Skip to content

【ESET家用產品更名公告】即日起煥新升級更名為:ESET家用安全基礎版(ESET HOME Security Essential)與ESET家用安全旗艦版(ESET Home Security Premium)

關於ESET
ESET成立於1992年,是一家面向企業與個人用戶的全球性的電腦安全軟體提供商,其 獲獎產品——NOD32防病毒軟體系統,能夠針對各種已知或未知病毒、間諜軟體 (spyware)、rootkits和其他惡意軟體為電腦系統提供實時保護。ESET NOD32佔用 系統資源最少,偵測速度最快,可以提供最有效的保護,並且比其他任何防病毒產品獲 得了更多的Virus Bulletin 100%獎項。ESET連續五年被評為“德勤高科技快速成長500 強”(Deloitte’s Technology Fast 500)公司,擁有廣泛的合作夥伴網絡,包括佳 能、戴爾、微軟等國際知名公司,在布拉迪斯拉發(斯洛伐克)、布里斯托爾(英國 )、布宜諾斯艾利斯(阿根廷)、布拉格(捷克)、聖地亞哥(美國)等地均設有辦事 處,代理機構覆蓋全球超過100個國家。

關於 Version 2 Digital
資安解決方案 專業代理商與領導者
台灣二版 ( Version 2 ) 是亞洲其中一間最有活力的 IT 公司,多年來深耕資訊科技領域,致力於提供與時俱進的資安解決方案 ( 如EDR、NDR、漏洞管理 ),工具型產品 ( 如遠端控制、網頁過濾 ) 及資安威脅偵測應 變服務服務 ( MDR ) 等,透過龐大銷售點、經銷商及合作伙伴,提供廣被市場讚賞的產品及客製化、在地化的專業服務。

台灣二版 ( Version 2 ) 的銷售範圍包括台灣、香港、中國內地、新加坡、澳門等地區,客戶涵 蓋各產業,包括全球 1000 大跨國企業、上市公司、公用機構、政府部門、無數成功的中小企業及來自亞 洲各城市的消費市場客戶。

23.9.10 ‘Voyager’ released

Enhancements

  • Significantly improved performance when restoring directories containing only a few files from a File and Folder Protected Item
  • Lowered memory usage when uploading to S3-backed Storage Vaults in some use cases
  • Removed the device dropdown in web UI when adding a protected item when there’s only one device

Bug Fixes

  • Fixed an issue with compatibility with Cloudflare R2 S3-compatible storage service
  • Fixed an issue with granular restore of symlinks when Comet Backup is running on a non-Windows OS
  • Fixed an issue with granular restore of NTFS partitions on MBR with an invalid partition type flag
  • Fixed an issue with inconsistent behaviour of granular restore from Disk Image backups where the partition table was not included
  • Fixed an issue with granular restore of disk images if the image is contained within a directory with certain names
  • Fixed an issue with granular restore when selecting files from a Disk Image partition extent following a deselected extent
  • Fixed an issue with missing non-disk-image files when browsing parent directories in granular restore mode
  • Fixed an issue with missing partition names for display in granular restore mode
  • Fixed a cosmetic issue with the dropdown mode selector for Hyper-V Protected Items
  • Fixed an issue causing excessive memory usage when compressing large index files during a retention pass
  • Fixed a cosmetic issue with the Disk Image restore dialog in the Comet Server web interface and the Comet Backup desktop app
  • Fixed a cosmetic issue with the Object Lock configuration in the Comet Server web interface

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About Comet
We are a team of dedicated professionals committed to developing reliable and secure backup solutions for MSP’s, Businesses and IT professionals. With over 10 years of experience in the industry, we understand the importance of having a reliable backup solution in place to protect your valuable data. That’s why we’ve developed a comprehensive suite of backup solutions that are easy to use, scalable and highly secure.

23.9.9 ‘Voyager’ released

Enhancements

  • Updated the preconfigured exclusion list for File and Folder Protected Items on the Comet Server web interface with valid exclusions

Bug Fixes

  • Fixed an issue with ‘not found in index’ error messages when restoring from some recent backup job snapshots that were created simultaneously with a retention pass
  • Fixed an issue with default Protected Items displaying “Not yet run” in the Comet Backup desktop app despite having run
  • Fixed an issue where default Protected Items with the option “Update existing devices” enabled could have their configuration menu opened through the user’s Protected Items table in the Comet Server web interface
  • Fixed an issue where default Protected Items with the option “Update existing devices” enabled still displayed the “Configure” button in the Comet Backup desktop app
  • Removed the AWS and Wasabi Object Lock dropdown options in the replication dialog on the Comet Server web interface
  • Fixed an issue with browsing and restoring files from a Disk Image backup where the original partition data was not part of the backup job
  • Fixed an issue with browsing files from disk partitions created by non-Windows systems

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About Comet
We are a team of dedicated professionals committed to developing reliable and secure backup solutions for MSP’s, Businesses and IT professionals. With over 10 years of experience in the industry, we understand the importance of having a reliable backup solution in place to protect your valuable data. That’s why we’ve developed a comprehensive suite of backup solutions that are easy to use, scalable and highly secure.

