Synolocker 0-Day Ransomware Puts NAS Files At Risk
Deathlizard (115856) writes "Have a Synology NAS? Is it accessible to the internet? If it is, You might want to take it offline for a while. Synolocker is a 0-day ransomware that once installed, will encrypt all of the NAS's files and hold them for ransom just like Cryptolocker does for windows PC's. The Virus is currently exploiting an unknown vulnerability to spread. Synology is investigating the issue."
not to connect your NAS directly to the internet.
You do have backups, right?
bein sport 2 fr en direct
bein sport 1 fr en direct
iTELE france en direct
It's the shit we're not looking for that gets us.
I came back from Capetown in February fevered, vomiting, with diarrhea, sore throat, sneezing, coughing. Had to go to Mt. Sinai and have tests run and fluids pumped into me. It was e. Coli. I had a 26 hr. flight. No one asked me anything.
We almost had an American from Minnesota working in Liberia come back to the Us with Ebola. He died en route.
But first he pissed all over the hospital workers looking after him. I can't think of a more frightening epidemic.
Fatal in 90% of cases. Vomiting, fever, diarrhea, aches, sneezing, coughing, plus you bleed from every orifice in your body. Despite claims to the contrary, it can become airborne. It can also be sexually transmitted through male semen of asymptomatic carriers for up to two months. This is like AIDS meets the bubonic plague with a little influenza thrown in.
Then we flew two do gooder fucktards into the US with it. I don't care how nice they are. They broke containment.
Why would we do that? Maybe for cover, because it was already here. This shit has me freaked the fuck out.
The first plane bound for Atlanta from Africa refueled in Bangor. Why would it fly to Maine?
Then I thought, it's the Appalachian trail. It starts in Maine and ends in Georgia. They want to kill the teahadists, as the IRS and DHS call them. The facility these workers were stationed at in Africa was run by a Soros-funded NGO.
Do you think this hasn't been brought to Obama'd attention? I seriously don't think he gives a fuck. More likely the House set us up for amnesty before they went on vacation, so he can quit bluffing, worthless cocksuckers that they are.
Captcha: AFFLICT
Heh heh. Heh heh.
because all my files are encrypted. I can see the list of files, but it only makes me want to puke. I am fucked, screwed, and borked, all at once. Thanks Syno. Damn Chinese software! Never again. They can make cheap hardware but they can't make software worth ... my files! All my pretty files. Gone.
https://www.youtube.com/watch?v=32z4ILDjijU
He wanted to win an Xbox for his son. So he spent $2600 at a carnival game over two days and only ended up with a stuffed banana. Note that you can buy an Xbox 360 at Walmart for $180.
On his way home from the carnival he told reporters: "Yes I do plan to vote for Obama for a third term, why do you ask?"
Really?
Amazing! Somebody is paying attention.
They feared that it could be used to suppress protest or support unpopular rule.
So between TOR and bitcoin, they think they finally have a viable method of collecting on ransomware. Also, I found it interesting that they're asking specifically for 0.6BTC - that is, double what Cryptolocker is asking. I wonder if there's an intentional correlation there.
Is it. Is it really.
'Investigating', not 'investAgating'. American cretins.
Is the firmware that was hacked open-source?
"Open source projects that are included with Synology DiskStation/RackStation series."
http://sourceforge.net/projects/dsgpl/
This shows that users should switch from windows to Linux because Linux is more secure.
Oh wait...
From TFA: the message that pops up to the victims ends with:
Copyright 2014 SynoLocker(TM) All Rights Reserved.
I have a real hard time respecting that copyright...
Updated posted 8/5/2014 by Jeremie on the English language Synology Forum: [We’d like to provide a brief update regarding the recent ransomware called “SynoLocker,” which is currently affecting certain Synology NAS servers. Based on our current observations, this issue only affects Synology NAS servers running some older versions of DSM (DSM 4.3-3810 or earlier), by exploiting a security vulnerability that was fixed and patched in December, 2013. At present, we have not observed this vulnerability in DSM 5.0.]
This article is complete FUD. According to Synology "this issue only affects Synology NAS servers running some older versions of DSM (DSM 4.3-3810 or earlier), by exploiting a security vulnerability that was fixed and patched in December, 2013." Like any operating system - if you don't patch it then you it will be probably be vunerable to hacking. Just upgrade to the lastest version. As you were.
There is no mention in the article of this being a zero day vulnerability, in fact the article specifically says "it’s not clear yet how SynoLocker’s operators installed the malware".
As others have said Synology is reporting the vulnerability was patched in December. Hardly a zero day.
Forum post so far:
Hello Everyone,
We’d like to provide a brief update regarding the recent ransomware called “SynoLocker,” which is currently affecting certain Synology NAS servers.
Based on our current observations, this issue only affects Synology NAS servers running some older versions of DSM (DSM 4.3-3810 or earlier), by exploiting a security vulnerability that was fixed and patched in December, 2013. At present, we have not observed this vulnerability in DSM 5.0.
For Synology NAS servers running DSM 4.3-3810 or earlier, and if users encounter any of the below symptoms, we recommend they shut down their system and contact our technical support team here: https://myds.synology.com/supp....
-When attempting to log in to DSM, a screen appears informing users that data has been encrypted and a fee is required to unlock data.
-A process called “synosync” is running in Resource Monitor.
-DSM 4.3-3810 or earlier is installed, but the system says the latest version is installed at Control Panel > DSM Update.
For users who have not encountered any of the symptoms stated above, we highly recommend downloading and installing DSM 5.0, or any version below:
-For DSM 4.3, please install DSM 4.3-3827 or later
-For DSM 4.1 or DSM 4.2, please install DSM 4.2-3243 or later
-For DSM 4.0, please install DSM 4.0-2259 or later
DSM can be updated by going to Control Panel > DSM Update. Users can also manually download and install the latest version from our Download Center here: http://www.synology.com/suppor....
If users notice any strange behavior or suspect their Synology NAS server has been affected by the above issue, we encourage them to contact us at security@synology.com.
Apologies for any problems or inconvenience caused. We will keep you updated with latest information as we address this issue.
As for the article...
First part says "According to the user, there’s a small window of opportunity to minimise the damage. That is, if you can backup files faster than the program encrypts them."
Then buried where many don't wonder (towards the end, it mentions "1) Power off the DiskStation immediately to avoid more files being encrypted"
I would think the wise thing would be to exchange the location of the two sentences. least you have some would be hero actually try to find where to start saving at.
There's plenty of free options out there, if you really need that much storage, you need to care how it works and how well.
I want to delete my account but Slashdot doesn't allow it.
I misread this as
Synolocker 0-Day Ransomware Puts NSA Files At Risk
That would have been a much more interesting article to read, methinks :)
A while back synology had a problem with unauthorized bitcoin miners running on their devices:
http://www.cvedetails.com/vuln...
There seems to be a culture of fast and loose with regards to software development at Synology.
I love my Synology NAS, but you have to be nuts to put these things on the internet.
Are all the security geeks busy at Blackhat such that nobody realized this mistake?
w00t
Here I was, reading the headline as:
Synolocker 0-Day Ransomware Puts NSA Files At Risk
If only....
http://www.cvedetails.com/cve/CVE-2013-6955/
what we learned is always to check the latest OS version and upgrade to it!