![]() |
|
BadLock vulnerability - Printable Version +- Sinisterly (https://sinister.li) +-- Forum: General (https://sinister.li/Forum-General) +--- Forum: World News (https://sinister.li/Forum-World-News) +--- Thread: BadLock vulnerability (/Thread-BadLock-vulnerability) |
BadLock vulnerability - PLX-2M - 04-09-2016 So, in a few days security researchers will release details regarding critical vulnerability in SMB (Server Message Block) and CIFS (Common Internet File System) protocols. Vulnerability will most likely affect most of Windows systems and any Linux computer running SAMBA. Microsoft will release relevant patch next Tuesday, April 12. Additional information: http://badlock.org/ RE: BadLock vulnerability - mothered - 04-09-2016 The details are still sketchy at the moment. A quick Google search revealed this: Quote:The name Badlock is a clue on where the vulnerability may be located, as it could refer to a file or resource-locking mechanism within the SMB implementation, and the code that controls it. There's even a file in the Samba source code called lock.c. Source: http://www.infoworld.com/article/3048452/security/the-badlock-bug-start-your-patch-prep-today.html Still, nothing really conclusive. I shall look further Into It. Thanks for bringing this to everyone's attention. RE: BadLock vulnerability - Oni - 04-10-2016 Awfully nice of them to warn people ahead of time, before releasing the vulnerability. RE: BadLock vulnerability - PLX-2M - 04-12-2016 So, BadLock did not turn out to be as critical as the researchers claimed, it's primarily just a MitM/DDoS attack vector, so meh..."SadLock".. For everyone's reference - CVEs that are related to Badlock: CVE-2016-2118 (SAMR and LSA man in the middle attacks possible) CVE-2016-0128 / MS16-047 (Windows SAM and LSAD Downgrade Vulnerability) CVE-2015-5370 (Multiple errors in DCE-RPC code) CVE-2016-2110 (Man in the middle attacks possible with NTLMSSP) CVE-2016-2111 (NETLOGON Spoofing Vulnerability) CVE-2016-2112 (LDAP client and server don't enforce integrity) CVE-2016-2113 (Missing TLS certificate validation) CVE-2016-2114 ("server signing = mandatory" not enforced) CVE-2016-2115 (SMB IPC traffic is not integrity protected) RE: BadLock vulnerability - meow - 04-12-2016 (04-12-2016, 10:18 PM)PLX-2M Wrote: So, BadLock did not turn out to be as critical as the researchers claimed They probably over-exaggerated it for the fame and in hopes of it becoming something big like heartbleed, which is probably why they tied a logo to it too. RE: BadLock vulnerability - PLX-2M - 04-12-2016 The team that stood up badlock.org and created the hype is currently getting 'burned at the stake' on Twitter #badlock |