23.8.2 ‘Adrastea’ released

Bug Fixes

  • Fixed an issue with the Comet Server stats endpoint returning Internal Error in some specific scenarios.
  • Fixed an issue with the Comet Server stats processing returning incorrect stats for previous days
  • Fixed an issue with browsing and restoring one or more files from Hyper-V backup
  • Fixed an issue with CVE-2023-44487 HTTP/2 Rapid Reset Attack
  • Fixed an issue with Files and Folders Protected Items being configurable through the Comet Server web interface while restricted by policy
  • Fixed a cosmetic issue with pixelated text in the Comet Backup desktop app on multi-screen setups
  • Fixed a cosmetic issue with the ‘Configure’ text being in the wrong location in the Comet Backup desktop app
  • Fixed an issue with Storage Vault configuration if the Object Lock duration was set to zero days
  • Fixed an issue with Virtual Storage Vault policy options being available incorrectly when configuring a schedule for a Protected Item
  • Fixed an issue with the list of allowed Storage Vault types not being immediately visible when editing admin permissions in the Comet Server web interface for an admin user with the “Restrict available Storage Vault types” setting enabled
  • Fixed an issue with a non-existent empty Protected Item being shown in the Comet Backup desktop app after restoring a snapshot from other device
  • Fixed an issue with the Restore dialog in the Comet Backup desktop app showing snapshots from another devices as if they were from the current device
  • Fixed an issue with the Policy Protected Items getting multiple unknown entries when the dialog for the OS picker is cancelled.
  • Fixed an issue where Microsoft 365 email backups would error instead of warn for server-side retrieval failures
  • Fixed an issue with the desktop application not launching after installation when “Launch Comet Backup” is checked on Windows Server
  • Fixed an issue with handling unexpected files inside an S3-compatible storage location

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About Comet
We are a team of dedicated professionals committed to developing reliable and secure backup solutions for MSP’s, Businesses and IT professionals. With over 10 years of experience in the industry, we understand the importance of having a reliable backup solution in place to protect your valuable data. That’s why we’ve developed a comprehensive suite of backup solutions that are easy to use, scalable and highly secure.

23.9.8 ‘Voyager’ released

Enhancements

  • Improve security posture of the Comet Server web interface by adding additional XSS protections

Bug Fixes

  • Fixed an issue with CVE-2023-44487 HTTP/2 Rapid Reset Attack
  • Fixed an issue with MySQL streaming restore raising packet size errors when restoring large blobs
  • Fixed an issue that prevented using Spanned storage for Storage Role in the Comet Server web interface
  • Fixed a cosmetic issue with spacing around the warning message when viewing stale vault analysis information in the Comet Server web interface

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About Comet
We are a team of dedicated professionals committed to developing reliable and secure backup solutions for MSP’s, Businesses and IT professionals. With over 10 years of experience in the industry, we understand the importance of having a reliable backup solution in place to protect your valuable data. That’s why we’ve developed a comprehensive suite of backup solutions that are easy to use, scalable and highly secure.

23.9.8 ‘Voyager’ released

Changes compared to 23.9.7 

Enhancements

  • Improve security posture of the Comet Server web interface by adding additional XSS protections

Bug Fixes

  • Fixed an issue with CVE-2023-44487 HTTP/2 Rapid Reset Attack
  • Fixed an issue with MySQL streaming restore raising packet size errors when restoring large blobs
  • Fixed an issue that prevented using Spanned storage for Storage Role in the Comet Server web interface
  • Fixed a cosmetic issue with spacing around the warning message when viewing stale vault analysis information in the Comet Server web interface

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About Comet
We are a team of dedicated professionals committed to developing reliable and secure backup solutions for MSP’s, Businesses and IT professionals. With over 10 years of experience in the industry, we understand the importance of having a reliable backup solution in place to protect your valuable data. That’s why we’ve developed a comprehensive suite of backup solutions that are easy to use, scalable and highly secure.

October 2023: What’s New

“What’s New?” is a series of blog posts covering recent changes to Comet in more detail. This article covers the latest changes in Comet Voyager over October 2023.  

There were four Comet software releases during October, all in the 23.9.x Voyager release series.

VMware support

Comet 23.9.7 adds support for backing up VMware virtual machines.

This has been a long-standing request on our Feature Voting page. After running a successful beta program over the last few months, we’re very happy to be able to deliver this feature to partners in our Voyager track.

