SambaCry 正式登錄Linux

37 回覆
1 Like 0 Dislike
2017-05-26 10:02:28



今次到 #Samba (Linux 上嘅 SMB share server) 有遙距攻擊漏洞,Exploit code 已流通,不禁令人擔心類似 #WannaCry 同 #EternalBlue 相關嘅攻擊今次會針對 Linux-based 系統。如果攻擊成功,除咗有機會中 Ransomware 外,仲可能偷或修改到部機入面嘅資料

https://www.facebook.com/InfoSecOnGround/posts/716393495206994

#NAS 高危!

Btw 跟據小編尋晚收集嘅資料,攻擊條件可能包括有 writable share / pipe,未必係人都得,但值得大家留意一下。

詳情:https://www.samba.org/samba/security/CVE-2017-7494.html
2017-05-26 10:21:41
有patch未
2017-05-26 10:26:50
有patch未

2017-05-26 13:12:18
MrA:用家問題
2017-05-26 15:22:15
Mitigation:

Any of the following:

1. SELinux is enabled by default and our default policy prevents loading of modules from outside
of samba's module directories and therefore blocks the exploit

2. Mount the filessytem which is used by samba for its writeable share, using "noexec" option.

3. Add the parameter:

nt pipe support = no

to the [global] section of your smb.conf and restart smbd. This prevents clients from accessing
any named pipe endpoints. Note this can disable some expected functionality for Windows clients.
2017-05-26 15:26:04
2017-05-26 16:14:57
🤢
2017-05-26 23:17:22
NAS 啲 vendor 升級密唔密
用緊西部數碼
2017-05-27 00:48:15
NAS 啲 vendor 升級密唔密
用緊西部數碼

你部NAS係真IP定響firewall後面?firewall有無Samba port forwarding?
如果響firewall 後,firewall有無forwarding應該安全。不過我識有人屋企部NAS駁出街睇相,但無知到係乜protocol。我自己部router行Linux但一年以上無得update,不過我Samba無開到。
2017-05-27 01:03:45
NAS 啲 vendor 升級密唔密
用緊西部數碼

你部NAS係真IP定響firewall後面?firewall有無Samba port forwarding?
如果響firewall 後,firewall有無forwarding應該安全。不過我識有人屋企部NAS駁出街睇相,但無知到係乜protocol。我自己部router行Linux但一年以上無得update,不過我Samba無開到。

behind firewall, through NAT i think. not sure what ports they use, but i occasionally use the included app to access files there. I probably have uPNP turned on on the router
2017-05-27 01:53:33
NAS 啲 vendor 升級密唔密
用緊西部數碼

你部NAS係真IP定響firewall後面?firewall有無Samba port forwarding?
如果響firewall 後,firewall有無forwarding應該安全。不過我識有人屋企部NAS駁出街睇相,但無知到係乜protocol。我自己部router行Linux但一年以上無得update,不過我Samba無開到。

behind firewall, through NAT i think. not sure what ports they use, but i occasionally use the included app to access files there. I probably have uPNP turned on on the router


Run this test at home behind firewall.

http://www.t1shopper.com/tools/port-scan/
2017-05-27 01:57:36
真係好撚驚
2017-05-27 12:46:17
用Router vpn, 有個setting係要enable samba,
係唔係一樣受影響
2017-05-27 13:40:24
Mitigation:

Any of the following:

1. SELinux is enabled by default and our default policy prevents loading of modules from outside
of samba's module directories and therefore blocks the exploit

2. Mount the filessytem which is used by samba for its writeable share, using "noexec" option.

3. Add the parameter:

nt pipe support = no

to the [global] section of your smb.conf and restart smbd. This prevents clients from accessing
any named pipe endpoints. Note this can disable some expected functionality for Windows clients.

即係 sambacry 係 windows client 導致 ?
2017-05-27 14:46:33
Mitigation:

Any of the following:

1. SELinux is enabled by default and our default policy prevents loading of modules from outside
of samba's module directories and therefore blocks the exploit

2. Mount the filessytem which is used by samba for its writeable share, using "noexec" option.

3. Add the parameter:

nt pipe support = no

to the [global] section of your smb.conf and restart smbd. This prevents clients from accessing
any named pipe endpoints. Note this can disable some expected functionality for Windows clients.

即係 sambacry 係 windows client 導致 ?

......

唔識英文定唔知咩係SMB
2017-05-27 16:35:03
唔怕,不可同WannyCry相提並論。

Windows好多人用老翻,焗住要停左windows update

Linux完全免費,且有相關社羣強大支援,就算有漏洞都可以堂而煌之討論及迅速修補
2017-05-27 17:52:20
Mitigation:

Any of the following:

1. SELinux is enabled by default and our default policy prevents loading of modules from outside
of samba's module directories and therefore blocks the exploit

2. Mount the filessytem which is used by samba for its writeable share, using "noexec" option.

3. Add the parameter:

nt pipe support = no

to the [global] section of your smb.conf and restart smbd. This prevents clients from accessing
any named pipe endpoints. Note this can disable some expected functionality for Windows clients.

即係 sambacry 係 windows client 導致 ?

......

唔識英文定唔知咩係SMB

係呀,唔識呀,解黎聽下
2017-05-27 20:17:05
裝 Linux





都要 update 㗎
2017-05-28 00:33:44
NAS 啲 vendor 升級密唔密
用緊西部數碼

你部NAS係真IP定響firewall後面?firewall有無Samba port forwarding?
如果響firewall 後,firewall有無forwarding應該安全。不過我識有人屋企部NAS駁出街睇相,但無知到係乜protocol。我自己部router行Linux但一年以上無得update,不過我Samba無開到。

behind firewall, through NAT i think. not sure what ports they use, but i occasionally use the included app to access files there. I probably have uPNP turned on on the router


Run this test at home behind firewall.

http://www.t1shopper.com/tools/port-scan/

冇 common ports 開住
但其實屋企有4 5 樣 smart home 嘢用 app through cloud access. 中間 個 router upnp 唔肯定有冇開乜 port
2017-05-28 07:13:02
On9問句 mac會唔會有事
2017-05-28 08:52:58
On9問句 mac會唔會有事

有Time Machine米有事都唔駛驚lor
2017-05-28 14:11:38
MrA:一切都係window嘅錯
吹水台自選台熱 門最 新手機台時事台政事台World體育台娛樂台動漫台Apps台遊戲台影視台講故台健康台感情台家庭台潮流台美容台上班台財經台房屋台飲食台旅遊台學術台校園台汽車台音樂台創意台硬件台電器台攝影台玩具台寵物台軟件台活動台電訊台直播台站務台黑 洞