΢ÈíSMBv3ÐÒéÔ¶³Ì´úÂëÖ´ÐÐÎó²îÐÞ¸´½¨Òé
Ðû²¼Ê±¼ä 2020-03-14Îó²î±àºÅºÍ¼¶±ð
CVE±àºÅ£ºCVE-2020-0796£¬Î£ÏÕ¼¶±ð£ºÑÏÖØ£¬CVSS·ÖÖµ£º¹Ù·½Î´ÆÀ¶¨
Ó°Ïì°æ±¾
Windows 10 Version 1903 for 32-bit Systems
Windows 10 Version 1903 for x64-based Systems
Windows 10 Version 1903 for ARM64-based Systems
Windows Server, version 1903 (Server Core installation)
Windows 10 Version 1909 for 32-bit Systems
Windows 10 Version 1909 for x64-based Systems
Windows 10 Version 1909 for ARM64-based Systems
Windows Server, version 1909 (Server Core installation)
Îó²î¸ÅÊö
3ÔÂ12ÈÕ£¬Î¢Èí¸üÐÂÇ徲ͨ¸æÕë¶ÔWindows SMBv3¿Í»§¶Ë/·þÎñÆ÷Ô¶³Ì´úÂëÖ´ÐÐÎó²î½ôÆÈÐû²¼ÁËÇå¾²²¹¶¡£¬È·¶¨¸ÃÎó²î±àºÅΪCVE-2020-0796¡£
Microsoft Server Message Block 3.1.1(SMBv3)ÐÒéÔÚ´¦Öóͷ£Ä³Ð©ÇëÇóµÄ·½·¨Öб£´æ´úÂëÖ´ÐÐÎó²î¡£¹¥»÷Õß¿ÉÒÔÈ«ÐĽṹÊý¾Ý°ü·¢Ë͵½SMB·þÎñÆ÷£¬ÎÞÐè¾ÓÉÉí·ÝÑéÖ¤£¬¼´¿ÉÔÚÄ¿µÄ·þÎñÆ÷ÉÏÖ´ÐÐí§Òâ´úÂë¡£¹¥»÷Õß¿Éͨ¹ý°²ÅÅһ̨¶ñÒâSMB v3·þÎñÆ÷£¬²¢ÓÕµ¼Óû§£¨¿Í»§¶Ë£©ÅþÁ¬µ½¸Ã·þÎñÆ÷£¬Ò»µ©Ä¿µÄÓû§ÅþÁ¬£¬¼´¿ÉÔÚÅÌËã»úÉÏÖ´Ðй¥»÷Õß×Ô½ç˵µÄ¶ñÒâ´úÂë¡£
ÓÉÓÚÉÏÊöÎó²îÒ×±»Èä³æÊ¹ÓÃÈö²¥¶ñÒâ³ÌÐò£¬ÍƲâ¿ÉÄÜÔÚδÀ´»á³ÉΪ¶ñÒâÈí¼þºÍ¹¥»÷Õ߯ձéʹÓõÄÎó²î£¬Óë2017Äê5Ô¡°ÓÀºãÖ®À¶¡±Îó²î½ÏΪÏàËÆ¡£
Îó²î¼ì²â
1. ϵͳ°æ±¾¼ì²â
Éó²é×Ô¼ºÊ¹ÓõÄWindows°æ±¾ÊÇ·ñΪÊÜÓ°ÏìµÄ°æ±¾£¬ÒªÁìÈçÏ£º
ʹÓÃWin + RºóÊäÈë¡°WinVer¡±Éó²éÄ¿½ñ²Ù×÷ϵͳµÄ°æ±¾ºÅ¡£ÈôÊǰ汾ºÅÏÔʾΪ1903»ò1909£¬Ôò֤ʵÊÜ´ËÎó²îÓ°Ï죬½¨ÒéÁ¬Ã¦×°Öò¹¶¡¡£
2. ²¹¶¡¼ì²â
ÔÚÊÜÓ°Ïì¹æÄ£ÄڵIJÙ×÷ϵͳÖУ¬¿ÉÖ´ÐÐÒÔÏÂÏÂÁîÉó²é²¹¶¡×°ÖõÄÇéÐΡ£
systeminfo | findstr KB4551762
ÏÂÁîÖ´Ðп¢ÊºóÈôÊÇûÓÐÅÌÎʵ½KB4551762²¹¶¡£¬Ôò¸Ãϵͳ±£´æÇ徲Σº¦¡£
3. ¹¤¾ß¼ì²â
´ËÎó²îÔÚÍøÉÏÒÑÓйûÕæµÄ¼ì²â¹¤¾ß£¬ÂÄÀúÖ¤ÏÂÁо籾¿É¶ÔSMB°æ±¾¾ÙÐмì²â£¬Ïà¹ØÓû§
¿É×ÔÐÐÑ¡ÔñÏÂÔØÊ¹Óá£
Python¼ì²â¾ç±¾
ÏÂÔØÁ´½Ó£ºhttps://github.com/ollypwn/SMBGhost/blob/master/scanner.py
Nmap¼ì²â¾ç±¾(nse¾ç±¾)
ÏÂÔØÁ´½Ó£ºhttps://github.com/cyberstruggle/DeltaGroup/blob/master/CVE-2020-0796/CVE-2020-0796.nse
Powershell¼ì²â¾ç±¾
ÏÂÔØÁ´½Ó£ºhttps://github.com/T13nn3s/CVE-2020-0976/blob/master/CVE-2020-0796-Smbv3-checker.ps1
4. ²úÆ·¼ì²â
