Results 1 to 12 of 12

Thread: Warning - Synolocker - Cryptolocker for NASes [Synology]

  1. #1
    Chaos Monkey Apex's Avatar
    Join Date
    Jul 2003
    Location
    Huddersfield
    Posts
    4,709
    Thanks
    1,143
    Thanked
    285 times in 204 posts
    • Apex's system
      • Motherboard:
      • Asus Z87M-PLUS
      • CPU:
      • Intel i5-4670K
      • Memory:
      • 32 GiB
      • Storage:
      • 20 TiB
      • Graphics card(s):
      • PowerColor Radeon RX 6700 Fighter 10GB OC
      • PSU:
      • 750
      • Case:
      • Core View 21
      • Operating System:
      • Windows 10 pro
      • Monitor(s):
      • Dell S2721DGFA
      • Internet:
      • 200Mb nTL Cable

    Warning - Synolocker - Cryptolocker for NASes [Synology]

    Just a heads up for any of us here on HeXus that might be running a Synology NAS unit, there is a nasty bit of ransomware out there that is going after us.

    I've taken the option to shut all remote access to my NAS unit off bar access from my own pc and the WDTVLive downstairs till we get more information on what is going off.

    https://www.facebook.com/synology/po...857897?fref=nf

    More info

    http://www.geekzone.co.nz/forums.asp...0814&page_no=1
    Last edited by Apex; 05-08-2014 at 01:18 PM.

  2. #2
    ɯʎɔɐɹsɐʌʍ mycarsavw's Avatar
    Join Date
    Feb 2007
    Posts
    4,945
    Thanks
    1,097
    Thanked
    652 times in 481 posts
    • mycarsavw's system
      • Motherboard:
      • P8H77-M Pro
      • CPU:
      • i5 3350P
      • Memory:
      • 16Gb
      • Storage:
      • Lots
      • Graphics card(s):
      • R9 285
      • PSU:
      • HX 620w
      • Case:
      • FD Define Mini
      • Operating System:
      • W10
      • Monitor(s):
      • BenQ G2420HDBL + GL2450HT
      • Internet:
      • Sky

    Re: Warning - Synolocker - Cryptolocker for NASes [Synology]

    I've got four of these in use. Three are behind a hardware firewall (Smoothwall) and one is locked fairly tightly.

    Hopefully I'm safe for now
    |Kata: "Read title as 'fisting'. Not sure why I clicked. Relieved, really."|
    |TAKTAK: "It was so small that mine wouldn't fit into it"|

  3. #3
    Splash
    Guest

    Re: Warning - Synolocker - Cryptolocker for NASes [Synology]

    As I said in the other thread: why would anyone expose a NAS to the internet?

  4. #4
    ɯʎɔɐɹsɐʌʍ mycarsavw's Avatar
    Join Date
    Feb 2007
    Posts
    4,945
    Thanks
    1,097
    Thanked
    652 times in 481 posts
    • mycarsavw's system
      • Motherboard:
      • P8H77-M Pro
      • CPU:
      • i5 3350P
      • Memory:
      • 16Gb
      • Storage:
      • Lots
      • Graphics card(s):
      • R9 285
      • PSU:
      • HX 620w
      • Case:
      • FD Define Mini
      • Operating System:
      • W10
      • Monitor(s):
      • BenQ G2420HDBL + GL2450HT
      • Internet:
      • Sky

    Re: Warning - Synolocker - Cryptolocker for NASes [Synology]

    Synology bundle a whole heap of packages with their NASes some of which require outside access - See here > https://www.synology.com/en-uk/dsm/app_packages

    My backups are piped from an onsite NAS to an offsite NAS but I use a VPN. Others, like the chap who went on to twitter to complain, have SMB and AFP wide open without (at least in his case) knowing. Quite how they've managed to do that is beyond me though.
    |Kata: "Read title as 'fisting'. Not sure why I clicked. Relieved, really."|
    |TAKTAK: "It was so small that mine wouldn't fit into it"|