Comet’s new VMware Protected Item type allows you to easily connect to your ESXi or vCenter server. You can pick individual VMs for backup across all datacenters, or choose “All VMs” to ensure all VMs are backed up with targeted exclusions.

The feature supports Changed Block Tracking. After completing an initial backup job, any future backup jobs will coordinate with the VMware host server to identify which ranges of the disk have changed since the previous backup job. These changed ranges from the VMware server are adapted into content-defined boundaries for Comet’s deduplicating chunking engine. This results in an extremely efficient, incremental-forever backup.

As this is a new Protected Item type, it must be configured to run from an installed device that will perform the compression and encryption workload. Installing Comet Backup on a VM within the VMware server itself is recommended for reduced end-to-end latency. In this first released version in Comet 23.9.7, this feature requires the device to be running Windows x86_64.

We are excited to bring this new Protected Item type to our entire Comet Community, so look out for our upcoming quarterly software release at the end of this month. We’d love your feedback and are here to help if you need any assistance getting started, reach out via our support ticket system.

Comet Storage powered by Wasabi

It’s official – Comet Storage is a new cloud storage offering from Comet, in partnership with Wasabi. We offer Wasabi’s same great S3-compatible service, at no additional cost above their public pricing. The feature is fully integrated and managed from within your account.cometbackup.com account, giving you unified billing and reporting across both cloud storage and your backup software licenses.

Comet Backup will continue to support a wide range of cloud storage providers. However, the new all-in-one Comet Storage offering is both highly convenient and excellent value. If you are interested in migrating to Comet Storage from an existing Wasabi account or from another cloud provider, please contact us for migration assistance.

Comet Storage also supports S3 Object Lock, allowing the backed-up data to be marked as immutable. This is a complete defense against ransomware attacking the backup storage location itself, giving you a fixed number of days to identify and mitigate the issue. In the latest version of Comet, we’ve also made Object Lock easier to use for all supported Object Lock-compatible providers, by simplifying the configuration options for both Storage Vaults and Storage Templates.

For more information, please see the documentation, or check out our latest YouTube video:

New account.cometbackup.com user interface design

The next time you log in to the account.cometbackup.com system, you’ll see a brand new user interface.

Every element on the page has been given a fresh coat of paint – from buttons to popups, from paying your bill to raising a support ticket. We’ve also grouped some pages together in a more logical way, so you’ll find it simpler to make your way around the site.

Inspired by the similar change to the Comet Server web interface earlier this year, the new design has moved the main navigation bar from the top to the left-hand side. This change brings our branding more closely in line across these two interfaces. On devices with smaller screens, such as laptops and tablets, you can click the small arrow button to collapse the navigation bar and regain horizontal screen real estate.

Virtual disk restore

Comet supports backing up physical Disk Images, Hyper-V virtual machines, and VMware virtual machines. All of these different Protected Item types result in virtual disk files. Comet supports granular restore for all three types, allowing you to browse through partitions and supported filesystems, to restore individual files from within a full disk backup.

In the latest versions of Comet, we’ve significantly improved the speed of granular restores from Disk Image backups. Some particular use-cases seeing a large improvement are granular restores involving a large number of directories, or a large quantity of small files. We’re committed to continuing to improve Comet’s performance and this work has identified more opportunities for improvement across all three types, so watch this space!

We’ve also added a feature to restore Disk Image backup jobs as VMware vSphere-compatible virtual disks.

Both Disk Image and our new VMware Protected Item type generate virtual *.vmdk files inside Comet’s deduplicated Storage Vault. However, the subformat of the files does differ slightly. Until now, users who are using Comet to perform a physical-to-virtual (P2V) migration from a physical disk to a VMware virtual machine have been required to perform an extra file format conversion after the restore, requiring extra time and temporary disk space. With the new option in Comet to restore the disk in VMware vSphere-compatible file format, the conversion takes place dynamically as part of the restore job, simplifying the process and helping meet your recovery time objective (RTO).

Audit logging

Earlier this year, we added Audit Logging support to the self-hosted Comet Server product, to help our partners meet their compliance obligations. Since then, we’ve expanded the list of audit properties, and added a helpful option to configure this feature directly from the Comet Server web interface from the Settings page on the “License & Access” tab.

The new controls should make it much more accessible to configure Audit Logging support for your Comet Server.

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About Comet
We are a team of dedicated professionals committed to developing reliable and secure backup solutions for MSP’s, Businesses and IT professionals. With over 10 years of experience in the industry, we understand the importance of having a reliable backup solution in place to protect your valuable data. That’s why we’ve developed a comprehensive suite of backup solutions that are easy to use, scalable and highly secure.

