non accedo più tramite interfaccia web
Inviato: 04 gen 2015, 08:37
Dopo aver letto i messaggi del Security Bulletins and Advisories ho seguito il consiglio di questa segnalazione: "Security Alert for Misfortune Cookie Vulnerability on Residential Gateways" dove si leggeva: Release date: December 24, 2014
Last updated: December 24, 2014
Bulletin ID: NAS-201412-24
Severity rating: Critical
CVE number: CVE-2014-9222
Affected products:
All Turbo NAS series that are connected to residential gateway devices (e.g. routers) using vulnerable versions of the Allegro RomPager embedded web server
Summary
The Misfortune Cookie vulnerability can be exploited to allow remote attackers to remotely take over a residential gateway and may execute arbitrary code on the device. Other devices that are connected to the gateway have an increased risk of compromise. Thus, the attacker can easily steal your credentials and personal or business data or attempt to infect your machines with malware.
Una delle soluzioni era, "To make your Turbo NAS more secure, please do the following:
Update your Turbo NAS to the latest firmware version or install Qfix for Bash security patch (Qfix 1.0.2 build 1008) for QTS firmware prior to 2014/10/03 (QTS 4.1.1 Build 1003).
Change the default password for the admin account.
Protect shared folders on your NAS with privileged access rights (non-guest rights).
Force your Turbo NAS to use only HTTPs connection for secure communication. To do so, Login to your Turbo NAS as the admin, go to “Control Panel” > “System Settings”>”General Settings”> and choose the “System Administration” tab. Check the “Enable secure connection (HTTPS)” option and enter the port number, and then check the “Force secure connection (HTTPS) only” option. Click “Apply” to apply the changes."
Così ho fatto, apparentemente tutto ha continuato a funzionare fino a quando ho spento il NAS e riacceso, da quel momento non sono più riuscito ad entrare via web!!!
Chi mi aiuta?
Grazie
Last updated: December 24, 2014
Bulletin ID: NAS-201412-24
Severity rating: Critical
CVE number: CVE-2014-9222
Affected products:
All Turbo NAS series that are connected to residential gateway devices (e.g. routers) using vulnerable versions of the Allegro RomPager embedded web server
Summary
The Misfortune Cookie vulnerability can be exploited to allow remote attackers to remotely take over a residential gateway and may execute arbitrary code on the device. Other devices that are connected to the gateway have an increased risk of compromise. Thus, the attacker can easily steal your credentials and personal or business data or attempt to infect your machines with malware.
Una delle soluzioni era, "To make your Turbo NAS more secure, please do the following:
Update your Turbo NAS to the latest firmware version or install Qfix for Bash security patch (Qfix 1.0.2 build 1008) for QTS firmware prior to 2014/10/03 (QTS 4.1.1 Build 1003).
Change the default password for the admin account.
Protect shared folders on your NAS with privileged access rights (non-guest rights).
Force your Turbo NAS to use only HTTPs connection for secure communication. To do so, Login to your Turbo NAS as the admin, go to “Control Panel” > “System Settings”>”General Settings”> and choose the “System Administration” tab. Check the “Enable secure connection (HTTPS)” option and enter the port number, and then check the “Force secure connection (HTTPS) only” option. Click “Apply” to apply the changes."
Così ho fatto, apparentemente tutto ha continuato a funzionare fino a quando ho spento il NAS e riacceso, da quel momento non sono più riuscito ad entrare via web!!!
Chi mi aiuta?
Grazie