View this email in your browser
You are receiving this email because of your relationship with ASUSTOR Inc. If you do not wish to receive any more emails, you can unsubscribe here.
marketing@asustor.com
2023 年 7 月 ASUSTOR 电子报 第 200
本期焦点

保护个资不外泄, 跟着ASUSTOR 一起这样做 

个人资料防护很重要! 除了定期遵守 3-2-1原则备份,还要建立好正确观念和防护措施才能有效守护你我的资安。
一、随时将 ADM 更新至最新版:
ASUSTOR ADM 操作系统会根据潜在的资安漏洞持续做出修改,为了保护数据安全,建议每位用户将 ADM 更新到最新版本。
二、使用高强度的管理者账号与密码并定期更新密码:
设定复杂的账号和密码是一件很常令人忽略的事情,多数人为了方便只设定了简单的组合,但这让帐户容易被有心人士入侵并窃取隐私。ASUSTOR NAS 用户可以点选 ADM 里的「访问控制」-「本机使用者」-「新增」,填入自己命名的管理者账号以及高强度密码,并停用默认的 admin 账号。
三、开启 ADM Defender 防火墙以及网络防护:
点选 ADM 里的「偏好设定」-「ADM Defender」-「网络防护」,启用自动黑名单以防止恶意网络攻击及尝试登入。当任何客户端 IP 地址在指定时间内重复登入失败超过指定的次数,该用户 IP 地址即会自动被封锁。
Security Advisory

A Cross-Site Scripting(XSS) vulnerability was found on ADM, LooksGood and SoundsGood Apps. An attacker can exploit this vulnerability to inject malicious scripts into the target applications to access any cookies or sensitive information retained by the browser and used with that application. (CVE-2023-2509)

  • The issue has been fixed on ADM 4.2.2.RI61.

EZ Sync service fails to adequately handle user input, allowing an attacker to navigate beyond the intended directory structure and delete files. (CVE-2023-2909)

  • The issue has been fixed on ADM 4.2.2.RI61.

The Netatalk development team disclosed multiple fixed vulnerabilities affecting earlier versions of the software on the latest release of Netatalk 3.1.13: CVE-2022-43634 and CVE-2022-45188.

  • Netatalk 3.1.13 patch has been updated on ADM 4.2.2.RI61 to resolve the issue.

Download Center fails to properly validate the file path submitted by a user, An attacker can exploit this vulnerability to gain unauthorized access to sensitive files or directories without appropriate permission restrictions. (CVE-2023-2749)

  • The issue has been fixed on Download Center 1.1.5.r1298 for ADM 4.2.

The PHP Group announced multiple vulnerabilities that have been fixed in the latest release of PHP 8.1.

CVE-2023-0662, CVE-2022-31631, CVE-2022-31630, CVE-2022-37454, CVE-2022-31628, CVE-2022-31629 and CVE-2022-31627 will affect ASUSTOR products with PHP 8.1 installed on ADM 4.1 or ADM 4.2

  • Updates with PHP 8.1.18 has been released on App Central for ADM 4.2.2.
得奖讯息
marketing@asustor.com
ASUSTOR Inc. NAS 再获肯定! Lockerstor 2 Gen2 / AS6702T 获得美国权威科技媒体 PC Magazine 认可,再度夺得「2022 年度最佳科技产品和服务」大奖,AS6702T 以强大的运算能力及丰富的功能,荣获编辑青睐,评鉴为满足未来企业储存需求的绝佳选择。
 
PC Magazine 编辑经过长达一年及不断的反复测试及验证,从超过 2,000 项的产品中整理出 15 个年度最杰出的科技产品类别及多项顶级产品,以帮助大家在选购科技产品时作出最正确的判断。AS6702T 为网通类别里唯一获奖的 NAS 产品,双 2.5GbE 高速联机、超过 300 款商用、备份、安全及家庭娱乐应用程序的 ADM 系统、4 个 M.2 SSD 磁盘槽,高扩充性的特性、出色的功能使 AS6702T 在获得「编辑首选」的奖项之后,再度获得肯定,入选「2022 年度最佳科技产品和服务」。
marketing@asustor.com
 
 
This message was sent from marketing@asustor.com to marketing@asustor.com
3F, No.136, Da-Ye Rd., Beitou Dist., Taipei City 112, Taiwan


Update Profile/Email Address | Forward Email | Report Abuse