  5. #5
    Chaos Monkey Apex's Avatar
    Join Date
    Jul 2003
    Location
    Huddersfield
    Posts
    4,709
    Thanks
    1,143
    Thanked
    285 times in 204 posts
    • Apex's system
      • Motherboard:
      • Asus Z87M-PLUS
      • CPU:
      • Intel i5-4670K
      • Memory:
      • 32 GiB
      • Storage:
      • 20 TiB
      • Graphics card(s):
      • PowerColor Radeon RX 6700 Fighter 10GB OC
      • PSU:
      • 750
      • Case:
      • Core View 21
      • Operating System:
      • Windows 10 pro
      • Monitor(s):
      • Dell S2721DGFA
      • Internet:
      • 200Mb nTL Cable

    Re: Warning - Synolocker - Cryptolocker for NASes [Synology]

    The quick connection app more then likely if you let it will open a hell of a lot of ports out to the router.....

  6. #6
    Chaos Monkey Apex's Avatar
    Join Date
    Jul 2003
    Location
    Huddersfield
    Posts
    4,709
    Thanks
    1,143
    Thanked
    285 times in 204 posts
    • Apex's system
      • Motherboard:
      • Asus Z87M-PLUS
      • CPU:
      • Intel i5-4670K
      • Memory:
      • 32 GiB
      • Storage:
      • 20 TiB
      • Graphics card(s):
      • PowerColor Radeon RX 6700 Fighter 10GB OC
      • PSU:
      • 750
      • Case:
      • Core View 21
      • Operating System:
      • Windows 10 pro
      • Monitor(s):
      • Dell S2721DGFA
      • Internet:
      • 200Mb nTL Cable

    Re: Warning - Synolocker - Cryptolocker for NASes [Synology]


  7. #7
    Senior Member
    Join Date
    Feb 2006
    Posts
    1,773
    Thanks
    104
    Thanked
    76 times in 69 posts
    • pp05's system
      • Motherboard:
      • AsRock Fatal1ty B450 Gaming itx
      • CPU:
      • Ryzen 3 2200G
      • Memory:
      • Ballistix Elite 8GB Kit 3200 UDIMM
      • Storage:
      • Kingston 240gb SSD
      • PSU:
      • Kolink SFX 350W PSU
      • Case:
      • Kolink Sattelite plus MITX
      • Operating System:
      • Windows 10

    Re: Warning - Synolocker - Cryptolocker for NASes [Synology]

    Thanks man.

    I've turned mine off until I get home and close all open ports that it requires. Hopefully a patch will be released in due course.

    Quote Originally Posted by Apex View Post
    Just a heads up for any of us here on HeXus that might be running a Synology NAS unit, there is a nasty bit of ransomware out there that is going after us.

    I've taken the option to shut all remote access to my NAS unit off bar access from my own pc and the WDTVLive downstairs till we get more information on what is going off.

    https://www.facebook.com/synology/po...857897?fref=nf

    More info

    http://www.geekzone.co.nz/forums.asp...0814&page_no=1

  8. #8
    Chaos Monkey Apex's Avatar
    Join Date
    Jul 2003
    Location
    Huddersfield
    Posts
    4,709
    Thanks
    1,143
    Thanked
    285 times in 204 posts
    • Apex's system
      • Motherboard:
      • Asus Z87M-PLUS
      • CPU:
      • Intel i5-4670K
      • Memory:
      • 32 GiB
      • Storage:
      • 20 TiB
      • Graphics card(s):
      • PowerColor Radeon RX 6700 Fighter 10GB OC
      • PSU:
      • 750
      • Case:
      • Core View 21
      • Operating System:
      • Windows 10 pro
      • Monitor(s):
      • Dell S2721DGFA
      • Internet:
      • 200Mb nTL Cable

    Re: Warning - Synolocker - Cryptolocker for NASes [Synology]

    Just a quick update:

    Based on our current observations, this issue only affects Synology NAS servers running some older versions of DSM (DSM 4.3-3810 or earlier), by exploiting a security vulnerability that was fixed and patched in December, 2013. At present, we have not observed this vulnerability in DSM 5.0.

    For Synology NAS servers running DSM 4.3-3810 or earlier, and if users encounter any of the below symptoms, we recommend they shut down their system and contact our technical support team here: https://myds.synology.com/support/support_form.php.

    When attempting to log in to DSM, a screen appears informing users that data has been encrypted and a fee is required to unlock data.
    A process called “synosync” is running in Resource Monitor.
    DSM 4.3-3810 or earlier is installed, but the system says the latest version is installed at Control Panel > DSM Update.

