[SECURITY ADVISORY] Security Advisory for Malware on QTS - NAS-201902-13

Introduce yourself to us and other members here, or share your own product reviews, suggestions, and tips and tricks of using QNAP products.
Post Reply
User avatar
Toxic17
Ask me anything
Posts: 6477
Joined: Tue Jan 25, 2011 11:41 pm
Location: Planet Earth
Contact:

[SECURITY ADVISORY] Security Advisory for Malware on QTS - NAS-201902-13

Post by Toxic17 »

Security Advisory for Malware on QTS
Release date: February 13, 2019
Security ID: NAS-201902-13
Severity: High
CVE identifier: N/A
Affected products: To be confirmed
Summary
A recently reported malware is known to affect QNAP NAS devices. We are currently analyzing the malware and will provide the solution as soon as possible.

If you have any questions regarding this issue, please contact us through the QNAP Helpdesk.

Recommendation
To avoid possible exploits, you must:

Manually update Malware Remover to the latest version.
Update QTS to the latest version.
Update all apps installed on your NAS.
In case you encounter problems or receive the following error message while updating Malware Remover, please wait for the solution:

[App Center] Failed to install MalwareRemover. Model does not support MalwareRemover.

Manually Installing and Running the Latest Version of Malware Remover
On your web browser, go to the QNAP App Center.
Select your QTS version.
The application list appears.
Locate and click Malware Remover.
The Malware Remover download window appears.
Identify your processor type, and then click Download.
Your system downloads the installer zip file.
Extract the installer file.
Log on to QTS as administrator.
Open App Center, and then click .
The manual installation dialog box appears.
Read the instructions, and then click Browse.
The file broswer appears.
Locate and select the installer file.
Click Install.
A confirmation message appears.
Click OK.
QTS installs the latest version of Malware Remover.
A confirmation message appears.
Click OK.
The required updates dialog box appears.
Click Update Now.
QTS updates Malware Remover to the latest version.
Open Malware Remover.
Click Start Scan.
Malware Remover scans the NAS for malware.
Installing the QTS Update
Log on to QTS as administrator.
Go to Control Panel > System > Firmware Update.
Under Live Update, click Check for Update.
QTS downloads and installs the latest available update.
Updating All NAS Applications
Log on to QTS as administrator.
Open App Center.
Locate Install Updates on the upper right corner of the screen.
Click All.
A confirmation message appears.
Click OK.
QTS updates all installed applications.


Revision History: V1.0 (February 13, 2019) - Published
Regards Simon

Qnap Downloads
MyQNap.Org Repository
Submit a ticket • QNAP Helpdesk
QNAP Tutorials, User Manuals, FAQs, Downloads, Wiki
When you ask a question, please include the following


NAS: TS-673A QuTS hero h5.1.2.2534 • TS-121 4.3.3.2420 • APC Back-UPS ES 700G
Network: VM Hub3: 500/50 • UniFi UDM Pro: 3.2.9 • UniFi Network Controller: 8.0.28
USW-Aggregation: 6.6.61 • US-16-150W: 6.6.61 • 2x USW Mini Flex 2.0.0 • UniFi AC Pro 6.6.62 • UniFi U6-LR 6.6.62
UniFi Protect: 2.11.21/8TB Skyhawk AI • 3x G3 Instants: 4.69.55 • UniFi G3 Flex: 4.69.55 • UniFi G5 Flex: 4.69.55
User avatar
Toxic17
Ask me anything
Posts: 6477
Joined: Tue Jan 25, 2011 11:41 pm
Location: Planet Earth
Contact:

Re: [SECURITY ADVISORY] Security Advisory for Malware on QTS - NAS-201902-13

Post by Toxic17 »

Still this advisory has not yet been updated.
Affected products: To be confirmed

Revision History: V1.0 (February 13, 2019) - Published
Regards Simon

Qnap Downloads
MyQNap.Org Repository
Submit a ticket • QNAP Helpdesk
QNAP Tutorials, User Manuals, FAQs, Downloads, Wiki
When you ask a question, please include the following


