SMBv3¡°Èä³æ¼¶¡±Â©¶´À´Ï® ¶¶È¦Îª¶Ä¶øÉúÌṩ½â¾ö·½°¸£¡
Ðû²¼Ê±¼ä 2020-03-123ÔÂ10ÈÕ£¬Î¢ÈíÐû²¼Äþ¾²Í¨¸æ£¨ADV200005£©³ÆÔÚMicrosoft Server Message Block 3.1.1 £¨SMBv3£©ÐÒéÖдæÔÚÒ»¸öÔ¶³Ì´úÂëÖ´ÐЩ¶´(CVE-2020-0796£¬Óֳơ°CoronaBlue¡±»ò¡°SMB Ghost¡±)¡£¸Ã©¶´ÊÇÓÉSMBv3ÐÒé´¦ÖöñÒâѹËõÊý¾Ý°üʱ½øÈë´íÎóÁ÷³ÌÔì³ÉµÄ£¬Ô¶³Ìδ¾Éí·ÝÑéÖ¤µÄ¹¥»÷Õß¿ÉÒÔÀûÓø鶴Ôì³ÉÄ¿±êÖ÷»úϵͳÍ߽⡢À¶ÆÁÉõÖÁÖ´ÐÐÈÎÒâ´úÂë¡£
ÓÉÓڸ鶴¿ÉÒÔÖ±½ÓÓÃÓÚÔ¶³Ì¹¥»÷£¬¶øÇÒ¿ÉÒÔ¡°Èä³æ»¯¡±£¬Òò´Ë£¬ÆäΣº¦Ë®Æ½ÀàËÆÓÚ2017ÄêµÄ¡°ÓÀºãÖ®À¶¡±Â©¶´¡£µ«Ïà½ÏÓÚ¡°ÓÀºãÖ®À¶¡±£¬¸Ã©¶´Ó°ÏìµÄ·¶Î§Ïà¶Ô½ÏС£¬Ö»ÏÞÓÚWindows10ÒÔ¼°Windows Server µÄ1903ºÍ1909°æ±¾£¬¾ßÌåÓ°ÏìµÄ°æ±¾ºÅÈçÏ£º
Windows 10 Version 1903 for 32-bit Systems
Windows 10 Version 1903 for ARM64-based Systems
Windows 10 Version 1903 for x64-based Systems
Windows 10 Version 1909 for 32-bit Systems
Windows 10 Version 1909 for ARM64-based Systems
Windows 10 Version 1909 for x64-based Systems
Windows Server, version 1903 (Server Core installation)
Windows Server, version 1909 (Server Core installation)
¶¶È¦Îª¶Ä¶øÉú½â¾ö·½°¸
Ò»¡¢ ½ûÓÃSMBv3ѹËõ
ËäÈ»±¾Â©¶´Ó°ÏìµÄ·¶Î§Ïà¶Ô½ÏС£¬µ«ÊÇÓÉÓÚΣº¦¼¶±ð½Ï¸ß£¬¶øÇÒ΢ÈíûÓиø³öÏàÓ¦µÄ©¶´²¹¶¡£¬ËùÒÔ½¨Òé¶ÔÊÜÓ°ÏìµÄ²Ù×÷ϵͳʹÓÃÒÔÏ»º½â´ëÊ©½ûÓÃSMBv3µÄѹËõ¹¦Ð§À´½øÐзÀ»¤¡£
