Security ID : NAS-201911-01
Security Advisory for Malware QSnatch
Release date : November 1, 2019
CVE identifier : N/A
Affected products: QNAP NAS devices
Severity
Important
Status
Resolved
Recommendation
To prevent malware infections, we strongly recommend the following steps:
- Update QTS to the latest available version.
- Install and update Malware Remover to the latest version.
- Install and update Security Counselor to the latest version.
- Update your installed QTS applications to the latest versions if available in the App Center.
- Configure the following settings to enhance system security.
Important: QSnatch collects confidential information from infected devices, such as login credentials and system configuration. Due to these data breach concerns, QNAP devices that had been infected may still be vulnerable to reinfection after removing the malware. We strongly recommend applying these settings to further secure your system and to prevent reinfection.
- Change the admin password.
- Change other user passwords.
- Change QNAP ID password.
- Use a stronger database root password
- Remove unknown or suspicious accounts.
- Enable IP and account access protection to prevent brute force attacks.
- Disable SSH and Telnet connections if you are not using these services.
- Disable Web Server, SQL server or phpMyAdmin app if you are not using these applications.
- Remove malfunctioning, unknown, or suspicious apps
- Avoid using default port numbers, such as 22, 443, 80, 8080 and 8081.
- Disable Auto Router Configuration and Publish Services and restrict Access Control in myQNAPcloud.
- Subscribe to QNAP security newsletters.
Note:
- Malware Remover (supported by QTS 4.2 and later) and Security Counselor (supported by QTS 4.3.5 and later) may not be available on older QNAP NAS models. You can check the product support status of your NAS model.
- Installing Security Counselor helps further enhance the security of your NAS. Nevertheless, you can still protect your device from the QSnatch malware following other steps without Security Counselor.
Installing the QTS Update
- Log on to QTS as administrator.
- Go to Control Panel > System > Firmware Update.
- Under Live Update, click Check for Update.
QTS downloads and installs the latest available update.
Installing and Running the Latest Version of Malware Remover
- Log on to QTS as administrator.
- Open App Center, and then click
.
The manual installation dialog box appears. - Read the instructions, and then click Browse.
The file browser appears. - Locate and select the installer file.
- Click Install.
A confirmation message appears. - Click OK.
QTS installs the latest version of Malware Remover.
A confirmation message appears. - Click OK.
The required updates dialog box appears. - Click Update Now.
QTS updates Malware Remover to the latest version. - Open Malware Remover.
- Click Start Scan.
Malware Remover scans the NAS for malware.
Installing and running the latest version of Security Counselor
- Log on to QTS as administrator.
- Open the App Center, and then click the Search icon.
A search box appears. - Type “Security Counselor”, and then press ENTER.
The Security Counselor application appears in the search results list. - Click Install or Update.
A confirmation message appears. - Click OK.
The application is installed or updated to the latest version. - Open Security Counselor.
- Click Start Scan.
Security Counselor scans the NAS for rules.
Changing the Admin Password
- Log on to QTS as administrator.
- Click the profile picture on the QTS Task Bar.
The Options window opens. - Click Change Password.
- Specify the old password.
- Specify the new password.
QNAP recommends the following criteria to improve password strength:- Should be at least 8 characters in length
- Should include both uppercase and lowercase characters
- Should include at least one number and one special character
- Must not be the same as the username or the username reversed
- Must not include characters that are consecutively repeated three or more times
- Verify the new password.
- Click Apply.
Changing User Passwords
- Log on to QTS as administrator.
- Go to Control Panel > Privilege > Users.
- Select a user.
- Click Change Password.
The Change Password window appears. - Specify the old password.
- Specify the new password.
QNAP recommends the following criteria to improve password strength:- Should be at least 8 characters in length
- Should include both uppercase and lowercase characters
- Should include at least one number and one special character
- Must not be the same as the username or the username reversed
- Must not include characters that are consecutively repeated three or more times
- Verify the new password.
- Click Apply.
- Repeat the above steps to change passwords for other users.
Changing QNAP ID Password
- Go to https://account.qnap.com
- Sign in with your QNAP account.
- Select Change Password.
- Specify the old password.
- Specify the new password.
- Confirm the new password.
- Click Submit.
Removing Unknown or Suspicious Users.
- Log on to QTS as administrator.
- Go to Control Panel > Privilege > Users.
- Verify all users on the list.
- Select unknown or suspicious users.
- Click Delete.
A confirmation message appears. - Click OK.
Enabling IP and Account Access Protection
- Log on to QTS as administrator.
- Go to Control Panel > System > Security.
- Select IP Access Protection.
- Enable SSH and HTTP(s) access protection.
- Select SSH and HTTP(S).
- Specify time periods and the number of failed login attempts.
- Select Account Access Protection.
- Enable SSH and HTTP(s) access protection.
- Select SSH and HTTP(S).
- Specify time periods and the number of failed login attempts.
- Click Apply.
Disabling SSH and Telnet Connections
- Log on to QTS as administrator.
- Go to Control Panel > Network & File Services > Telnet/SSH.
- Deselect Allow Telnet connection.
- Deselect Allow SSH connection.
- Click Apply.
Disabling Web Server
- Log on to QTS as administrator.
- Go to Control Panel > Applications > Web Server.
- Deselect Enable Web Server.
- Click Apply.
Disabling SQL Server
- Log on to QTS as administrator.
- Go to Control Panel > Applications > SQL Server.
- Deselect Enable SQL Server.
- Click Apply.
Changing the System Port Number
- Log on to QTS as administrator.
- Go to Control Panel > System > General Settings > System Administration.
- Specify a new system port number.
Warning: Do not use 22, 443, 80, 8080 or 8081. - Click Apply.
Changing myQNAPcloud Settings
- Log on to QTS as administrator.
- Open myQNAPcloud.
- Go to Auto Router Configuration.
- Deselect Enable UPnP port forwarding.
- Go to Access Control.
- Set Device access controls to Private.
- Click Apply.
Subscribing to QNAP Security Newsletters
- Go to https://www.qnap.com/i/_event/epaper/index.php?lang_set=safe
- Specify your email address.
- Click Subscribe.
QNAP sends a confirmation letter to the specified email address. - Open the confirmation letter in your email inbox.
- Click the link to confirm your subscription.
Revision History:
V6.0 (January 9, 2020) - Revised recommendation
V5.0 (December 31, 2019) - Revised recommendation
V4.0 (December 27, 2019) - Revised recommendation
V3.0 (November 19, 2019) - Revised recommendation
V2.0 (November 2, 2019) - Update