NAS: TS-673A QuTS hero h5.1.2.2534 • TS-121 4.3.3.2420 • APC Back-UPS ES 700G
Network: VM Hub3: 500/50 • UniFi UDM Pro: 3.2.9 • UniFi Network Controller: 8.0.28
USW-Aggregation: 6.6.61 • US-16-150W: 6.6.61 • 2x USW Mini Flex 2.0.0 • UniFi AC Pro 6.6.62 • UniFi U6-LR 6.6.62
UniFi Protect: 2.11.21/8TB Skyhawk AI • 3x G3 Instants: 4.69.55 • UniFi G3 Flex: 4.69.55 • UniFi G5 Flex: 4.69.55
Blackbar7
Know my way around
Posts: 111
Joined: Fri Jan 04, 2019 7:33 pm

Re: [SECURITY ADVISORY] Security Advisory for Malware on QTS - NAS-201902-13

Post by Blackbar7 »

Toxic17 wrote: Thu Mar 14, 2019 7:00 pm Still this advisory has not yet been updated.
Affected products: To be confirmed

Revision History: V1.0 (February 13, 2019) - Published
What did you expect from qnap?
I am asking for about years to upgrade php. No luck.
TS-253 8Gb Pro with QTS 4.4.1.0978 build 20190627 Public Beta
TS-131 1Gb with QTS 4.4.1.0978 Build 20190627 Public Beta
Both drives are equiped with WD-RED drives.
Affordable seedbox > https://panel.seedbox.io/aff.php?aff=641
User avatar
Toxic17
Ask me anything
Posts: 6477
Joined: Tue Jan 25, 2011 11:41 pm
Location: Planet Earth
Contact:

Re: [SECURITY ADVISORY] Security Advisory for Malware on QTS - NAS-201902-13

Post by Toxic17 »

The php 7.x upgrade will break most QNAP web apps supported by them now, so they would need to update PHP, then update all web apps to support php7.x and only then, release all of them together.
Regards Simon

Qnap Downloads
MyQNap.Org Repository
Submit a ticket • QNAP Helpdesk
QNAP Tutorials, User Manuals, FAQs, Downloads, Wiki
When you ask a question, please include the following


NAS: TS-673A QuTS hero h5.1.2.2534 • TS-121 4.3.3.2420 • APC Back-UPS ES 700G
Network: VM Hub3: 500/50 • UniFi UDM Pro: 3.2.9 • UniFi Network Controller: 8.0.28
USW-Aggregation: 6.6.61 • US-16-150W: 6.6.61 • 2x USW Mini Flex 2.0.0 • UniFi AC Pro 6.6.62 • UniFi U6-LR 6.6.62
UniFi Protect: 2.11.21/8TB Skyhawk AI • 3x G3 Instants: 4.69.55 • UniFi G3 Flex: 4.69.55 • UniFi G5 Flex: 4.69.55
User avatar
Toxic17
Ask me anything
Posts: 6477
Joined: Tue Jan 25, 2011 11:41 pm
Location: Planet Earth
Contact:

Re: [SECURITY ADVISORY] Security Advisory for Malware on QTS - NAS-201902-13

Post by Toxic17 »

Update from QNAP at last.

Affected products: QNAP NAS devices with QTS 4.2.6 build 20181227,
QTS 4.3.3 build 20190102,
QTS 4.3.4 build 20190102,
QTS 4.3.6 build 20181228 and earlier versions

more info here:

https://www.qnap.com/en-au/security-adv ... -201902-13

Revision History:
V1.1(April 19, 2019) - Update Affected Products, Summary and Recommendation
V1.0 (February 13, 2019) - Published
Regards Simon

Qnap Downloads
MyQNap.Org Repository
Submit a ticket • QNAP Helpdesk
QNAP Tutorials, User Manuals, FAQs, Downloads, Wiki
When you ask a question, please include the following


NAS: TS-673A QuTS hero h5.1.2.2534 • TS-121 4.3.3.2420 • APC Back-UPS ES 700G
Network: VM Hub3: 500/50 • UniFi UDM Pro: 3.2.9 • UniFi Network Controller: 8.0.28
USW-Aggregation: 6.6.61 • US-16-150W: 6.6.61 • 2x USW Mini Flex 2.0.0 • UniFi AC Pro 6.6.62 • UniFi U6-LR 6.6.62
UniFi Protect: 2.11.21/8TB Skyhawk AI • 3x G3 Instants: 4.69.55 • UniFi G3 Flex: 4.69.55 • UniFi G5 Flex: 4.69.55
Post Reply

Return to “Users' Corner”