FAQ | Search | Memberlist | Usergroups | Register | Profile | Inbox | Log in | SmartFeedSmartFeed


 okgg.org > Forum Index > All Things Technical > Vulnerability/Exploit Alert

  Author    Thread Post new topic  Reply to topic
Shinare
SEXNOCULAR


Joined: 17 Mar 2004
Posts: 13332
Location: Up your butt with a coconut!!
Vulnerability/Exploit Alert  Reply with quote  

You all have probably heard about this already, but I thought I would pass this along.

A flaw in the Microsoft SMB2 protocol has been identified and is being
actively exploited. While originally identified as a denial-of-service
issue, recent developments indicate that a remote code execution component
will be added to attack frameworks in the very near future. A successful
attack could result in the attacker obtaining complete control of the
compromised
system. In the absence of a patch, Microsoft recommends that users disable
SMB v2
and block TCP ports 139 and 445 at the firewall.


This should be a best practice for any internet facing Microsoft server.


The vulnerability exists on SMB2 in Windows Vista SP1 and above and in
Server 2008 operating systems.

Heres a link to a new article that contains links to REG files that will automatically disable SMB2 and also one that will re-enable it.
_________________
For with what measure you measure it will be measured to you.

Post Thu Sep 17, 2009 3:20 pm  View user's profile Send private message ICQ Number
LightningCrash
Smile like Bob, order your free LC today


Joined: 03 Apr 2003
Posts: 5020
 Reply with quote  

If you open 139 and 445 on your public systems, you're probably already compromised.

Post Thu Sep 17, 2009 5:19 pm  View user's profile Send private message
  Display posts from previous:      
Post new topic  Reply to topic

Last Thread | Next Thread  >

Quick Reply

  
Jump to:  
Forum Rules:
You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum