QNAPã®NASããã¤ã¹ã使ç¨ãã¦ããå ´åã注æãå¿ è¦ã ãQNAP Systemsã5æ14æ¥(ç±³å½æé)ããeCh0raix Ransomware - Security Advisoryï½QNAPãã«ããã¦æ°ããã»ãã¥ãªãã£ã¢ããã¤ã¶ãªãçºè¡ãããã»ãã¥ãªãã£ã¢ããã¤ã¶ãªã«ããã¨ãQNAPã®NASããã¤ã¹ã¯eCh0raixã©ã³ãµã ã¦ã§ã¢ã®å½±é¿ãåããå¯è½æ§ãããã¨ããã QNAPã¯ã¦ã¼ã¶ã¼ã«å¯¾ãã次ã®ææé²æ¢çã®å®æ½ãå¼ã³ããã¦ããã 管çè ã¢ã«ã¦ã³ããããå¼·åãªãã¹ã¯ã¼ãã¸å¤æ´ãã IPã¢ã¯ã»ã¹ä¿è·æ©è½ãæå¹ã«ãããã«ã¼ããã©ã¼ã¹æ»æããã¢ã«ã¦ã³ããä¿è·ãã ããã©ã«ããã¼ãã§ãã443çªããã³8080çªã®ä½¿ç¨ãé¿ãã eCh0raix Ransomware - Security Advisoryï½QNAP ã»ãã¥ãªãã£ä¸ãå¼·ãã¨ãããããã¹ã¯ã¼ãã¯ãã¹ã¯ã¼ã管çã¢ããªãªã©ã使ããã¨ã§
QNAP Systems製ã®ãããã¯ã¼ã¯æ¥ç¶ã¹ãã¬ã¼ã¸ï¼NASï¼ãæ¨çã¨ãããã«ã¦ã§ã¢ãQSnatchãã®ææãåºãã£ã¦ããã¨ãã¦è±ç±³æ¿åºã®ã»ãã¥ãªãã£æ©é¢ã注æåèµ·ãè¡ã£ãããã¡ã¼ã ã¦ã§ã¢ã®æ´æ°ãé»å®³ããæ©è½ãåãã¦ãããå·¥å ´åºè·æã®ç¶æ ã¸ãªã»ããããã¨ãã£ã対çãå¼ã³ããããã¦ããã ã¯ã¼ã«ãã¯ã¤ãã«ãããæææ¡å¤§ãåãã¦ãµã¤ãã¼ã»ãã¥ãªãã£ã¤ã³ãã©ã¹ãã©ã¯ãã£ã»ãã¥ãªãã£åºï¼CISAï¼ã¨ã¤ã®ãªã¹ã®å½å®¶ãµã¤ãã¼ã»ãã¥ãªãã£ã»ã³ã¿ã¼ï¼NCSCï¼ãé£åã§æ³¨æåèµ·ãè¡ã£ããã®ã åé¡ã®ãQSnatchãã¯ãQNAP製NASåãã®OSãQTS OSããæ¨çã¨ãããã«ã¦ã§ã¢ããã¡ã¼ã ã¦ã§ã¢ã«ææããæ å ±ãçªåãã¦ã³ãã³ãï¼ã³ã³ããã¼ã«ï¼Cï¼Cï¼ãµã¼ãã¨éä¿¡ããããã£ã³ã©ã³ãã®å½ç«ãµã¤ãã¼ã»ãã¥ãªãã£ã»ã³ã¿ã¼ï¼NCSC-FIï¼ã2019å¹´10æã«ã¬ãã¼ããå ¬è¡¨ããæããã¨ãªã£ãã ååé¡ãåãã¦Q
é¢é£ãã¼ã¯ã¼ã NAS | ã»ãã¥ãªã㣠| ã¯ã©ã¦ããµã¼ãã¹ | ãããã¯ã¼ã¯ã»ã»ãã¥ãªã㣠| ã»ãã¥ãªãã£ãªã¹ã¯ | ã»ãã¥ãªãã£å¯¾ç æè¡ã®çºå±ã¯ãã¸ãã¹ã«å©çãããããã ãã§ãªãããµã¤ãã¼æ»æã®å·§å¦åãæããåç·¨ãâä½ã§ãããã§ããIoTãåâãå±éºãªããã ãã®æ ¹æ ãããã³ä¸ç·¨ãã5GããRPAããAIãã¯ãªãå±éºãªã®ãï¼ããªã¹ã¯ãçã¾ããåå ã解説ãã§ç´¹ä»ããããã«ãæ»æè ã¯IoTï¼ã¢ãã®ã¤ã³ã¿ã¼ãããï¼ãRPAï¼ãããã£ãã¯ããã»ã¹ãªã¼ãã¡ã¼ã·ã§ã³ï¼ã¨ãã£ãæ°ããªæè¡ã®èå¼±ï¼ãããããï¼æ§ãçããæ»æãåããããæè¡ã«ã¯ãä»ã«ã©ã®ãããªãã®ãããã ãããã ãªãNASãçãããã®ã
