Ä³ÍøÂç×°±¸¹©Ó¦ÉÌRoonServerȨÏÞÈÏÖ¤Îó²îÓëÏÂÁî×¢ÈëÎó²îÔ¤¾¯
Ðû²¼Ê±¼ä 2021-06-112021Äê5ÔÂ9ÈÕ£¬£¬£¬Æ¾Ö¤CNCERTÎïÁªÍøÍþвÇ鱨Êý¾Ýƽ̨µÄ¼à²âÏßË÷£¬£¬£¬ÍòÀû¹ú¼Ê¹ÙÍø¼¯ÍŽð¾¦Çå¾²Ñо¿ÍŶÓÁªºÏCNCERTÎïÁªÍøÇå¾²Ñо¿ÍŶӷ¢Ã÷2ÏîÁãÈÕÎó²îµÄÔÚҰʹÓÃÐÐΪ¡£¡£¡£¡£
¾È·ÈÏ£¬£¬£¬Õâ2ÏîÁãÈÕÎó²î¾ù±£´æÓÚÍþÁªÍ¨£¨QNAP£©²úÆ·µÄRoonServerÓ¦ÓÃÖУ¬£¬£¬»®·ÖÊÇȨÏÞÈÏÖ¤Îó²îÓëÏÂÁî×¢ÈëÎó²î£¬£¬£¬¹¥»÷Õß¿ÉÒÔ½«Õâ2¸öÎó²î×éºÏÆðÀ´Ê¹Ó㬣¬£¬ÒÔµÖ´ïδÊÚȨԶ³ÌÖ´ÐÐí§ÒâÏÂÁîµÄÄ¿µÄ¡£¡£¡£¡£
ÎÒÃǽ«Ïà¹ØµÄÎó²îÆÊÎö¡¢¸´ÏÖ±¨¸æÊµÊ±±¨Ë͸ø³§ÉÌQNAP£¬£¬£¬ÏÖÔÚ£¬£¬£¬QNAPÒÑÐÞ¸´¸ÃÎó²î£¬£¬£¬²¢Éý¼¶Ó¦ÓÃÈí¼þ¡£¡£¡£¡£
Îó²îÆÊÎö
ÍþÁªÍ¨¿Æ¼¼£¬£¬£¬¼ò³ÆÍþÁªÍ¨£¬£¬£¬Ó¢ÓïÒëÃûô߯·ÅÆÃû³ÆÎªQNAP£¬£¬£¬ÎªÒ»¼ä×ܲ¿Î»ÓÚÖйų́ÍåµÄ¿Æ¼¼¹«Ë¾¡£¡£¡£¡£Æä²úÆ·°üÀ¨ÍøÂ總¼Ó´æ´¢×°±¸¡¢ÊÓÆµ¼à¿ØÂ¼Ïñ×°±¸¡¢ÍøÂç½»Á÷»ú¡¢ÎÞÏß·ÓÉÆ÷¡¢ÎÞÏß/ÓÐÏßÍø¿¨ºÍÊÓÆµ¾Û»á×°±¸µÈ¡£¡£¡£¡£
Îó²îÔÀí
¡ôȨÏÞÈÆ¹ýÎó²î£¨CVE-2021-28810£©
ÓÉÓÚÓ¦ÓöԵǼȨÏÞµÄÑéÖ¤±£´æÎó²î£¬£¬£¬Ö»ÒªÄ³²ÎÊý±£´æÇÒÆäÖµ·Ç¿Õ£¬£¬£¬¼´¿ÉÈÆ¹ýµÇ¼ÑéÖ¤¡£¡£¡£¡£¹¥»÷Õß¿É×ÔÐÐ½á¹¹ÌØÊâµÄÇëÇó¾ÙÐÐÈÆ¹ý¡£¡£¡£¡£

¡ôÏÂÁî×¢ÈëÎó²î£¨CVE-2021-28811£©
µ±urlÖÐÖ¸¶¨µÄactionÎªÌØ¶¨ÖµÊ±£¬£¬£¬Ó¦ÓûáÎüÊÕÁíÒ»¸ö²ÎÊýµÄÖµ£¬£¬£¬¾ÓɼòÆÓµÄÈ¥³ý±êÇ©´¦Öóͷ£ºó£¬£¬£¬´«Èëset_db_pathº¯Êý¡£¡£¡£¡£¸ú×Ùset_db_pathº¯Êý£¬£¬£¬¿ÉÒÔ¿´µ½´Ëº¯Êý½«Æä²ÎÊýÖ±½ÓÆ´½Óµ½ÁËshell_execº¯ÊýÖÐÖ´ÐУ¬£¬£¬Ã»ÓÐÔÙ¾ÙÐÐÈκιýÂË¡£¡£¡£¡£