Ê×Ïȼì²ì×Ô¼ºÊ¹ÓõÄWindows°æ±¾ÊÇ·ñΪÊÜÓ°ÏìµÄ°æ±¾£¬ÒªÁìÈçÏ£º
ʹÓÃWin + RºóÊäÈë¡°WinVer¡±¼ì²ìµ±Ç°²Ù×÷ϵͳµÄ°æ±¾ºÅ¡£
Èç¹ûÈ·ÈÏϵͳÊÜÓ°Ï죬Ôò½¨ÒéʹÓÃÒÔÏÂPowerShellÃüÁî½ûÓÃѹËõ¹¦Ð§£¬ÒÔ×èֹδ¾Éí·ÝÑéÖ¤µÄ¹¥»÷ÕßÀûÓÃSMBv3·þÎñÆ÷µÄ©¶´£¨ÎÞÐèÖØÐÂÆô¶¯£©¡£
Set-ItemProperty-Path "HKLM:\SYSTEM\CurrentControlSet\Services\LanmanServer\Parameters" DisableCompression -Type DWORD -Value 1 -Force
¶þ¡¢ ²úÎï½â¾ö·½°¸
1¡¢ÒѲ¿Êð¶¶È¦Îª¶Ä¶øÉúIDS¡¢IPS¡¢WAF¡¢APT²úÎïµÄ¿Í»§ÇëÈ·ÈÏÈçÏÂʼþ¹æÔòÒѾÏ·¢²¢Ó¦Ó㬼´¿ÉÓÐЧ¼ì²âÏà¹Ø¹¥»÷£º TCP_CVE-2020-0796©¶´ÀûÓá£
£¨1£©ÌìãÙÈëÇÖ¼ì²âÓë¹ÜÀíϵͳ±¨¾¯½Øͼ£º
£¨2£©ÌìÇåÈëÇÖ·ÀÓùϵͳ±¨¾¯½Øͼ£º
£¨3£©ÌìÇåWebÓ¦ÓÃÄþ¾²Íø¹Ø±¨¾¯½Øͼ£º
£¨4£©Ììãٸ߼¶Á¬ÐøÐÔÍþв¼ì²âÓë¹ÜÀíϵͳ±¨¾¯½Øͼ£º
2¡¢¶¶È¦Îª¶Ä¶øÉúÌì¾µ´àÈõÐÔɨÃèÓë¹ÜÀíϵͳV6.0ÓÚ2020Äê3ÔÂ12ÈÕ½ô¼±Ðû²¼Õë¶Ô¸Ã©¶´µÄÉý¼¶°ü£¬Ö§³Ö¶Ô¸Ã©¶´½øÐмì²â£¬Óû§Éý¼¶Ì쾵©ɨ²úÎ勇´¿âºó¼´¿É¶Ô¸Ã©¶´½øÐÐɨÃè¡£6070°æ±¾Éý¼¶°üΪ607000278£¬Éý¼¶°üÏÂÔصØÖ·£º
/article/type/1/146.html
ÇëÌì¾µ´àÈõÐÔɨÃèÓë¹ÜÀíϵͳV6.0²úÎïµÄÓû§¾¡¿ìÉý¼¶µ½×îа汾£¬¼°Ê±¶Ô¸Ã©¶´½øÐмì²â£¬ÒԱ㾡¿ì½ÓÄÉ·À·¶´ëÊ©¡£
3¡¢ÒѲ¿ÊðÌ©ºÏTSOCϵÁвúÎïµÄÆóÊÂÒµµ¥Ôª£¬½¨ÒéÌí¼ÓÏàÓ¦µÄ¹æÔòÁ¬Ðø¶Ô¸ÃÐÐΪ½øÐмà¿Ø¡£
¹ØÁª¹æÔò£ºL3_MC_SMBv3Èä³æÔ¶³ÌÖ´ÐЩ¶´ÀûÓÃ-CVE-2020-0796
˵Ã÷£º
