Dat zijn twee bugs, eentje in Samba (waar meer Linuxkastjes last van zullen hebben gehad), maar ook een in de FileBrowser van Synology zelf.http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2013-4475http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2013-6987De FileBrowser bug was kennelijk vrij gemakkelijk om te misbruiken. Welke van de twee gebruikt wordt door de Synolocker malware weet ik niet, maar met de FileBrowser bug kun je al flink wat vervelende dingen uithalen.
CVSS Severity (version 2.0):CVSS v2 Base Score: 7.5 (HIGH)Impact Subscore: 6.4Exploitability Subscore: 10.0CVSS Version 2 Metrics:Access Vector: Network exploitableAccess Complexity: LowAuthentication: Not required to exploitImpact Type: Allows unauthorized disclosure of information; Allows unauthorized modification; Allows disruption of service
CVSS Version 2 Metrics:Access Vector: Network exploitableAccess Complexity: LowAuthentication: Not required to exploitImpact Type: Allows unauthorized disclosure of information; Allows unauthorized modification; Allows disruption of service
Multiple directory traversal vulnerabilities in the FileBrowser components in Synology DiskStation Manager (DSM) before 4.3-3810 Update 3 allow remote attackers to read, write, and delete arbitrary files via a .. (dot dot) in the (1) path parameter...
https://www.synology.com/nl-nl/company/news/article/472