QTS

QTS 是入门到中阶 QNAP NAS 使用的操作系统,采用 Linux 核心及 ext4 文件系统,让每个人轻松享有可靠的存储空间,并体验多样的加值功能及应用,例如快照及 Plex 媒体服务器,此外,免费的 myQNAPcloud 服务更可让您快速便利地存取个人私有云。

系统
应用

QuTScloud

QuTScloud 是 QNAP 云 NAS 虚拟设备的操作系统。QuTScloud 可供部署在公有云及本地 Hypervisor,让您优化云端数据运用及灵活分配资源,且订阅成本清楚可预估。

系统
应用

QES

QES 是双控制器 QNAP NAS 使用的操作系统,采用 FreeBSD 核心及 ZFS 文件系统,并针对 SSD 进行优化,能带来超卓的全快闪数组性能。

系统
产品
资源

QNE Network

QNE Network 是 QNAP 的通用客户端设备 (uCPE) 产品 QuCPE 采用的操作系统。您可在 QNE Network 上执行虚拟化网络功能 (VNF)、自由配置软件定义网络 (SD-WAN) 并享受多重优势,例如更合宜的成本,以及更少的管理投入。

系统
应用

QSS

QSS 是 QNAP 的网管型交换机的管理接口。您可快速启用及配置多种网管功能,包括链路聚合 (LACP)、VLAN 及 RSTP,轻松管理您的局域网络架构。

系统

QuRouter

QuRouter 路由器管理系统专为 QNAP 路由器量身打造,帮助您轻松管理高速、高覆盖率的有线无线网络,并执行 NAT、VPN、安全性与 QuWAN SD-WAN 等进阶功能。网络管理化繁为简,远程联机更加安全。

系统
应用

QVR Surveillance

QVR Surveillance 是 QNAP 网络录像监控主机 (NVR) 解决方案,提供订阅制 QVR Elite 及买断制 QVR Pro 软件,可搭配一系列软件使用,包括人脸识别及门禁管理等,让运用更广泛多元。

系统
应用
资源

QVR Face

QVR Face 是一套智慧人脸辨识解决方案,可实时分析来自联机摄像机的实时影像串流。QVR Face 更可整合多种应用场景,进行智慧考勤管理、门禁控制管理、VIP 人员提示系统及智能零售服务等。

系统
应用
资源

KoiMeeter

QNAP 智能影像解决方案提供多种不同的智能型整合解决方案,例如视频会议及智慧零售等,让个人及企业生产力获得显著提升。

视频会议
智慧零售

安全ID : QSA-22-24

DeadBolt Ransomware


  • 发布日期 : September 3, 2022

  • 通用漏洞披露 : CVE-2022-27593

  • 受影响产品: Certain QNAP NAS running Photo Station with internet exposure

严重程度

严重

状态

已解决


Summary

QNAP detected a new DeadBolt ransomware campaign on the morning of September 3rd, 2022 (GMT+8). The campaign appears to target QNAP NAS devices running Photo Station with internet exposure.

We have already fixed the vulnerability in the following versions: 

  • QTS 5.0.1: Photo Station 6.1.2 and later
  • QTS 5.0.0/4.5.x: Photo Station 6.0.22 and later
  • QTS 4.3.6: Photo Station 5.7.18 and later
  • QTS 4.3.3: Photo Station 5.4.15 and later
  • QTS 4.2.6: Photo Station 5.2.14 and later

Recommendation

To protect your NAS from the DeadBolt ransomware, QNAP strongly recommends securing your QNAP NAS devices and routers by following these instructions:

  1. Disable the port forwarding function on the router.
  2. Set up myQNAPcloud on the NAS to enable secure remote access and prevent exposure to the internet.
  3. Update the NAS firmware to the latest version.
  4. Update all applications on the NAS to their latest versions.
  5. Apply strong passwords for all user accounts on the NAS.
  6. Take snapshots and back up regularly to protect your data.

Setting Up myQNAPcloud on the NAS

  1. Log on to QTS as an administrator.
  2. Open myQNAPcloud.
  3. Disable UPnP port forwarding.
    1. Go to Auto Router Configuration.
    2. Deselect Enable UPnP Port forwarding.
  4. Enable DDNS.
    1. Go to My DDNS.
    2. Click the toggle button to enable My DDNS.
  5. Do not publish your NAS services.
    1. Go to Published Services.
    2. Deselect all items under Publish.
    3. Click Apply.
  6. Configure myQNAPcloud Link to enable secure remote access to your NAS via a SmartURL.
    1. Go to myQNAPcloud Link.
    2. Click Install to install myQNAPcloud Link on your NAS.
    3. Click the toggle button to enable myQNAPcloud Link.
  7. Restrict which users can remotely access your NAS via the SmartURL.
    1. Go to Access Control.
    2. Next to Device access controls, select Private or Customized.
      Note: Selecting Private allows only the QNAP ID logged in to myQNAPcloud to access the NAS via the SmartURL. Selecting Customized allows you to invite other QNAP ID accounts to access the device via the SmartURL.
    3. If you selected Customized, click Add and specify a QNAP ID to invite the user.
  8. Obtain the SmartURL by going to Overview.
    For questions on using myQNAPcloud, visit https://support.myqnapcloud.com/.

Updating QTS

  1. Log on to QTS as an administrator.
  2. Go to Control Panel > System > Firmware Update.
  3. Under Live Update, click Check for Update.
    QTS downloads and installs the latest available update.
    Tip: You can also download the update from the QNAP website. Go to Support > Download Center and then perform a manual update for your specific device.

Updating All Applications

  1. Log on to QTS as an administrator.
  2. Open App Center.
  3. Locate Install Updates in the top-right corner of the window.
  4. Click All.
    A confirmation message appears.
  5. Click OK.
    QTS installs the latest versions of all applications.

Updating Photo Station

  1. Log on to QTS as administrator.
  2. Open the App Center and then click  .
    A search box appears.
  3. Enter "Photo Station".
    Photo Station appears in the search results.
  4. Click Update.
    A confirmation message appears.
    Note: The Update button is not available if your version is already up to date.
  5. Click OK.
    The application is updated.

修订历史:
V1.0 (September 3, 2022) - Published
V1.1 (September 8, 2022) - Assign CVE ID

选择规格

      显示更多 隐藏更多
      open menu
      back to top