NETGEAR ReadyNAS

Community Support Forum
It is currently Tue Feb 09, 2010 7:08 am

All times are UTC - 8 hours [ DST ]




Forum locked This topic is locked, you cannot edit posts or make further replies.  [ 1 post ] 
Author Message
 Post subject: Security Advisory: Vulnerability of root SSH access (V3.01)
PostPosted: Mon Aug 06, 2007 5:09 pm 
Offline
Jedi Council
User avatar

Joined: Fri Nov 19, 2004 1:21 am
Posts: 12614
Location: Borah-Borah
ReadyNAS: Pro
NETGEAR ReadyNAS Security Advisory
Vulnerability of root SSH access

August 6, 2007

NETGEAR has released an add-on to toggle SSH support for the ReadyNAS systems based on a potential exploit to obtain root user access to the ReadyNAS RAIDiator 3 OS. Each ReadyNAS system incorporates a different root password that can be used by NETGEAR Support to understand and/or fix a ReadyNAS system remotely using the ReadyNAS serial number as a key. An attacker that has obtained the algorithm (and your serial number) to generate the root password would be able to remotely access the ReadyNAS and view, change, or delete data on the ReadyNAS.

ReadyNAS installation most vulnerable to this attack is in an unsecure LAN and where the ReadyNAS SSH port (22) is accessible by untrusting clients. Typical home environments are safe if a firewall is utilized and port 22 is not forwarded to the ReadyNAS from the router. We do advise that all ReadyNAS users perform this add-on installation regardless.

Installation of the ToggleSSH add-on will disable remote SSH access and thus close the vulnerability. At the same time, if you need remote access assistance from NETGEAR Support, you can install the ToggleSSH add-on again to re-enable SSH access during the time when the remote access is needed.

To install, download and save the ToggleSSH add-on to your computer. Then invoke the ReadyNAS FrontView and go to the System/Update/Local tab. Specify the add-on as the update image, accept the confirmation, and reboot the ReadyNAS. After reboot, you will get a “Successfully disabled SSH service” message in FrontView. The whole process will take about 5 minutes.

Note: RAIDiator 4 has SSH disabled by default.

_________________
"Sinks with water foot-pumps."
Yoh-dah's Useless Invention Ideas


Follow Yoh-dah on Twitter
If you really don't have anything better to do...


NETGEAR Support | USA: 888-NETGEAR / International Numbers
www.readynas.com | FAQ | Hardware Compatibility List | Testing Memory | Sending Logs | Documentation | Testimonials


Top
 Profile  
 
Display posts from previous:  Sort by  
Forum locked This topic is locked, you cannot edit posts or make further replies.  [ 1 post ] 

All times are UTC - 8 hours [ DST ]


Who is online

Users browsing this forum: No registered users and 2 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum

Search for:
Jump to:  
Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group
[ Time : 0.034s | 14 Queries | GZIP : On | Load : 0.08 ]