Ä³ÍøÂç×°±¸¹©Ó¦ÉÌRoonServerȨÏÞÈÏÖ¤Îó²îÓëÏÂÁî×¢ÈëÎó²îÔ¤¾¯
Ðû²¼Ê±¼ä 2021-06-112021Äê5ÔÂ9ÈÕ£¬£¬£¬Æ¾Ö¤CNCERTÎïÁªÍøÍþвÇ鱨Êý¾Ýƽ̨µÄ¼à²âÏßË÷£¬£¬£¬¿Ðý¹ú¼ÊÓÎÏ·¼¯ÍŽð¾¦Çå¾²Ñо¿ÍŶÓÁªºÏCNCERTÎïÁªÍøÇå¾²Ñо¿ÍŶӷ¢Ã÷2ÏîÁãÈÕÎó²îµÄÔÚҰʹÓÃÐÐΪ¡£¡£
¾È·ÈÏ£¬£¬£¬Õâ2ÏîÁãÈÕÎó²î¾ù±£´æÓÚÍþÁªÍ¨£¨QNAP£©²úÆ·µÄRoonServerÓ¦ÓÃÖУ¬£¬£¬»®·ÖÊÇȨÏÞÈÏÖ¤Îó²îÓëÏÂÁî×¢ÈëÎó²î£¬£¬£¬¹¥»÷Õß¿ÉÒÔ½«Õâ2¸öÎó²î×éºÏÆðÀ´Ê¹Ó㬣¬£¬ÒÔµÖ´ïδÊÚȨԶ³ÌÖ´ÐÐí§ÒâÏÂÁîµÄÄ¿µÄ¡£¡£
ÎÒÃǽ«Ïà¹ØµÄÎó²îÆÊÎö¡¢¸´ÏÖ±¨¸æÊµÊ±±¨Ë͸ø³§ÉÌQNAP£¬£¬£¬ÏÖÔÚ£¬£¬£¬QNAPÒÑÐÞ¸´¸ÃÎó²î£¬£¬£¬²¢Éý¼¶Ó¦ÓÃÈí¼þ¡£¡£
Îó²îÆÊÎö
ÍþÁªÍ¨¿Æ¼¼£¬£¬£¬¼ò³ÆÍþÁªÍ¨£¬£¬£¬Ó¢ÓïÒëÃûô߯·ÅÆÃû³ÆÎªQNAP£¬£¬£¬ÎªÒ»¼ä×ܲ¿Î»ÓÚÖйų́ÍåµÄ¿Æ¼¼¹«Ë¾¡£¡£Æä²úÆ·°üÀ¨ÍøÂ總¼Ó´æ´¢×°±¸¡¢ÊÓÆµ¼à¿ØÂ¼Ïñ×°±¸¡¢ÍøÂç½»Á÷»ú¡¢ÎÞÏß·ÓÉÆ÷¡¢ÎÞÏß/ÓÐÏßÍø¿¨ºÍÊÓÆµ¾Û»á×°±¸µÈ¡£¡£
Îó²îÔÀí
¡ôȨÏÞÈÆ¹ýÎó²î£¨CVE-2021-28810£©
ÓÉÓÚÓ¦ÓöԵǼȨÏÞµÄÑéÖ¤±£´æÎó²î£¬£¬£¬Ö»ÒªÄ³²ÎÊý±£´æÇÒÆäÖµ·Ç¿Õ£¬£¬£¬¼´¿ÉÈÆ¹ýµÇ¼ÑéÖ¤¡£¡£¹¥»÷Õß¿É×ÔÐÐ½á¹¹ÌØÊâµÄÇëÇó¾ÙÐÐÈÆ¹ý¡£¡£
¡ôÏÂÁî×¢ÈëÎó²î£¨CVE-2021-28811£©
µ±urlÖÐÖ¸¶¨µÄactionÎªÌØ¶¨ÖµÊ±£¬£¬£¬Ó¦ÓûáÎüÊÕÁíÒ»¸ö²ÎÊýµÄÖµ£¬£¬£¬¾ÓɼòÆÓµÄÈ¥³ý±êÇ©´¦Öóͷ£ºó£¬£¬£¬´«Èëset_db_pathº¯Êý¡£¡£¸ú×Ùset_db_pathº¯Êý£¬£¬£¬¿ÉÒÔ¿´µ½´Ëº¯Êý½«Æä²ÎÊýÖ±½ÓÆ´½Óµ½ÁËshell_execº¯ÊýÖÐÖ´ÐУ¬£¬£¬Ã»ÓÐÔÙ¾ÙÐÐÈκιýÂË¡£¡£
½«ÉÏÊöÁ½¸öÎó²îÅäºÏʹÓ㬣¬£¬¼´¿ÉÔì³ÉδÊÚȨµÄí§ÒâÏÂÁîÖ´ÐС£¡£
ÔÚÒ°¹¥»÷
ÎÒÃÇ»®·ÖÔÚ5ÔÂ8ÈÕÓë5ÔÂ18ÈÕ²¶»ñµ½Á½ÆðʹÓôËÎó²î¾ÙÐеÄÔÚÒ°¹¥»÷¡£¡£¾Ì«¹ýÎö£¬£¬£¬È·ÈϹ¥»÷ÕßʵÑéÖ²ÈëµÄÔØºÉΪeCh0raixÀÕË÷Èí¼þ¡£¡£