23.9.6 ‘Voyager’ released

Changes compared to 23.9.5 

New Features

  • Added new “Comet Storage” and “Comet Storage (Object Lock)” storage destinations, allowing users to select Comet’s new bundled Wasabi storage option for Storage Vaults (including Storage Templates)

Bug Fixes

  • Fixed an issue with the Comet Server stats processing returning incorrect stats for previous days
  • Fixed an issue in Comet Server web interface where creating or editing a custom Storage Vault can cause invalid Object Lock settings

About Version 2 Digital

Version 2 Digital is one of the most dynamic IT companies in Asia. The company distributes a wide range of IT products across various areas including cyber security, cloud, data protection, end points, infrastructures, system monitoring, storage, networking, business productivity and communication products.

Through an extensive network of channels, point of sales, resellers, and partnership companies, Version 2 offers quality products and services which are highly acclaimed in the market. Its customers cover a wide spectrum which include Global 1000 enterprises, regional listed companies, different vertical industries, public utilities, Government, a vast number of successful SMEs, and consumers in various Asian cities.

About Comet
We are a team of dedicated professionals committed to developing reliable and secure backup solutions for MSP’s, Businesses and IT professionals. With over 10 years of experience in the industry, we understand the importance of having a reliable backup solution in place to protect your valuable data. That’s why we’ve developed a comprehensive suite of backup solutions that are easy to use, scalable and highly secure.

駭客組織利用名為Spacecolon的惡意工具包,散布勒索軟體Scarab

國際資安大廠ESET揭露一起駭客組織CosmicBeetle的攻擊行動,駭客從2020年5月,利用名為Spacecolon的惡意工具包,鎖定存在ZeroLogon漏洞的電腦,或是針對能夠暴力破解的遠端桌面連線(RDP)伺服器下手,一旦成功入侵便會部署攻擊工具包的ScHackTool元件,進而透過其他工具來停用防毒軟體或資安防護元件,並收集敏感資料以便獲得進一步的存取權限。
接著,駭客部署工具包的另一個元件ScInstaller,並將其用於安裝遠端存取工具ScService,最終植入勒索軟體Scarab。在部分攻擊行動裡,駭客透過開源的網路掃描工具Impacket取代ScInstaller,不過,也有未用ScHackTool的情況。此外,在研究人員看到的勒索軟體當中,內含了名為ClipBanker的剪貼簿挾持軟體,該惡意程式竄改使用者複製的加密貨幣錢包地址,將資金轉到攻擊者的錢包。
另研究人員亦發現在部分情境裡,駭客還會執行.NET程式ScPatcher,修補受害系統的特定漏洞。

#若有任何資安需求,歡迎洽詢台灣二版資安專業團隊,服務電話:(02)7722-6899,或上官網查詢:https://version-2.com.tw/

原文出處:https://www.welivesecurity.com/en/eset-research/scarabs-colon-izing-vulnerable-servers/

關於ESET
ESET成立於1992年,是一家面向企業與個人用戶的全球性的電腦安全軟體提供商,其 獲獎產品——NOD32防病毒軟體系統,能夠針對各種已知或未知病毒、間諜軟體 (spyware)、rootkits和其他惡意軟體為電腦系統提供實時保護。ESET NOD32佔用 系統資源最少,偵測速度最快,可以提供最有效的保護,並且比其他任何防病毒產品獲 得了更多的Virus Bulletin 100%獎項。ESET連續五年被評為“德勤高科技快速成長500 強”(Deloitte’s Technology Fast 500)公司,擁有廣泛的合作夥伴網絡,包括佳 能、戴爾、微軟等國際知名公司,在布拉迪斯拉發(斯洛伐克)、布里斯托爾(英國 )、布宜諾斯艾利斯(阿根廷)、布拉格(捷克)、聖地亞哥(美國)等地均設有辦事 處,代理機構覆蓋全球超過100個國家。

關於 Version 2 Digital
資安解決方案 專業代理商與領導者
台灣二版 ( Version 2 ) 是亞洲其中一間最有活力的 IT 公司,多年來深耕資訊科技領域,致力於提供與時俱進的資安解決方案 ( 如EDR、NDR、漏洞管理 ),工具型產品 ( 如遠端控制、網頁過濾 ) 及資安威脅偵測應 變服務服務 ( MDR ) 等,透過龐大銷售點、經銷商及合作伙伴,提供廣被市場讚賞的產品及客製化、在地化的專業服務。

台灣二版 ( Version 2 ) 的銷售範圍包括台灣、香港、中國內地、新加坡、澳門等地區,客戶涵 蓋各產業,包括全球 1000 大跨國企業、上市公司、公用機構、政府部門、無數成功的中小企業及來自亞 洲各城市的消費市場客戶。