Боремся с вирусами и инфраструктурой, или отключение SMB v1


WannaCry, SMB v1, . , Microsoft SMB 2016 . , : , SMB Sonos.


« » SMB , .


SMB (Server Message Block) – . \servername\sharename. NetBIOS, UDP 137, 138 TCP 137, 139. Windows 2000 , TCP 445. SMB Active Directory .


« » – named pipes. \.\pipe\name.

, CIFS (Common Internet File System), 1980- , Windows Vista, 2006. Windows 8. Microsoft Samba.


, , . . , , WannaCry.


SMB.
,
SMB 2.0Windows Vista/2008100+ 19
«» –
HMAC SHA256 MD5
\
SMB 2.1Windows 7/2008R2
MTU
BranchCache – ,
SMB 3.0Windows 8/2012
(RDMA)
Powershell
VSS
AES–CMAC
AES–CCM
HyperV
Microsoft SQL
SMB 3.02Windows 8.1/2012R2
SMB 3.1.1Windows 10/2016AES–GCM
SHA512
«» SMB 2.x


, Get–SmbConnection:



Windows.


, , , . , , – . Windows Set–SmbServerConfiguration, :


Get–SmbServerConfiguration | Select EnableSMB1Protocol, EnableSMB2Protocol


SMBv1 Windows 2012 R2.



Windows 2003.


, , . Windows XP 2003 SMB v1 ( NAS GNU\Linux, samba).


, SMB v1.
BarracudaSSL VPN
Web Security Gateway backups
Canon
CiscoWSA/WSAv
WAAS5.0
F5RDP client gateway
Microsoft Exchange Proxy
Forcepoint (Raytheon)« »
HPEArcSight Legacy Unified Connector
IBMNetServerV7R2
QRadar Vulnerability Manager7.2.x
Lexmark,Firmware eSF 2.x eSF 3.x
Linux KernelCIFS2.5.42 3.5.x
McAfeeWeb Gateway
MicrosoftWindowsXP/2003
MYOBAccountants
NetAppONTAP9.1
NetGearReadyNAS
OracleSolaris11.3
Pulse SecurePCS8.1R9/8.2R4
PPS5.1R9/5.3R4
QNAP4.1
RedHatRHEL7.2
Ricoh,
RSAAuthentication Manager Server
SambaSamba3.5
Sonos
SophosSophos UTM
Sophos XG firewall
Sophos Web Appliance
SUSESLES11
SynologyDiskstation Manager
Thomson ReutersCS Professional Suite
TintriTintri OS, Tintri Global Center
VMwareVcenter
ESXi6.0
WorldoxGX3 DMS
Xerox,ConnectKey Firmware

Microsoft, .


, , – SMB v1 .


-


, SMB v1 , , , . SMB Windows 8/2012 Powershell, Windows 7/2008 . Powershell:



Set–ItemProperty –Path "HKLM:\SYSTEM\CurrentControlSet\Services\LanmanServer\Parameters" SMB1 –Type DWORD –Value 0Force

. .


SMB v1 lanmanworkstation. :


sc.exe config lanmanworkstation depend=bowser/mrxsmb20/nsi 

sc.exe config mrxsmb10 start=disabled

, Group Policy Preferences. .



.


, :




SMB v1 .


SMB v1 .


SMB v1:




.


LanmanWorkstation, SMB v1:




.


. SMB v1 .



, – . , .


, SMB ? ?



Source: https://habr.com/ru/post/J331906/


All Articles