Ä³ÍøÂç×°±¸¹©Ó¦ÉÌRoonServerȨÏÞÈÏÖ¤Îó²îÓëÏÂÁî×¢ÈëÎó²îÔ¤¾¯

Ðû²¼Ê±¼ä 2021-06-11

2021Äê5ÔÂ9ÈÕ£¬£¬£¬Æ¾Ö¤CNCERTÎïÁªÍøÍþвÇ鱨Êý¾Ýƽ̨µÄ¼à²âÏßË÷£¬£¬£¬¿­Ðý¹ú¼ÊÓÎÏ·¼¯ÍŽð¾¦Çå¾²Ñо¿ÍŶÓÁªºÏCNCERTÎïÁªÍøÇå¾²Ñо¿ÍŶӷ¢Ã÷2ÏîÁãÈÕÎó²îµÄÔÚҰʹÓÃÐÐΪ ¡£¡£


¾­È·ÈÏ£¬£¬£¬Õâ2ÏîÁãÈÕÎó²î¾ù±£´æÓÚÍþÁªÍ¨£¨QNAP£©²úÆ·µÄRoonServerÓ¦ÓÃÖУ¬£¬£¬»®·ÖÊÇȨÏÞÈÏÖ¤Îó²îÓëÏÂÁî×¢ÈëÎó²î£¬£¬£¬¹¥»÷Õß¿ÉÒÔ½«Õâ2¸öÎó²î×éºÏÆðÀ´Ê¹Ó㬣¬£¬ÒÔµÖ´ïδÊÚȨԶ³ÌÖ´ÐÐí§ÒâÏÂÁîµÄÄ¿µÄ ¡£¡£


ÎÒÃǽ«Ïà¹ØµÄÎó²îÆÊÎö¡¢¸´ÏÖ±¨¸æÊµÊ±±¨Ë͸ø³§ÉÌQNAP£¬£¬£¬ÏÖÔÚ£¬£¬£¬QNAPÒÑÐÞ¸´¸ÃÎó²î£¬£¬£¬²¢Éý¼¶Ó¦ÓÃÈí¼þ ¡£¡£


Îó²îÆÊÎö


ÍþÁªÍ¨¿Æ¼¼£¬£¬£¬¼ò³ÆÍþÁªÍ¨£¬£¬£¬Ó¢ÓïÒëÃûô߯·ÅÆÃû³ÆÎªQNAP£¬£¬£¬ÎªÒ»¼ä×ܲ¿Î»ÓÚÖйų́ÍåµÄ¿Æ¼¼¹«Ë¾ ¡£¡£Æä²úÆ·°üÀ¨ÍøÂ總¼Ó´æ´¢×°±¸¡¢ÊÓÆµ¼à¿ØÂ¼Ïñ×°±¸¡¢ÍøÂç½»Á÷»ú¡¢ÎÞÏß·ÓÉÆ÷¡¢ÎÞÏß/ÓÐÏßÍø¿¨ºÍÊÓÆµ¾Û»á×°±¸µÈ ¡£¡£


Îó²îÔ­Àí


¡ôȨÏÞÈÆ¹ýÎó²î£¨CVE-2021-28810£©


ÓÉÓÚÓ¦ÓöԵǼȨÏÞµÄÑéÖ¤±£´æÎó²î£¬£¬£¬Ö»ÒªÄ³²ÎÊý±£´æÇÒÆäÖµ·Ç¿Õ£¬£¬£¬¼´¿ÉÈÆ¹ýµÇ¼ÑéÖ¤ ¡£¡£¹¥»÷Õß¿É×ÔÐÐ½á¹¹ÌØÊâµÄÇëÇó¾ÙÐÐÈÆ¹ý ¡£¡£


1.png


¡ôÏÂÁî×¢ÈëÎó²î£¨CVE-2021-28811£©


µ±urlÖÐÖ¸¶¨µÄactionÎªÌØ¶¨ÖµÊ±£¬£¬£¬Ó¦ÓûáÎüÊÕÁíÒ»¸ö²ÎÊýµÄÖµ£¬£¬£¬¾­ÓɼòÆÓµÄÈ¥³ý±êÇ©´¦Öóͷ£ºó£¬£¬£¬´«Èëset_db_pathº¯Êý ¡£¡£¸ú×Ùset_db_pathº¯Êý£¬£¬£¬¿ÉÒÔ¿´µ½´Ëº¯Êý½«Æä²ÎÊýÖ±½ÓÆ´½Óµ½ÁËshell_execº¯ÊýÖÐÖ´ÐУ¬£¬£¬Ã»ÓÐÔÙ¾ÙÐÐÈκιýÂË ¡£¡£