    For users who have not encountered any of the symptoms stated above, we highly recommend downloading and installing DSM 5.0, or any version below:

    For DSM 4.3, please install DSM 4.3-3827 or later
    For DSM 4.1 or DSM 4.2, please install DSM 4.2-3243 or later
    For DSM 4.0, please install DSM 4.0-2259 or later

    DSM can be updated by going to Control Panel > DSM Update. Users can also manually download and install the latest version from our Download Center here: http://www.synology.com/support/download.

    If users notice any strange behaviour or suspect their Synology NAS server has been affected by the above issue, we encourage them to contact us at security@synology.com, where a dedicated team will look into their case.

    We sincerely apologise for any problems or inconvenience this issue has caused our users.


    CVE here

    Going from the Syno forum post, the CVE behind this exploit appears to be this one:

    http://www.rapid7.com/db/modules/exp...ad_exec_noauth

    No authentication required, dumps a file on the local system and then executes it as root apparently. Do the synology web services run as root?! Seriously... that's like eggs 101, Woodhouse.

  9. #9
    Senior Member
    Join Date
    Feb 2006
    Posts
    1,773
    Thanks
    104
    Thanked
    76 times in 69 posts
    • pp05's system
      • Motherboard:
      • AsRock Fatal1ty B450 Gaming itx
      • CPU:
      • Ryzen 3 2200G
      • Memory:
      • Ballistix Elite 8GB Kit 3200 UDIMM
      • Storage:
      • Kingston 240gb SSD
      • PSU:
      • Kolink SFX 350W PSU
      • Case:
      • Kolink Sattelite plus MITX
      • Operating System:
      • Windows 10

    Re: Warning - Synolocker - Cryptolocker for NASes [Synology]

    That's a relief, I installed 5.0 when installing it.

  10. #10
    SUMMONER
    Guest

    Re: Warning - Synolocker - Cryptolocker for NASes [Synology]

    Am I correct in saying that this exploit only immediately affects those who have their NAS set as the DMZ on the router/do not use NAT?

  11. #11
    Chaos Monkey Apex's Avatar
    Join Date
    Jul 2003
    Location
    Huddersfield
    Posts
    4,709
    Thanks
    1,143
    Thanked
    285 times in 204 posts
    • Apex's system
      • Motherboard:
      • Asus Z87M-PLUS
      • CPU:
      • Intel i5-4670K
      • Memory:
      • 32 GiB
      • Storage:
      • 20 TiB
      • Graphics card(s):
      • PowerColor Radeon RX 6700 Fighter 10GB OC
      • PSU:
      • 750
      • Case:
      • Core View 21
      • Operating System:
      • Windows 10 pro
      • Monitor(s):
      • Dell S2721DGFA
      • Internet:
      • 200Mb nTL Cable

    Re: Warning - Synolocker - Cryptolocker for NASes [Synology]

    Quote Originally Posted by SUMMONER View Post
    Am I correct in saying that this exploit only immediately affects those who have their NAS set as the DMZ on the router/do not use NAT?
    Not sure, they arn't really forthcoming on how the units are getting owned.

  12. Received thanks from:


  13. #12
    Banhammer in peace PeterB kalniel's Avatar
    Join Date
    Aug 2005
    Posts
    31,039
    Thanks
    1,880
    Thanked
    3,379 times in 2,716 posts
    • kalniel's system
      • Motherboard:
      • Gigabyte Z390 Aorus Ultra
      • CPU:
      • Intel i9 9900k
      • Memory:
      • 32GB DDR4 3200 CL16
      • Storage:
      • 1TB Samsung 970Evo+ NVMe
      • Graphics card(s):
      • nVidia GTX 1060 6GB
      • PSU:
      • Seasonic 600W
      • Case:
      • Cooler Master HAF 912
      • Operating System:
      • Win 10 Pro x64
      • Monitor(s):
      • Dell S2721DGF
      • Internet:
      • rubbish

    Re: Warning - Synolocker - Cryptolocker for NASes [Synology]

    In related news, they've got the database of keys for the original Cryptolocker so you now unlock if you get hit:

    http://www.bbc.co.uk/news/technology-28661463

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •