AFP Version Vunerable

SMB, NFS, AFP, FTP, web file manager and Rsync server.
Locked
User avatar
StephenM
Posts: 69
Joined: 11 Jan 2021, 21:55

AFP Version Vunerable

Post by StephenM »

I have ARM TNAS running 4.2.41

The installed AFPD/Netatalk is vulnerable as it is only at version 3.1.12

https://www.bleepingcomputer.com/news/s ... ical-bugs/

When will this be updated for ARM?

This vulnerability has been known about and a fix released by Netatalk for OVER A YEAR NOW.

Very poor! You should be ashamed of your lack of response to this vulnerability TerraMaster.
User avatar
crisisacting
Posts: 261
Joined: 20 Jan 2022, 16:42

Re: AFP Version Vunerable

Post by crisisacting »

AFP was deprecated by Apple on newer MacOS versions (10.9 and newer), so this should just be removed altogether, since it's vulnerable & even Apple wants users to move away from it.
User avatar
StephenM
Posts: 69
Joined: 11 Jan 2021, 21:55

Re: AFP Version Vunerable

Post by StephenM »

Unless there is a reliable solution to using SMB drives for Time Machine Backup that doesn't require me to re-partition my RAID array so that I can prevent the backups filling up my whole array then I'll be using AFP.

Besides the x86 TOS 5 version does have the 3.1.13 AFP version which has the security vulnerabilities resolved.

Why can't us ARM users get a fix as well.
powerQ
Posts: 65
Joined: 03 Dec 2019, 19:06

Re: AFP Version Vunerable

Post by powerQ »

afp is an abandoned file service, I have disabled it.
F4-221 TOS 5.1.34 (SAMSUNG 250 SSD x1, WD Red 8TB x 1, Single drive)
F2-423 TOS 5.1.34 RAID1(12TB IronWolf x 2)
Locked