2.png


½«ÉÏÊöÁ½¸öÎó²îÅäºÏʹÓ㬣¬£¬¼´¿ÉÔì³ÉδÊÚȨµÄí§ÒâÏÂÁîÖ´ÐÐ ¡£¡£


ÔÚÒ°¹¥»÷


ÎÒÃÇ»®·ÖÔÚ5ÔÂ8ÈÕÓë5ÔÂ18ÈÕ²¶»ñµ½Á½ÆðʹÓôËÎó²î¾ÙÐеÄÔÚÒ°¹¥»÷ ¡£¡£¾­Ì«¹ýÎö£¬£¬£¬È·ÈϹ¥»÷ÕßʵÑéÖ²ÈëµÄÔØºÉΪeCh0raixÀÕË÷Èí¼þ ¡£¡£


eCh0raixÒ²±»³ÆÎªQNAPCrypt£¬£¬£¬×îÔçÔÚ2019Äê·ºÆð£¬£¬£¬ÊÇÒ»¸ö»ùÓÚGoÓïÑÔ¡¢×¨ÃÅÕë¶ÔÍþÁªÍ¨×°±¸µÄÀÕË÷Èí¼þ ¡£¡£ÔËÐк󣬣¬£¬»á¼ÓÃÜ×°±¸ÉÏ´æ´¢µÄÎļþ£¬£¬£¬¼ÓÃܺóÀ©Õ¹ÃûÊÇ.encrypt ¡£¡£¼ÓÃÜÍê³Éºó£¬£¬£¬»¹»áÊÍ·ÅÒ»¸ö½ÐREADME_FOR_DECRYPT.txtµÄÎı¾Îļþ£¬£¬£¬ÌáÐÑÊܺ¦Õßͨ¹ýTORÖ§¸¶Êê½ð ¡£¡£ÄÚÈÝ´óÖÂÈçÏ£º


All your data has been locked(crypted).

How to unlock(decrypt) instruction located in this TOR website:

http://veqlxhq7ub5qze3qy56zx2cig2e6tzsgxdspkubwbayqije6oatma6id.onion/order/xxx

Use TOR browser for access .onion websites.


ÆäÖÐXXXÊÇhash£¬£¬£¬ÓÃÀ´±ê¼ÇΨһµÄÊܺ¦Õߣ¬£¬£¬TORÖ§¸¶Êê½ðµÄÒ³ÃæÈçÏ£º


3.png


ÊÜÓ°Ïì¹Ì¼þ°æ±¾


QNAP RoonServer 2021-02-01¼°Ö®Ç°°æ±¾ ¡£¡£


Îó²î·¢Ã÷ʱ¼äÖá


? 2021Äê5ÔÂ9ÈÕ£¬£¬£¬ÎÒÃÇ·¢Ã÷Á˺ڿÍʹÓÃÍþÁªÍ¨×°±¸0DayÎó²îÈö²¥ÀÕË÷Èí¼þeCh0raixµÄ¹¥»÷ÐÐΪ ¡£¡£

? 2021Äê5ÔÂ12ÈÕ£¬£¬£¬ÎÒÃÇÏò³§ÉÌ£¨QNAP£©µÄÇå¾²ÍŶӱ¨ËÍÁËÏêϸµÄÎó²îÆÊÎö¡¢¸´ÏÖ±¨¸æ£¬£¬£¬ÒÔ×ÊÖúËûÃÇÐÞ¸´²úÆ· ¡£¡£

? 2021Äê5ÔÂ14ÈÕ£¬£¬£¬³§ÉÌÈ·ÈÏÎó²î±£´æ£¬£¬£¬½«Îó²îÓ¦ÓôÓapp centerϼܣ¬£¬£¬²¢×îÏÈ×ÅÊÖÐÞ¸´ ¡£¡£

? 2021Äê6ÔÂ04ÈÕ£¬£¬£¬³§ÉÌÐÞ¸´Íê³É£¬£¬£¬QNAP¹Ù·½ÖØÐÂÔÚapp centerÐû²¼ÐÞ¸´ºóµÄÓ¦Óà ¡£¡£

? 2021Äê6ÔÂ08ÈÕ£¬£¬£¬¸üв¢È·ÈÏCVE±àºÅ ¡£¡£


½â¾ö¼Æ»®


Éý¼¶Roon Serverµ½×îа汾£¬£¬£¬ÏêϸÇë¹Ø×¢QNAP¹Ù·½¹ØÓÚ´ËÎó²îµÄÐÞ¸´¼Æ»® ¡£¡£

https://www.qnap.com.cn/zh-cn/security-advisory/qsa-21-17


£¨×¢£º±¾±¨¸æÓÉCNCERTÎïÁªÍøÇå¾²Ñо¿ÍŶÓÓë¿­Ðý¹ú¼ÊÓÎÏ·¼¯ÍŽð¾¦Çå¾²Ñо¿ÍŶÓÅäºÏÐû²¼ ¡£¡££©