ã¢ã¤ã»ãªã¼ã»ãã¼ã¿æ©å¨ã®NASï¼ãããã¯ã¼ã¯æ¥ç¶ã¹ãã¬ã¼ã¸ï¼ã«æ°ã¢ãã«ãHDL2-HA/TMãã·ãªã¼ãºãç»å ´ããããã¬ã³ããã¤ã¯ã社ã®NASåãã¦ã¤ã«ã¹å¯¾çãµã¼ãã¹ãTrend Micro NAS Securityãã®5å¹´åã©ã¤ã»ã³ã¹ãä»å±ããã¦ã¤ã«ã¹ã«ææãããã¡ã¤ã«ã社å ã«æ¡æ£ãè延ãããã¨ãé²ãã ã¦ã¤ã«ã¹ã®ä¾µå ¥ããªã¢ã«ã¿ã¤ã ã«ç£è¦ããä¸ãä¸ã¦ã¤ã«ã¹å¯¾çã®ä¸ååãªPCããããã¯ã¼ã¯ã«æ¥ç¶ããã¦ã¤ã«ã¹ææãããã¡ã¤ã«ãNASã«è»¢éããå ´åããéããã«ãã¡ã¤ã«ãé§é¤ãã¦ã¤ã«ã¹ã®è延ãé²ãã ã¾ã10GbE対å¿ã®LANãã¼ããæ¨æºæè¼ããé«éãªãã¼ã¿è»¢éãLANã«ã¼ãã®è¿½å å¢è¨ãªãå©ç¨ã§ããã大容éã®ãã¼ã¿ãã¹ãã¬ã¹ãªãé²è¦§ãç·¨éã§ããã ããã«å ããå±¥æ´å·®åããã¯ã¢ãããæ©è½ãå¿ç¨ããã©ã³ãã£ã¹ã¯å é¨ã¾ãã¯USBãã¼ããã£ã¹ã¯ã¸ããã¯ã¢ãããããã¼ã¿ããWindowsæ¨æºã®ã¤ã³ã¿ã¼ãã§ã¼
QNAP Systemsã¯ãå社製NAS製åã«å½±é¿ãä¸ãããã«ã¦ã§ã¢ã®å ±åãåãã¦ããã¨ãã¦ã解æãé²ãã¦ãããå社ã§ã¯ã§ããã ãæ©æ¥ã«å¯¾çãæä¾ãããèãã ã å社NAS製åã§æ¡ç¨ããã¦ããå°ç¨OSãQTSãã«å½±é¿ãåã¼ããã«ã¦ã§ã¢ã«ã¤ãã¦å ±åãåãã¦ããã¨ãã¦ãã¢ããã¤ã¶ãªãå ¬è¡¨ãããã®ã èå¼±æ§ã示ãCVEçªå·ã¯æ¡çªããã¦ããªãããå社ã§ã¯ã¢ããã¤ã¶ãªã®éè¦åº¦ããé«ï¼Highï¼ãã¨ã¬ã¼ãã£ã³ã°ãã¦ãããç·©åçãã¢ãã¦ã³ã¹ããã å ·ä½çã«ã¯ããMalware RemoverããåOSãNASã«ã¤ã³ã¹ãã¼ã«ããã¦ããã¢ããªã±ã¼ã·ã§ã³ãææ°ã®ç¶æ ã«ä¿ã¤ããå¼ã³ããã¦ããããã ãããMalware Removerãã®ã¢ãããã¼ãä¸ã«åé¡ãçããå ´åã¯ã対çãå¾ ã¤ããæ±ããã ã¾ãä»åã®åé¡ã«ã¤ãã¦ãJPCERTã³ã¼ãã£ãã¼ã·ã§ã³ã»ã³ã¿ã¼ã¯ãå ¬éãããå 容以å¤ã®æ å ±ã¯å¾ã¦ããªãã¨èª¬æãéçºå ã