½«ÉÏÊöÁ½¸öÎó²îÅäºÏʹÓ㬣¬£¬¼´¿ÉÔì³ÉδÊÚȨµÄí§ÒâÏÂÁîÖ´ÐС£¡£¡£¡£
ÔÚÒ°¹¥»÷
ÎÒÃÇ»®·ÖÔÚ5ÔÂ8ÈÕÓë5ÔÂ18ÈÕ²¶»ñµ½Á½ÆðʹÓôËÎó²î¾ÙÐеÄÔÚÒ°¹¥»÷¡£¡£¡£¡£¾Ì«¹ýÎö£¬£¬£¬È·ÈϹ¥»÷ÕßʵÑéÖ²ÈëµÄÔØºÉΪeCh0raixÀÕË÷Èí¼þ¡£¡£¡£¡£
eCh0raixÒ²±»³ÆÎªQNAPCrypt£¬£¬£¬×îÔçÔÚ2019Äê·ºÆð£¬£¬£¬ÊÇÒ»¸ö»ùÓÚGoÓïÑÔ¡¢×¨ÃÅÕë¶ÔÍþÁªÍ¨×°±¸µÄÀÕË÷Èí¼þ¡£¡£¡£¡£ÔËÐк󣬣¬£¬»á¼ÓÃÜ×°±¸ÉÏ´æ´¢µÄÎļþ£¬£¬£¬¼ÓÃܺóÀ©Õ¹ÃûÊÇ.encrypt¡£¡£¡£¡£¼ÓÃÜÍê³Éºó£¬£¬£¬»¹»áÊÍ·ÅÒ»¸ö½ÐREADME_FOR_DECRYPT.txtµÄÎı¾Îļþ£¬£¬£¬ÌáÐÑÊܺ¦Õßͨ¹ýTORÖ§¸¶Êê½ð¡£¡£¡£¡£ÄÚÈÝ´óÖÂÈçÏ£º
All your data has been locked(crypted).
How to unlock(decrypt) instruction located in this TOR website:
http://veqlxhq7ub5qze3qy56zx2cig2e6tzsgxdspkubwbayqije6oatma6id.onion/order/xxx
Use TOR browser for access .onion websites.
ÆäÖÐXXXÊÇhash£¬£¬£¬ÓÃÀ´±ê¼ÇΨһµÄÊܺ¦Õߣ¬£¬£¬TORÖ§¸¶Êê½ðµÄÒ³ÃæÈçÏ£º

ÊÜÓ°Ïì¹Ì¼þ°æ±¾
QNAP RoonServer 2021-02-01¼°Ö®Ç°°æ±¾¡£¡£¡£¡£
Îó²î·¢Ã÷ʱ¼äÖá
? 2021Äê5ÔÂ9ÈÕ£¬£¬£¬ÎÒÃÇ·¢Ã÷Á˺ڿÍʹÓÃÍþÁªÍ¨×°±¸0DayÎó²îÈö²¥ÀÕË÷Èí¼þeCh0raixµÄ¹¥»÷ÐÐΪ¡£¡£¡£¡£
? 2021Äê5ÔÂ12ÈÕ£¬£¬£¬ÎÒÃÇÏò³§ÉÌ£¨QNAP£©µÄÇå¾²ÍŶӱ¨ËÍÁËÏêϸµÄÎó²îÆÊÎö¡¢¸´ÏÖ±¨¸æ£¬£¬£¬ÒÔ×ÊÖúËûÃÇÐÞ¸´²úÆ·¡£¡£¡£¡£
? 2021Äê5ÔÂ14ÈÕ£¬£¬£¬³§ÉÌÈ·ÈÏÎó²î±£´æ£¬£¬£¬½«Îó²îÓ¦ÓôÓapp centerϼܣ¬£¬£¬²¢×îÏÈ×ÅÊÖÐÞ¸´¡£¡£¡£¡£
? 2021Äê6ÔÂ04ÈÕ£¬£¬£¬³§ÉÌÐÞ¸´Íê³É£¬£¬£¬QNAP¹Ù·½ÖØÐÂÔÚapp centerÐû²¼ÐÞ¸´ºóµÄÓ¦Óᣡ£¡£¡£
? 2021Äê6ÔÂ08ÈÕ£¬£¬£¬¸üв¢È·ÈÏCVE±àºÅ¡£¡£¡£¡£
½â¾ö¼Æ»®
Éý¼¶Roon Serverµ½×îа汾£¬£¬£¬ÏêϸÇë¹Ø×¢QNAP¹Ù·½¹ØÓÚ´ËÎó²îµÄÐÞ¸´¼Æ»®¡£¡£¡£¡£
https://www.qnap.com.cn/zh-cn/security-advisory/qsa-21-17
£¨×¢£º±¾±¨¸æÓÉCNCERTÎïÁªÍøÇå¾²Ñо¿ÍŶÓÓëÍòÀû¹ú¼Ê¹ÙÍø¼¯ÍŽð¾¦Çå¾²Ñо¿ÍŶÓÅäºÏÐû²¼¡£¡£¡£¡££©


¾©¹«Íø°²±¸11010802024551ºÅ