Geeks for your information
QNAP NAS user? You'd better check your hosts file for mystery anti-antivirus entries - Printable Version

+- Geeks for your information (https://www.geeks.fyi)
+-- Forum: News (https://www.geeks.fyi/forumdisplay.php?fid=105)
+--- Forum: Privacy & Security News (https://www.geeks.fyi/forumdisplay.php?fid=107)
+--- Thread: QNAP NAS user? You'd better check your hosts file for mystery anti-antivirus entries (/showthread.php?tid=5589)



QNAP NAS user? You'd better check your hosts file for mystery anti-antivirus entries - darktwilight - 12 February 19

Quote:
[Image: glory_hole.jpg?x=442&y=293&crop=1]
NAS-ty: Strange activity sinkholes antivirus update checks.

Network attached storage maker QNAP's customers have reported being hit by a mystery issue that disables software updates by hijacking entries in host machines' hosts file.

The full effects are, as yet, unknown – but users have reported that the most visible symptom is that some 700 entries are added to the /etc/hosts file that redirect a bunch of requests to IP address 0.0.0.0.

This, said forlorn QNAP forum user ianch99, stopped his antivirus from updating by sinkholing all of the software's requests to the vendor's website. Others reported that the Taiwanese NAS appliance maker's own MalwareRemover was borked, though it is not known whether these two things are linked.

"If you remove these entries, the update runs fine but they return on after rebooting," posted ianch99. So far the only cure appeared to be a script provided by QNAP itself, which one helpful Reddit user posted the link to after apparently being given it by one of the storage firm's techie in live chat.
Source: https://www.theregister.co.uk/2019/02/11/qnap_hosts_file_issues/