SambaCry 正式登錄Linux
power_off 2017-5-26 10:02:28


今次到 #Samba (Linux 上嘅 SMB share server) 有遙距攻擊漏洞,Exploit code 已流通,不禁令人擔心類似 #WannaCry 同 #EternalBlue 相關嘅攻擊今次會針對 Linux-based 系統。如果攻擊成功,除咗有機會中 Ransomware 外,仲可能偷或修改到部機入面嘅資料

#NAS 高危!

Btw 跟據小編尋晚收集嘅資料,攻擊條件可能包括有 writable share / pipe,未必係人都得,但值得大家留意一下。



初則口交 2017-5-26 10:21:41 有patch未
做咩呢? 2017-5-26 10:26:50

宮水.三葉 2017-5-26 13:12:18 MrA:用家問題
[object_Object] 2017-5-26 15:22:15 Mitigation:

Any of the following:

1. SELinux is enabled by default and our default policy prevents loading of modules from outside
of samba's module directories and therefore blocks the exploit

2. Mount the filessytem which is used by samba for its writeable share, using "noexec" option.

3. Add the parameter:

nt pipe support = no

to the [global] section of your smb.conf and restart smbd. This prevents clients from accessing
any named pipe endpoints. Note this can disable some expected functionality for Windows clients.
櫻井螢 2017-5-26 16:14:57 🤢
柴田ミチコ 2017-5-26 23:17:22 NAS 啲 vendor 升級密唔密

NAS 啲 vendor 升級密唔密


你部NAS係真IP定響firewall後面?firewall有無Samba port forwarding?
如果響firewall 後,firewall有無forwarding應該安全。不過我識有人屋企部NAS駁出街睇相,但無知到係乜protocol。我自己部router行Linux但一年以上無得update,不過我Samba無開到。
NAS 啲 vendor 升級密唔密


你部NAS係真IP定響firewall後面?firewall有無Samba port forwarding?
如果響firewall 後,firewall有無forwarding應該安全。不過我識有人屋企部NAS駁出街睇相,但無知到係乜protocol。我自己部router行Linux但一年以上無得update,不過我Samba無開到。

behind firewall, through NAT i think. not sure what ports they use, but i occasionally use the included app to access files there. I probably have uPNP turned on on the router


NAS 啲 vendor 升級密唔密


你部NAS係真IP定響firewall後面?firewall有無Samba port forwarding?
如果響firewall 後,firewall有無forwarding應該安全。不過我識有人屋企部NAS駁出街睇相,但無知到係乜protocol。我自己部router行Linux但一年以上無得update,不過我Samba無開到。

behind firewall, through NAT i think. not sure what ports they use, but i occasionally use the included app to access files there. I probably have uPNP turned on on the router

Run this test at home behind firewall.
LIHKGMr.A 2017-5-27 01:57:36 真係好撚驚
抹茶拿鐡 2017-5-27 12:46:17 用Router vpn, 有個setting係要enable samba,
即係 sambacry 係 windows client 導致 ?
即係 sambacry 係 windows client 導致 ?


家屬謝禮 2017-5-27 16:35:03 唔怕,不可同WannyCry相提並論。

Windows好多人用老翻,焗住要停左windows update

即係 sambacry 係 windows client 導致 ?



Fringe 2017-5-27 20:17:05 裝 Linux

都要 update 㗎
NAS 啲 vendor 升級密唔密


你部NAS係真IP定響firewall後面?firewall有無Samba port forwarding?
如果響firewall 後,firewall有無forwarding應該安全。不過我識有人屋企部NAS駁出街睇相,但無知到係乜protocol。我自己部router行Linux但一年以上無得update,不過我Samba無開到。

behind firewall, through NAT i think. not sure what ports they use, but i occasionally use the included app to access files there. I probably have uPNP turned on on the router

Run this test at home behind firewall.

冇 common ports 開住
但其實屋企有4 5 樣 smart home 嘢用 app through cloud access. 中間 個 router upnp 唔肯定有冇開乜 port


婆你呀麼彈彈波 2017-5-28 07:13:02 On9問句 mac會唔會有事
On9問句 mac會唔會有事

有Time Machine米有事都唔駛驚lor
宮水.三葉 2017-5-28 14:11:38 MrA:一切都係window嘅錯