏÊöÁ½¸öÎó²îÅäºÏʹÓ㬣¬¼´¿ÉÔì³ÉδÊÚȨµÄí§ÒâÏÂÁîÖ´ÐС£¡£


ÔÚÒ°¹¥»÷


ÎÒÃÇ»®·ÖÔÚ5ÔÂ8ÈÕÓë5ÔÂ18ÈÕ²¶»ñµ½Á½ÆðʹÓôËÎó²î¾ÙÐеÄÔÚÒ°¹¥»÷¡£¡£¾­Ì«¹ýÎö£¬£¬È·ÈϹ¥»÷ÕßʵÑéÖ²ÈëµÄÔØºÉΪeCh0raixÀÕË÷Èí¼þ¡£¡£


eCh0raixÒ²±»³ÆÎªQNAPCrypt£¬£¬×îÔçÔÚ2019Äê·ºÆð£¬£¬ÊÇÒ»¸ö»ùÓÚGoÓïÑÔ¡¢×¨ÃÅÕë¶ÔÍþÁªÍ¨×°±¸µÄÀÕË÷Èí¼þ¡£¡£ÔËÐк󣬣¬»á¼ÓÃÜ×°±¸ÉÏ´æ´¢µÄÎļþ£¬£¬¼ÓÃܺóÀ©Õ¹ÃûÊÇ.encrypt¡£¡£¼ÓÃÜÍê³Éºó£¬£¬»¹»áÊÍ·ÅÒ»¸ö½ÐREADME_FOR_DECRYPT.txtµÄÎı¾Îļþ£¬£¬ÌáÐÑÊܺ¦Õßͨ¹ýTORÖ§¸¶Êê½ð¡£¡£ÄÚÈÝ´óÖÂÈçÏ£º


All your data has been locked(crypted).

How to unlock(decrypt) instruction located in this TOR website:

http://veqlxhq7ub5qze3qy56zx2cig2e6tzsgxdspkubwbayqije6oatma6id.onion/order/xxx

Use TOR browser for access .onion websites.


ÆäÖÐXXXÊÇhash£¬£¬ÓÃÀ´±ê¼ÇΨһµÄÊܺ¦Õߣ¬£¬TORÖ§¸¶Êê½ðµÄÒ³ÃæÈçÏ£º


3.png


ÊÜÓ°Ïì¹Ì¼þ°æ±¾


QNAP RoonServer 2021-02-01¼°Ö®Ç°°æ±¾¡£¡£


Îó²î·¢Ã÷ʱ¼äÖá


? 2021Äê5ÔÂ9ÈÕ£¬£¬ÎÒÃÇ·¢Ã÷Á˺ڿÍʹÓÃÍþÁªÍ¨×°±¸0DayÎó²îÈö²¥ÀÕË÷Èí¼þeCh0raixµÄ¹¥»÷ÐÐΪ¡£¡£

? 2021Äê5ÔÂ12ÈÕ£¬£¬ÎÒÃÇÏò³§ÉÌ£¨QNAP£©µÄÇå¾²ÍŶӱ¨ËÍÁËÏêϸµÄÎó²îÆÊÎö¡¢¸´ÏÖ±¨¸æ£¬£¬ÒÔ×ÊÖúËûÃÇÐÞ¸´²úÆ·¡£¡£

? 2021Äê5ÔÂ14ÈÕ£¬£¬³§ÉÌÈ·ÈÏÎó²î±£´æ£¬£¬½«Îó²îÓ¦ÓôÓapp centerϼÜ£¬£¬²¢×îÏÈ×ÅÊÖÐÞ¸´¡£¡£

? 2021Äê6ÔÂ04ÈÕ£¬£¬³§ÉÌÐÞ¸´Íê³É£¬£¬QNAP¹Ù·½ÖØÐÂÔÚapp centerÐû²¼ÐÞ¸´ºóµÄÓ¦Óᣡ£

? 2021Äê6ÔÂ08ÈÕ£¬£¬¸üв¢È·ÈÏCVE±àºÅ¡£¡£


½â¾ö¼Æ»®


Éý¼¶Roon Serverµ½×îа汾£¬£¬ÏêϸÇë¹Ø×¢QNAP¹Ù·½¹ØÓÚ´ËÎó²îµÄÐÞ¸´¼Æ»®¡£¡£

https://www.qnap.com.cn/zh-cn/security-advisory/qsa-21-17


£¨×¢£º±¾±¨¸æÓÉCNCERTÎïÁªÍøÇå¾²Ñо¿ÍŶÓÓëÈËÉú¾ÍÊDz©¼¯ÍŽð¾¦Çå¾²Ñо¿ÍŶÓÅäºÏÐû²¼¡£¡££©