当前位置:网站首页>Serious PHP defects can lead to rce attacks on QNAP NAS devices
Serious PHP defects can lead to rce attacks on QNAP NAS devices
2022-06-25 03:56:00 【Game programming】

Focus on source code security , Collect the latest information at home and abroad !
compile : Code guard

QNAP Remind the customer to say , An attacker can take advantage of a serious problem that has existed for three years PHP Loophole (CVE-2019-11043), stay NAS The device executes remote code . The company said in the latest safety announcement that , Default configured NAS The equipment is not affected , Running old systems ( stay 2017 - 2019 Issued during the year ) Your device is affected .
QNAP Support... In security bulletins ,“PHP lower than 7.1.33 Version of 7.1.x、 lower than 7.2.24 Version of 7.2.x And below 7.2.11 Of 7.3.x Affected by a vulnerability , This vulnerability, if exploited, can cause an attacker to execute remote code . To protect your equipment , It is recommended to update the system to the latest version regularly .”
QNAP It is a hardware manufacturer in Taiwan, China , Some vulnerable operating system versions have been fixed (QTS 5.0.1.2034 build 20220515 Or later versions and QuTS hero h5.0.0.2069 build 20220614 Or later ).
The flaw is CVE-2019-11043, A large number of equipment that affect the operation of the following systems :
- QTS 5.0.x And later
QTS 4.5.x And later
QuTS hero h5.0.x And later
QuTS hero h4.5.x And later
QuTScloud c5.0.x And later QMAP If the customer needs to NAS The device automatically updates to the latest firmware version , You need to log in as an administrator QTS、QuTS hero or QuTScloud, Click on the control panel > System > Under firmware update “ Check for updates ” Button . In addition, you can also learn from Support>Download Center download QNAP Website update , Manually upgrade the device .
QNAP The device was attacked by blackmail software
Thursday ,QNAP Remind the customer that the equipment is deployed DeadBolt Blackmail Software payload Active attacks on .
Last weekend, ,Bleeping Computer Reports said , The ransomware began to attack vulnerable again QNAP NAS equipment . at present ,QNAP No further details about the attack have been released , So no new information about these DeadBolt And infection vectors used in extortion activities .
QNAP Starting to fix this in all vulnerable firmware versions PHP Loophole (CVE-2019-11043), Users should ensure that the device is not exposed to the Internet to prevent being attacked .QNAP Pointed out that ,NAS Users whose devices are exposed to the Internet should take the following measures to prevent remote access :Disable the router Port Forwading( Port forwarding ) function : Enter the management interface of the router , Check the virtual server 、NAT Or port forwarding settings , And disable NAS Manage service ports ( Default is port 8080 and 433) Port forwarding settings for .
Ban QNAP NAS Of UPnP function : Get into QTS The directory myQNAPcloud, Click on “ Automatic router configuration ” And uncheck “ Enable UPnP Port forwarding ”. QNAP It also details how to hide remote SSH and Telnet Connect , Change the system port number , Change the device password , And enable the IP And account access protection , Further protect the safety of the equipment .
Code guard trial address :https://codesafe.qianxin.com
Open source defender trial address :https://oss.qianxin.com
Recommended reading
Link to the original text
https://www.bleepingcomputer.com/news/security/critical-php-flaw-exposes-qnap-nas-devices-to-rce-attacks/
Title Map :Pixabay License
This article is compiled by Qianxin , It doesn't represent chianxin's point of view . Reprint please indicate “ Transferred from Cheonan code guard https://codesafe.qianxin.com”.


Cheanson code guard (codesafe)
The first domestic product line focusing on software development security .

I think it's good , Just click on it. “ Looking at ” or " Fabulous ” Well ~
author : Cheanson code guard
Game programming , A game development favorite ~
If the picture is not displayed for a long time , Please use Chrome Kernel browser .
边栏推荐
- 完美洗牌问题
- Jilin University 22 spring March "technical economics" assignment assessment-00073
- JSP cannot be resolved to a type error reporting solution
- Work assessment of pharmacotherapeutics of Jilin University in March of the 22nd spring -00064
- opencv怎么安装?opencv下载安装教程
- Apple's legendary design team disbanded after jobs refused to obey cook
- Winxp kernel driver debugging
- zabbix的安装避坑指南
- Jilin University 22 spring March "official document writing" assignment assessment-00084
- Demonstration of combination of dream CAD cloud map and GIS
猜你喜欢

JSP cannot be resolved to a type error reporting solution

opencv是开源的吗?

俄罗斯AIRI研究院等 | SEMA:利用深度迁移学习进行抗原B细胞构象表征预测

腾讯开源项目「应龙」成Apache顶级项目:前身长期服务微信支付,能hold住百万亿级数据流处理...

BGP biplane architecture

2022-06-21-Flink-49(一. SQL手册)

ICML 2022 | ByteDance AI Lab proposes a multimodal model: x-vlm, learning multi granularity alignment of vision and language

Tensorflow, danger! Google itself is the one who abandoned it

opencv怎么安装?opencv下载安装教程

2点睡10点起不算熬夜?除非你每天都能执行
随机推荐
windows 2003 64位系统php运行报错:1% 不是有效的 win32 应用程序
Skywalking implements cross thread trace delivery
How to use crawlers to capture bullet screen and comment data of station B?
OpenSUSE environment PHP connection Oracle
Crawler crawls Sina Weibo data
JSP cannot be resolved to a type error reporting solution
Jilin University 22 spring March "career design" assignment assessment-00072
Sorting of poor cattle (winter vacation daily question 40)
Xidian AI ranked higher than Qingbei in terms of AI majors, and Nantah ranked the first in China in 2022 in terms of soft science majors
Time management understood after working at home | community essay solicitation
Perfect shuffle problem
【Harmony OS】【ARK UI】ETS 上下文基本操作
On the self-cultivation of an excellent red team member
The art of writing simple code
x86 CPU,危!最新漏洞引发热议,黑客可远程窃取密钥,英特尔“全部处理器”受影响...
Mstp+vrrp+ospf implements a three-tier architecture
Jilin University 22 spring March "official document writing" assignment assessment-00084
服乔布斯不服库克,苹果传奇设计团队解散内幕曝光
Amazon's other side in China
Jilin University 22 spring March new development English comprehensive course (I) assignment assessment-00080