Free Republic
Browse · Search
General/Chat
Topics · Post Article

If you have an internet-accesible NAS made by synology you are cautioned to take it offline for a bit. A new version of the Cryptolocker virus is appearing as a 0-day exploit and the company is scrambling to fix the vulnerability.

Only this company hit so far but other NAS owners might wish to take a look at the article and consider taking their units offline for a bit as well until this new exploit is delved further into.

1 posted on 08/05/2014 10:42:15 AM PDT by Utilizer
[ Post Reply | Private Reply | View Replies ]


To: Utilizer

Cryptolocker stores the key they used to encrypted the drive on the workstation in a clear text file.


2 posted on 08/05/2014 10:55:22 AM PDT by driftdiver (I could eat it raw, but why do that when I have a fire.)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: ShadowAce

*ping* FYI.


5 posted on 08/05/2014 11:04:07 AM PDT by Utilizer (Bacon A'kbar! - In world today are only peaceful people, and the muzzle-em's trying to kill them-)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: rdb3; Calvinist_Dark_Lord; JosephW; Only1choice____Freedom; amigatec; Still Thinking; ...

8 posted on 08/05/2014 11:12:28 AM PDT by ShadowAce (Linux -- The Ultimate Windows Service Pack)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: Utilizer
Neal Stephenson did something like this in Reamde. BTT
10 posted on 08/05/2014 11:18:30 AM PDT by Billthedrill
[ Post Reply | Private Reply | To 1 | View Replies ]

To: Utilizer

Why are these maggots not shot when caught? For them to get paid, there has to be a trail leading to them. Maybe hidden by uncooperative countries and businesses, but their participation needs addressed too.


11 posted on 08/05/2014 11:20:35 AM PDT by LevinFan
[ Post Reply | Private Reply | To 1 | View Replies ]

To: Utilizer
FYI to anyone who might be affected, there's a somewhat palatable "workaround" to prevent this from completely consuming your data:

Synology disk HACKED (Synolock)

If you remove your disks from the NAS, boot to an empty/clean single disk, install DSM to that disk, shutdown, and replace the old disks, it can update the firmware without corrupting your personal data.

That being said, it appears the Synolocker loads into a local Linux module, sits in memory, and blocks access to the admin page. If you get the message on your admin page, you shutdown the NAS and your data might be safe. It appears that accessing the data via UNC despite the admin page message proves the data is not immediately affected.

16 posted on 08/05/2014 11:41:46 AM PDT by rarestia (It's time to water the Tree of Liberty.)
[ Post Reply | Private Reply | To 1 | View Replies ]

To: All

Well, duty calls. I have to start getting some equipment and discs, recovery software, and a rescue laptop and go try to help someone running a Vista OS that seems barely responsive -relatively speaking, of course.

I’ll check back in this evening to see what other info pops up.

Cheers!


22 posted on 08/05/2014 11:59:00 AM PDT by Utilizer (Bacon A'kbar! - In world today are only peaceful people, and the muzzle-em's trying to kill them-)
[ Post Reply | Private Reply | To 1 | View Replies ]

Free Republic
Browse · Search
General/Chat
Topics · Post Article


FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson