Synolocker 0-Day Ransomware Puts NAS Files At Risk
Deathlizard (115856) writes "Have a Synology NAS? Is it accessible to the internet? If it is, You might want to take it offline for a while. Synolocker is a 0-day ransomware that once installed, will encrypt all of the NAS's files and hold them for ransom just like Cryptolocker does for windows PC's. The Virus is currently exploiting an unknown vulnerability to spread. Synology is investigating the issue."
not to connect your NAS directly to the internet.
You do have backups, right?
because all my files are encrypted. I can see the list of files, but it only makes me want to puke. I am fucked, screwed, and borked, all at once. Thanks Syno. Damn Chinese software! Never again. They can make cheap hardware but they can't make software worth ... my files! All my pretty files. Gone.
Really?
Amazing! Somebody is paying attention.
They feared that it could be used to suppress protest or support unpopular rule.
So between TOR and bitcoin, they think they finally have a viable method of collecting on ransomware. Also, I found it interesting that they're asking specifically for 0.6BTC - that is, double what Cryptolocker is asking. I wonder if there's an intentional correlation there.
200% Offtopic
Not only this post is offtopic relative to the the news, it's also offtopic relative to itself (guy loses money at a carnival game -> blah blah Obama). Nice one.
Is it. Is it really.
'Investigating', not 'investAgating'. American cretins.
Is the firmware that was hacked open-source?
"Open source projects that are included with Synology DiskStation/RackStation series."
http://sourceforge.net/projects/dsgpl/
This shows that users should switch from windows to Linux because Linux is more secure.
Oh wait...
STFU Troll
From TFA: the message that pops up to the victims ends with:
Copyright 2014 SynoLocker(TM) All Rights Reserved.
I have a real hard time respecting that copyright...
Updated posted 8/5/2014 by Jeremie on the English language Synology Forum: [We’d like to provide a brief update regarding the recent ransomware called “SynoLocker,” which is currently affecting certain Synology NAS servers. Based on our current observations, this issue only affects Synology NAS servers running some older versions of DSM (DSM 4.3-3810 or earlier), by exploiting a security vulnerability that was fixed and patched in December, 2013. At present, we have not observed this vulnerability in DSM 5.0.]
This article is complete FUD. According to Synology "this issue only affects Synology NAS servers running some older versions of DSM (DSM 4.3-3810 or earlier), by exploiting a security vulnerability that was fixed and patched in December, 2013." Like any operating system - if you don't patch it then you it will be probably be vunerable to hacking. Just upgrade to the lastest version. As you were.
There is no mention in the article of this being a zero day vulnerability, in fact the article specifically says "it’s not clear yet how SynoLocker’s operators installed the malware".
As others have said Synology is reporting the vulnerability was patched in December. Hardly a zero day.
Forum post so far:
Hello Everyone,
We’d like to provide a brief update regarding the recent ransomware called “SynoLocker,” which is currently affecting certain Synology NAS servers.
Based on our current observations, this issue only affects Synology NAS servers running some older versions of DSM (DSM 4.3-3810 or earlier), by exploiting a security vulnerability that was fixed and patched in December, 2013. At present, we have not observed this vulnerability in DSM 5.0.
For Synology NAS servers running DSM 4.3-3810 or earlier, and if users encounter any of the below symptoms, we recommend they shut down their system and contact our technical support team here: https://myds.synology.com/supp....
-When attempting to log in to DSM, a screen appears informing users that data has been encrypted and a fee is required to unlock data.
-A process called “synosync” is running in Resource Monitor.
-DSM 4.3-3810 or earlier is installed, but the system says the latest version is installed at Control Panel > DSM Update.
For users who have not encountered any of the symptoms stated above, we highly recommend downloading and installing DSM 5.0, or any version below:
-For DSM 4.3, please install DSM 4.3-3827 or later
-For DSM 4.1 or DSM 4.2, please install DSM 4.2-3243 or later
-For DSM 4.0, please install DSM 4.0-2259 or later
DSM can be updated by going to Control Panel > DSM Update. Users can also manually download and install the latest version from our Download Center here: http://www.synology.com/suppor....
If users notice any strange behavior or suspect their Synology NAS server has been affected by the above issue, we encourage them to contact us at security@synology.com.
Apologies for any problems or inconvenience caused. We will keep you updated with latest information as we address this issue.
As for the article...
First part says "According to the user, there’s a small window of opportunity to minimise the damage. That is, if you can backup files faster than the program encrypts them."
Then buried where many don't wonder (towards the end, it mentions "1) Power off the DiskStation immediately to avoid more files being encrypted"
I would think the wise thing would be to exchange the location of the two sentences. least you have some would be hero actually try to find where to start saving at.
There's plenty of free options out there, if you really need that much storage, you need to care how it works and how well.
I want to delete my account but Slashdot doesn't allow it.
I misread this as
Synolocker 0-Day Ransomware Puts NSA Files At Risk
That would have been a much more interesting article to read, methinks :)
A while back synology had a problem with unauthorized bitcoin miners running on their devices:
http://www.cvedetails.com/vuln...
There seems to be a culture of fast and loose with regards to software development at Synology.
I love my Synology NAS, but you have to be nuts to put these things on the internet.
Are all the security geeks busy at Blackhat such that nobody realized this mistake?
w00t
Here I was, reading the headline as:
Synolocker 0-Day Ransomware Puts NSA Files At Risk
If only....
http://www.cvedetails.com/cve/CVE-2013-6955/
what we learned is always to check the latest OS version and upgrade to it!