当前位置:网站首页>Serious PHP defects can lead to rce attacks on QNAP NAS devices
Serious PHP defects can lead to rce attacks on QNAP NAS devices
2022-06-25 03:56:00 【Game programming】

Focus on source code security , Collect the latest information at home and abroad !
compile : Code guard

QNAP Remind the customer to say , An attacker can take advantage of a serious problem that has existed for three years PHP Loophole (CVE-2019-11043), stay NAS The device executes remote code . The company said in the latest safety announcement that , Default configured NAS The equipment is not affected , Running old systems ( stay 2017 - 2019 Issued during the year ) Your device is affected .
QNAP Support... In security bulletins ,“PHP lower than 7.1.33 Version of 7.1.x、 lower than 7.2.24 Version of 7.2.x And below 7.2.11 Of 7.3.x Affected by a vulnerability , This vulnerability, if exploited, can cause an attacker to execute remote code . To protect your equipment , It is recommended to update the system to the latest version regularly .”
QNAP It is a hardware manufacturer in Taiwan, China , Some vulnerable operating system versions have been fixed (QTS 5.0.1.2034 build 20220515 Or later versions and QuTS hero h5.0.0.2069 build 20220614 Or later ).
The flaw is CVE-2019-11043, A large number of equipment that affect the operation of the following systems :
- QTS 5.0.x And later
QTS 4.5.x And later
QuTS hero h5.0.x And later
QuTS hero h4.5.x And later
QuTScloud c5.0.x And later QMAP If the customer needs to NAS The device automatically updates to the latest firmware version , You need to log in as an administrator QTS、QuTS hero or QuTScloud, Click on the control panel > System > Under firmware update “ Check for updates ” Button . In addition, you can also learn from Support>Download Center download QNAP Website update , Manually upgrade the device .
QNAP The device was attacked by blackmail software
Thursday ,QNAP Remind the customer that the equipment is deployed DeadBolt Blackmail Software payload Active attacks on .
Last weekend, ,Bleeping Computer Reports said , The ransomware began to attack vulnerable again QNAP NAS equipment . at present ,QNAP No further details about the attack have been released , So no new information about these DeadBolt And infection vectors used in extortion activities .
QNAP Starting to fix this in all vulnerable firmware versions PHP Loophole (CVE-2019-11043), Users should ensure that the device is not exposed to the Internet to prevent being attacked .QNAP Pointed out that ,NAS Users whose devices are exposed to the Internet should take the following measures to prevent remote access :Disable the router Port Forwading( Port forwarding ) function : Enter the management interface of the router , Check the virtual server 、NAT Or port forwarding settings , And disable NAS Manage service ports ( Default is port 8080 and 433) Port forwarding settings for .
Ban QNAP NAS Of UPnP function : Get into QTS The directory myQNAPcloud, Click on “ Automatic router configuration ” And uncheck “ Enable UPnP Port forwarding ”. QNAP It also details how to hide remote SSH and Telnet Connect , Change the system port number , Change the device password , And enable the IP And account access protection , Further protect the safety of the equipment .
Code guard trial address :https://codesafe.qianxin.com
Open source defender trial address :https://oss.qianxin.com
Recommended reading
Link to the original text
https://www.bleepingcomputer.com/news/security/critical-php-flaw-exposes-qnap-nas-devices-to-rce-attacks/
Title Map :Pixabay License
This article is compiled by Qianxin , It doesn't represent chianxin's point of view . Reprint please indicate “ Transferred from Cheonan code guard https://codesafe.qianxin.com”.


Cheanson code guard (codesafe)
The first domestic product line focusing on software development security .

I think it's good , Just click on it. “ Looking at ” or " Fabulous ” Well ~
author : Cheanson code guard
Game programming , A game development favorite ~
If the picture is not displayed for a long time , Please use Chrome Kernel browser .
边栏推荐
- 论一个优秀红队人员的自我修养
- Crawler grabs the idea of reading on wechat
- 西电AI专业排名超清北,南大蝉联全国第一 | 2022软科中国大学专业排名
- 一文搞懂php中的(DI)依赖注入
- 存算一体芯片离普及还有多远?听听从业者怎么说 | 对撞派 x 后摩智能
- BSC parsing input data of transaction
- Tensorflow, danger! Google itself is the one who abandoned it
- Demonstration of combination of dream CAD cloud map and GIS
- 服乔布斯不服库克,苹果传奇设计团队解散内幕曝光
- The problem that only the home page can be accessed under openSUSE Apache laravel
猜你喜欢

Amazon's other side in China

BGP biplane architecture

谷歌创始人布林二婚破裂:被曝1月已提出与华裔妻子离婚,目前身家6314亿美元...

Sun Wu plays Warcraft? There is a picture and a truth

Redis related-02

Two common OEE monitoring methods for equipment utilization

2022-06-21-Flink-49(一. SQL手册)

Musk was sued for $258billion in MLM claims. TSMC announced the 2nm process. The Chinese Academy of Sciences found that the lunar soil contained water in the form of hydroxyl. Today, more big news is

马斯克:推特要学习微信,让10亿人「活在上面」成为超级APP

CVPR大会现场纪念孙剑博士,最佳学生论文授予同济阿里,李飞飞获黄煦涛纪念奖...
随机推荐
Program. Launch (xxx) open file
Configuration source code
Rebeco: using machine learning to predict stock crash risk
【Harmony OS】【ArkUI】ets开发 图形与动画绘制
AI writes its own code to let agents evolve! The big model of openai has the flavor of "human thought"
The more AI evolves, the more it resembles the human brain! Meta found the "prefrontal cortex" of the machine. AI scholars and neuroscientists were surprised
Tai Chi graphics 60 lines of code to achieve classic papers, 0.7 seconds to get Poisson disk sampling, 100 times faster than numpy
[rust submission] review impl trail and dyn trail in rust
Disassembly of Weima prospectus: the electric competition has ended and the intelligent qualifying has just begun
x86 CPU,危!最新漏洞引发热议,黑客可远程窃取密钥,英特尔“全部处理器”受影响...
如何使用IDE自动签名调试鸿蒙应用
陆奇首次出手投资量子计算
Solution to the problem that Linux crontab timed operation Oracle does not execute (crontab environment variable problem)
服乔布斯不服库克,苹果传奇设计团队解散内幕曝光
Google founder brin's second marriage broke up: it was revealed that he had filed for divorce from his Chinese wife in January, and his current fortune is $631.4 billion
【组队学习】SQL编程语言笔记——Task04
Does it count as staying up late to sleep at 2:00 and get up at 10:00? Unless you can do it every day
The problem that only the home page can be accessed under openSUSE Apache laravel
香蕉为什么能做随机数生成器?因为,它是水果界的“辐射之王”
JS tool function, self encapsulating a throttling function