×ðÁú¿Ê±Ì쾵ųÈõÐÔɨÃèÓëÖÎÀíϵͳV6.0²úÆ·ÒѾ߱¸¶Ô´ËÎó²î£¨CVE-2020-0796£©µÄɨÃè¼ì²âÄÜÁ¦£¬6070°æ±¾Éý¼¶°üΪ607000278£¬Éý¼¶°üÏÂÔØµØµã£º/article/type/1/146.html¡£
ÐÞ¸´½¨Òé
΢Èí¹Ù·½ÒÑÕë¶Ô¸ÃÎó²îÐû²¼ÁËÇå¾²²¹¶¡KB4551762£¬½¨ÒéÊÜÓ°ÏìÓû§¿ªÆôϵͳ×Ô¶¯¸üÐÂ×°Öøò¹¶¡¾ÙÐзÀ»¤¡£
×¢£ºÓÉÓÚÍøÂçÎÊÌâ¡¢ÅÌËã»úÇéÐÎÎÊÌâµÈÔµ¹ÊÔÓÉ£¬Windows UpdateµÄ²¹¶¡¸üпÉÄÜ·ºÆðʧ°Ü¡£Óû§ÔÚ×°Öò¹¶¡ºó£¬Ó¦ÊµÊ±¼ì²é²¹¶¡ÊÇ·ñÀֳɸüС£ÓÒ¼üµã»÷×ÀÃæ×óϽǵÄWindowsͼ±ê£¬Ñ¡Ôñ¡°ÉèÖÃ(N)¡±£¬Ñ¡Ôñ¡°¸üкÍÇå¾²¡±-¡°Windows¸üС±£¬Éó²é¸ÃÒ³ÃæÉϵÄÌáÐÑÐÅÏ¢£¬Ò²¿Éµã»÷¡°Éó²é¸üÐÂÀúÊ·¼Í¼¡±Éó²éÀúÊ·¸üÐÂÇéÐΣ¬È·ÈÏÆäÖÐÊÇ·ñ°üÀ¨¡°KB4551762¡±
Èô·ºÆðδÀÖ³É×°Öøüв¹¶¡µÄÇéÐΣ¬¿É´Ó¹ÙÍøÏÂÔØÀëÏß×°Öðü¾ÙÐиüУ¬ÏÂÔØÁ´½ÓÈçÏ£º
https://www.catalog.update.microsoft.com/Search.aspx?q=KB4551762
»º½â²½·¥£º
1£® ½ûÓÃSMBv3ѹËõ
ÒªÁìÒ»£ºÊ¹ÓÃÒÔÏÂPowerShellÏÂÁî½ûÓÃѹËõ¹¦Ð§£¬ÒÔ×èֹδ¾Éí·ÝÑéÖ¤µÄ¹¥»÷ÕßʹÓÃSMBv3 ·þÎñÆ÷µÄÎó²î¡£
Set-ItemProperty -Path "HKLM:\SYSTEM\CurrentControlSet\Services\LanmanServer\Parameters" DisableCompression -Type DWORD -Value 1 -Force
Óû§¿Éͨ¹ýÒÔÏÂPowerShellÏÂÁî×÷·Ï½ûÓÃѹËõ¹¦Ð§
Set-ItemProperty -Path "HKLM:\SYSTEM\CurrentControlSet\Services\LanmanServer\Parameters" DisableCompression -Type DWORD -Value 0 -Force
ÒªÁì¶þ£ºÓÒ¼üµã»÷×ÀÃæ×óϽǵÄWindowsͼ±ê£¬ÔÚµ¯³ö²Ëµ¥ÖÐÑ¡Ôñ¡°ÔËÐС±²Ëµ¥ÏÔÚµ¯³öµÄÔËÐпòÖÐÊäÈëregedit£¬·¿ª×¢²á±í±à¼Æ÷¡£
ÔÚ ¡°HKLM\SYSTEM\CurrentControlSet\Services\LanmanServer\Parameters¡±Ä¿Â¼ÖÐÌí¼ÓÒ»¸öDWORDÀàÐ͵Ä×¢²á±íÏîDisableCompression £¬ÊýֵΪ1¡£
ÈçÐè×÷·Ï½ûÓÃSMBv3ѹËõ¹¦Ð§£¬½«¸Ã×¢²á±íÏîÊýÖµÐÞ¸ÄΪ0»òɾ³ý×¢²á±íÏî¼´¿É¡£
×¢£ºÊ¹ÓÃÒÔÉÏÒªÁì¾ÙÐиü¸Äºó£¬ÎÞÐèÖØÆô¼´¿ÉÉúЧ£»¸ÃÒªÁì½ö¿ÉÓÃÀ´·À»¤Õë¶ÔSMB·þÎñÆ÷£¨SMB SERVER£©µÄ¹¥»÷£¬ÎÞ·¨¶ÔSMB¿Í»§¶Ë£¨SMB Client£©¾ÙÐзÀ»¤¡£
2. ÉèÖ÷À»ðǽսÂÔ
ÔÚ½çÏß·À»ðǽ×öºÃÇå¾²Õ½ÂÔ×èÖ¹SMBͨѶÁ÷³öÆóÒµÄÚ²¿£¬ÏêÇé¿É²Î¿¼Î¢Èí¹Ù·½µÄÖ¸ÄÏ£ºhttps://support.microsoft.com/zh-cn/help/3185535/preventing-smb-traffic-from-lateral-connections¡£
3. ²úÆ··À»¤
Õë¶Ô´ËÎó²î£¬×ðÁú¿Ê±IDS¡¢IPS¡¢WAF¡¢APT²úÆ·ÒÑÐû²¼¹æÔòÉý¼¶°ü£¬ÏÂÔØµØµã£º/article/type/1/140.html¡£
²Î¿¼Á´½Ó
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0796


¾©¹«Íø°²±¸11010802024551ºÅ