eCh0raixÒ²±»³ÆÎªQNAPCrypt£¬£¬£¬×îÔçÔÚ2019Äê·ºÆð£¬£¬£¬ÊÇÒ»¸ö»ùÓÚGoÓïÑÔ¡¢×¨ÃÅÕë¶ÔÍþÁªÍ¨×°±¸µÄÀÕË÷Èí¼þ¡£¡£ÔËÐк󣬣¬£¬»á¼ÓÃÜ×°±¸ÉÏ´æ´¢µÄÎļþ£¬£¬£¬¼ÓÃܺóÀ©Õ¹ÃûÊÇ.encrypt¡£¡£¼ÓÃÜÍê³Éºó£¬£¬£¬»¹»áÊÍ·ÅÒ»¸ö½ÐREADME_FOR_DECRYPT.txtµÄÎı¾Îļþ£¬£¬£¬ÌáÐÑÊܺ¦Õßͨ¹ýTORÖ§¸¶Êê½ð¡£¡£ÄÚÈÝ´óÖÂÈçÏ£º
All your data has been locked(crypted).
How to unlock(decrypt) instruction located in this TOR website:
http://veqlxhq7ub5qze3qy56zx2cig2e6tzsgxdspkubwbayqije6oatma6id.onion/order/xxx
Use TOR browser for access .onion websites.
ÆäÖÐXXXÊÇhash£¬£¬£¬ÓÃÀ´±ê¼ÇΨһµÄÊܺ¦Õߣ¬£¬£¬TORÖ§¸¶Êê½ðµÄÒ³ÃæÈçÏ£º
ÊÜÓ°Ïì¹Ì¼þ°æ±¾
QNAP RoonServer 2021-02-01¼°Ö®Ç°°æ±¾¡£¡£
Îó²î·¢Ã÷ʱ¼äÖá
? 2021Äê5ÔÂ9ÈÕ£¬£¬£¬ÎÒÃÇ·¢Ã÷Á˺ڿÍʹÓÃÍþÁªÍ¨×°±¸0DayÎó²îÈö²¥ÀÕË÷Èí¼þeCh0raixµÄ¹¥»÷ÐÐΪ¡£¡£
? 2021Äê5ÔÂ12ÈÕ£¬£¬£¬ÎÒÃÇÏò³§ÉÌ£¨QNAP£©µÄÇå¾²ÍŶӱ¨ËÍÁËÏêϸµÄÎó²îÆÊÎö¡¢¸´ÏÖ±¨¸æ£¬£¬£¬ÒÔ×ÊÖúËûÃÇÐÞ¸´²úÆ·¡£¡£
? 2021Äê5ÔÂ14ÈÕ£¬£¬£¬³§ÉÌÈ·ÈÏÎó²î±£´æ£¬£¬£¬½«Îó²îÓ¦ÓôÓapp centerϼܣ¬£¬£¬²¢×îÏÈ×ÅÊÖÐÞ¸´¡£¡£
? 2021Äê6ÔÂ04ÈÕ£¬£¬£¬³§ÉÌÐÞ¸´Íê³É£¬£¬£¬QNAP¹Ù·½ÖØÐÂÔÚapp centerÐû²¼ÐÞ¸´ºóµÄÓ¦Óᣡ£
? 2021Äê6ÔÂ08ÈÕ£¬£¬£¬¸üв¢È·ÈÏCVE±àºÅ¡£¡£
½â¾ö¼Æ»®
Éý¼¶Roon Serverµ½×îа汾£¬£¬£¬ÏêϸÇë¹Ø×¢QNAP¹Ù·½¹ØÓÚ´ËÎó²îµÄÐÞ¸´¼Æ»®¡£¡£
https://www.qnap.com.cn/zh-cn/security-advisory/qsa-21-17
£¨×¢£º±¾±¨¸æÓÉCNCERTÎïÁªÍøÇå¾²Ñо¿ÍŶÓÓë¿Ðý¹ú¼ÊÓÎÏ·¼¯ÍŽð¾¦Çå¾²Ñо¿ÍŶÓÅäºÏÐû²¼¡£¡££©