Fourteen Years of Service
Posts: 19,151
Threads: 2,067
RE: BadLock vulnerability 04-10-2016, 03:44 PM
#3
Awfully nice of them to warn people ahead of time, before releasing the vulnerability.
The following 1 user Likes Oni's post:1 user Likes Oni's post
• mothered
Ten Years of Service
Posts: 117
Threads: 29
RE: BadLock vulnerability 04-12-2016, 10:18 PM
#4
So, BadLock did not turn out to be as critical as the researchers claimed, it's primarily just a MitM/DDoS attack vector, so meh..."SadLock"..
For everyone's reference - CVEs that are related to Badlock:
CVE-2016-2118 (SAMR and LSA man in the middle attacks possible)
CVE-2016-0128 / MS16-047 (Windows SAM and LSAD Downgrade Vulnerability)
CVE-2015-5370 (Multiple errors in DCE-RPC code)
CVE-2016-2110 (Man in the middle attacks possible with NTLMSSP)
CVE-2016-2111 (NETLOGON Spoofing Vulnerability)
CVE-2016-2112 (LDAP client and server don't enforce integrity)
CVE-2016-2113 (Missing TLS certificate validation)
CVE-2016-2114 ("server signing = mandatory" not enforced)
CVE-2016-2115 (SMB IPC traffic is not integrity protected)
(This post was last modified: 04-12-2016, 10:20 PM by PLX-2M.)
PLX-2M
~ Dead Enough For Life ~
•
Ten Years of Service
Posts: 117
Threads: 29
RE: BadLock vulnerability 04-12-2016, 11:39 PM
#6
The team that stood up badlock.org and created the hype is currently getting 'burned at the stake' on Twitter #badlock
PLX-2M
~ Dead Enough For Life ~
•