Thecusï¼ã·ã¼ã«ã¹ï¼ã¯ãå°æ¹¾ã§ä¸»ã«ã¹ãã¬ã¼ã¸æ©å¨ãæããã¦ããã¡ã¼ã«ã¼ã ã大ä¼æ¥åãã®ã©ãã¯ãã¦ã³ãåã¹ãã¬ã¼ã¸ãããã¿ã¯ã¼åã®NASã±ã¼ã¹ããã¼ã ã»SOHOåãã®å¤ä»ãHDDã±ã¼ã¹ã¾ã§å¹ åºãæããã¦ããããã®ä¸ã§ã1æã«çºå£²ããã5ãã¤ã®NASã±ã¼ã¹ãN5810ãã¨ãW5810ãã¯ãç°¡åãªè¨å®ã§ä½¿ããã®ãç¹å¾´ã ã Thecusã®ãN5810ãã¨ãW5810ãã¯5ã¤ã®HDDãã¤ãæã¤NASã±ã¼ã¹ã ãä»åã¯ä¸ä½ã¢ãã«ã®ãN5810PROãï¼åçï¼ã§ãã®æ©è½ã確ããã¦ã¿ãããN5810ãã¯LANãã¼ãã®æ°ãªã©ä¸é¨ãé¤ãã¦åãæ©è½ãæã¡ãåé¢ã®ãã¶ã¤ã³ãåãã ãã¼ã¿ã®ä¿åã«å°ã£ããNASãä¾¿å© ãã¸ã¿ã«ã«ã¡ã©ã使ã£ã¦ãã¦ãæ®å½±ããåçãã¡ã¤ã«ã®ä¿åã«é ãæ©ã¾ãã¦ãã人ã¯å¤ãã ãããJPEGå½¢å¼ã§ãåç1æã§æ°MBãã10MB以ä¸ã«ãªãã®ã§ãæ²¹æãã¦ããã¨ãã½ã³ã³ã®HDDããããã£ã±ãã«ãªã£
ä¸çã®ã»ãã¥ãªãã£ã»ãã³ãã¼ã®ããã°ãããæ¼ããã¦ãããã話é¡ãããã¯ã¢ãããã¦ç´¹ä»ãããä»åã¯æ¥çãè³ããããShellshockãã«é¢ããå¾ç¶ã®è¨äºããç´¹ä»ãããã Shellshockã¯ãLinuxãªã©UNIXãã¼ã¹ã®OSã§åºã使ããã¦ããã·ã§ã«ãBashãã«è¦ã¤ãã£ãèå¼±æ§ã§ãããå®éã«æ»æãããäºä¾ãããã¤ãå ±åãããããã«è¤æ°ã®èå¼±æ§ãBashã§ç¢ºèªãããããã¬ã³ããã¤ã¯ããå½ããã°ãå·çããæç¹ï¼10æ2æ¥ç¾å¨ï¼ã§ãShellshockã«é¢é£ãã6件ã®CVEï¼èå¼±æ§èå¥åï¼ãå ¬éããã¦ããã åé¡ã®èå¼±æ§ãå©ç¨ããé éæ»æã¯ãå ¥åå¤ãé¢æ°ãç°å¢å¤æ°ã«å²ãå½ã¦ãããã¨ããBashã®æ¢ç¥ã®æ©è½ã¨é¢ä¿ãã¦ããã ãããã®ãã°ã¯ãã·ã³ã¿ãã¯ã¹ã() {ãã§å§ã¾ãé¢æ°å®ç¾©ã¨çµã³ã¤ãã¦ãããä¾ãã°ã³ãã³ããenv -i x='() { :;}; echo vulnerable' bash
[NEW] 2014/09/30: ã¢ãã©ã¤ã¢ã³ã¹ã®å¯¾å¿ç¶æ³ã¾ã¨ããéææ´æ°ä¸ CVE-2014-6271åã³CVE-2014-7169ãã(Bashèå¼±æ§)ã ä¸éã§ã¯ãå¤é¨å ¬éãµã¼ãã¼(ç¹ã«Webãµã¼ãã¼)ã¸ã®å¯¾å¦ãçã ã¨é²ãããã¦ãã¾ããWebãµã¼ãã¼ã ãã§ãªããã¡ã¼ã«ãµã¼ãã¼ã¸ã®æ»æãã¿ã¼ã³ãæ©æã«è¦ä»ãã£ã¦ãã¾ããå¤é¨å ¬éãµã¼ãã¼ã«å¯¾ããç·åçãªç¹æ¤ãè¿ããã¡ã«é²ãã§ãããã®ã¨æããã¾ãã bash Shellshock through MAIL .forward / qmail-alias piping (ML program etc.) CVE-2014-6271 http://t.co/QPbSE8dppM http://t.co/AFuHudkCdh September 26, 2014ããããä¸è¬çãªãµã¼ãã¼é¡ã ãã§ãªã主ã«ãã¡ã¤ã¢ã¦ã©ã¼ã«ã®å é¨ã«è¨ç½®ããã¦ããã¢ãã©ã¤
家ã«ä½¿ãå¤ããPCããããã ãã©ãããã§ãã¼ã ãµã¼ãã¼ã§ãä½ããªãããª...ï¼ããªãã¦äººã«ã´ã£ããã®ã¢ããªãããã¾ãããã㯠ãAmahiãï¼ Amahiã¯ãã©ããªPCã§ããã¼ã VPNããã¼ã NASãã¡ãã£ã¢ã¹ããªã¼ãã¼ã«å¤ãã¦ãã¾ãéæ³ã®ã¢ããªã§ãã Amahiã¨ã¯ï¼ Amahi ã¯ã Fedora Linux ããã¼ã¹ã¨ããããªã¼ãã³ã½ã¼ã¹ã®ãã¼ã ãµã¼ãã¼ã»ã½ããã¦ã§ã¢ã§ããæè»ã§ã«ã¹ã¿ãã¤ãºæ§ã«å¯ã¿ãã¤ã³ã¹ãã¼ã«ãç°¡åããã©ã°ã¤ã³ãæ¡å¼µæ©è½ãã¢ããªã³ã½ããã¦ã§ã¢ãæã£ã¦ãã¾ããã¢ãã¤ã«ããã¤ã¹ã¸ã¡ãã£ã¢ã¹ããªã¼ãã³ã°ãããããªããAmahi ããã¼ãã§ã¯ããªçãã§ããããèªåã®ãã¡ã¤ã«ãµã¼ãã¼ã NAS ãæ§ç¯ãããï¼ããªãã° Amahi ã§ããå¤åºå ãããã¼ã ãããã¼ã¯ã¼ã¯ã«å®å ¨ã«æ¥ç¶ã§ãã VPN ãæ§ç¯ãããï¼ããªãã° Amahi ã§å®ç§ã詳ããã¯ãAmahi ã®æ©è½ä¸è¦§ããã
Gigabyteãæ大4å°ã¾ã§ã®2.5ã¤ã³ããã¼ããã£ã¹ã¯ãæè¼å¯è½ãª Android NAS ã¡ãã£ã¢ãµã¼ãã¼ãBrix Maxãçºè¡¨ Gigabyte Brix Max å°æ¹¾ã¡ã¼ã«ã¼ Gigabyte ã¯ãã¤ã³ãã«ããã»ããµ Core i5 㨠Android OS ãæè¼ãããããã¯ã¼ã¯ã¡ãã£ã¢ãµã¼ãã¼ã«ããªã NAS 製åãBrix Maxããçºè¡¨ãæ大4å°ã® SATA ãã¼ããã£ã¹ã¯ãæè¼å¯è½ã§ Raid æ§æã«ã対å¿ã â ã¹ãã㯠OS: Android OS ãã¼ã¹ CPU: Intel Core i5-4250U âHaswellâ GPU: Intel HD 5000 Graphics RAM: DDR3L-1600 å¯¾å¿ (ã¹ããã2ã¤) Strage: SATA HDD x4 ãµã¤ãº: 120Ã112Ã90mm (å®¹ç© 1.2L) ç»é¢åºå: HDMI éä¿¡: Wi
ã©ã³ãã³ã°
ã©ã³ãã³ã°
ã©ã³ãã³ã°
ãªãªã¼ã¹ãé害æ å ±ãªã©ã®ãµã¼ãã¹ã®ãç¥ãã
ææ°ã®äººæ°ã¨ã³ããªã¼ã®é ä¿¡
å¦çãå®è¡ä¸ã§ã
j次ã®ããã¯ãã¼ã¯
kåã®ããã¯ãã¼ã¯
lãã¨ã§èªã
eã³ã¡ã³ãä¸è¦§ãéã
oãã¼ã¸ãéã
{{#tags}}- {{label}}
{{/tags}}