瀏覽單個文章
公不
*停權中*
 

加入日期: Dec 2010
文章: 341
Thumbs up 用Synology 免費賺錢!!!!!!! 賺個2億以上

synology 系統的最好去更新一下新版dsm..

dsm 4.0-4.3版本有個漏洞可以讓人非法寫入檔案...

大概有上萬台nas 被當成挖礦機

引用:
作者CVE-2013-6955
webman/imageSelector.cgi in Synology DiskStation Manager (DSM) 4.0 before 4.0-2259, 4.2 before 4.2-3243, and 4.3 before 4.3-3810 Update 1 allows remote attackers to append data to arbitrary files, and consequently execute arbitrary code, via a pathname in the SLICEUPLOAD X-TMP-FILE HTTP header.


http://www.kb.cert.org/vuls/id/615910

http://cve.mitre.org/cgi-bin/cvenam...e=CVE-2013-6955

http://forum.synology.com/enu/viewt...hp?f=19&t=80857
     
      
舊 2014-02-14, 11:29 PM #1
回應時引用此文章
公不離線中