¡°L3_MC_SMBv3Èä³æÔ¶³ÌÖ´ÐЩ¶´ÀûÓÃ-CVE-2020-0796¡±¹ØÁª¹æÔòÊǹæÔòǶÌ׵ĹæÔò£¬ÓÃÓÚ¼à²âSMBv3©¶´¡¾CVE-2020-0706¡¿ÀûÓÃÐÐΪ£¬Í¬Ê±Ò²¼à²âÅúÁ¿445¶Ë¿Ú·ÃÎʵÄÐÐΪ¡£
Èô½ÓÈëTSOCƽ̨µÄÄþ¾²¼ì²âÉ豸¼ÆıÎÞÉý¼¶¡¢¸üУ¬¿ÉÒÔµ¥¶ÀʹÓá°L2_ADS_ÅúÁ¿445¶Ë¿Ú·ÃÎÊ¡±¹æÔò¶Ô445¶Ë¿Ú·ÃÎÊÇé¿ö½øÐмà¿Ø¡£
×¢£º¡°L3_MC_SMBv3Èä³æÔ¶³ÌÖ´ÐЩ¶´ÀûÓÃ-CVE-2020-0796¡±¹æÔòÒÑ°üÂÞ¡°L2_ADS_ÅúÁ¿445¶Ë¿Ú·ÃÎÊ¡±£¬Ö±½Óµ¼Èë¡°L3_MC_SMBv3Èä³æÔ¶³ÌÖ´ÐЩ¶´ÀûÓÃ-CVE-2020-0796¡±¹æÔò°ü£¬ÎÞÐèµ¥¶ÀÅäÖá°L2_ADS_ÅúÁ¿445¶Ë¿Ú·ÃÎÊ¡±¡£
¡°L3_MC_SMBv3Èä³æÔ¶³ÌÖ´ÐЩ¶´ÀûÓÃ-CVE-2020-0796¡±¹æÔòÌõ¼þ£º
ʼþ=£¨ÈÕÖ¾ÀàÐÍ£¡=¡°¹ØÁªÊ¼þ¡±£©&£¨£¨É豸ÀàÐÍÊôÓÚ£¨Äþ¾²É豸/Äþ¾²·À»¤Íø¹Ø¡¢Äþ¾²É豸/webÓ¦ÓÃÍø¹Ø¡¢Äþ¾²É豸/ÈëÇÖ¼ì²â¡¢Äþ¾²É豸/Äþ¾²·ÀÓù¡¢Äþ¾²É豸/·À²¡¶¾ÏµÍ³¡¢Äþ¾²É豸/¶ñÒâ´úÂë¼ì²â¡¢Äþ¾²É豸/ÖÕ¶ËÄþ¾²¹ÜÀí£©£©&£¨Ä¿µÄ¶Ë¿Ú=¡°445¡±£©&£¨ÒýÓùýÂËÆ÷=¡°CVE20200796_Äþ¾²É豸¡±£©£©|£¨ÒýÓùæÔò=¡°L2_ADS_ÅúÁ¿445¶Ë¿Ú·ÃÎÊ¡±£©
¡°CVE20200796_Äþ¾²É豸¡±¹ýÂËÆ÷Ìõ¼þ£º
ʼþ=£¨ÈÕÖ¾ÀàÐÍ£¡=¡°¹ØÁªÊ¼þ¡±£©&£¨£¨Ê¼þÃû³Æ °üÂÞ ¡°Corona¡± £©&£¨Ê¼þÃû³Æ °üÂÞ ¡°Blue¡±£©&£¨Ê¼þÃû³Æ °üÂÞ ¡°Â©¶´¡±£©£©|(£¨Ê¼þÃû³Æ °üÂÞ ¡°CVE-2020-0796¡± £©)|(£¨Ê¼þÃû³Æ °üÂÞ ¡°SMBv3¡± £©&£¨£¨£¨Ê¼þÃû³Æ °üÂÞ ¡°Â©¶´¡± £©|£¨Ê¼þÃû³Æ °üÂÞ ¡°Á¬½Ó¡± £©£©£©)
¡°L2_ADS_ÅúÁ¿445¶Ë¿Ú·ÃÎÊ¡±¹æÔòÌõ¼þ£º
ʼþ=£¨ÈÕÖ¾ÀàÐÍ£¡=¡°¹ØÁªÊ¼þ¡±£©&£¨Ä¿µÄ¶Ë¿Ú=¡°445¡±£©
¡°L2_ADS_ÅúÁ¿445¶Ë¿Ú·ÃÎÊ¡±´ÎÊýÉèÖãº