Nissan 370Z Forum  

The New "What did you do with your Z today" (with off topic replies) XXIII

Anyone heard of this "badlock" vulnerability?

Go Back   Nissan 370Z Forum > Nissan 370Z General Area > The Lounge (Off Topic)


Like Tree6284Likes

Closed Thread
 
LinkBack Thread Tools Display Modes
Old 04-07-2016, 02:11 PM   #1 (permalink)
A True Z Fanatic
 
Leingod's Avatar
 
Join Date: Mar 2015
Location: Some Place Cold
Posts: 16,060
Drives: In Circles
Rep Power: 2684397
Leingod has a reputation beyond reputeLeingod has a reputation beyond reputeLeingod has a reputation beyond reputeLeingod has a reputation beyond reputeLeingod has a reputation beyond reputeLeingod has a reputation beyond reputeLeingod has a reputation beyond reputeLeingod has a reputation beyond reputeLeingod has a reputation beyond reputeLeingod has a reputation beyond reputeLeingod has a reputation beyond repute
Default

Anyone heard of this "badlock" vulnerability?
__________________
I AM FLOOF! SOMEBODY FLOOF MY HORN!! ALL HAIL THE FLOOF!!I JUST FLOOFED ON THE FLOOR
Leingod is offline  
Old 04-07-2016, 02:14 PM   #2 (permalink)
A True Z Fanatic
 
madwi's Avatar
 
Join Date: Sep 2012
Location: West Michigan
Posts: 31,410
Drives: Granma red Z
Rep Power: 2684429
madwi has a reputation beyond reputemadwi has a reputation beyond reputemadwi has a reputation beyond reputemadwi has a reputation beyond reputemadwi has a reputation beyond reputemadwi has a reputation beyond reputemadwi has a reputation beyond reputemadwi has a reputation beyond reputemadwi has a reputation beyond reputemadwi has a reputation beyond reputemadwi has a reputation beyond repute
Default

Quote:
Originally Posted by Leingod View Post
Anyone heard of this "badlock" vulnerability?
It has something to do with Windows-Samba doesnt it? Something about an April 12th deadline too. I think I saw something on it a little while ago.

( Click to show/hide )
On April 12th, 2016, a crucial security bug in Windows and Samba will be disclosed. We call it: Badlock.

Engineers at Microsoft and the Samba Team are working together to get this problem fixed. Patches will be released on April 12th.

Admins and all of you responsible for Windows or Samba server infrastructure: Mark the date. (Again: It's April 12th, 2016.)

Please get yourself ready to patch all systems on this day. We are pretty sure that there will be exploits soon after we publish all relevant information.

Q&A

Which Samba versions will get patches?

Patches will be available for Samba 4.4, Samba 4.3 and Samba 4.2 on April 12th.

With the release of Samba 4.4.0 on March 22nd the 4.1 release branch has been marked DISCONTINUED.

Please be aware that Samba 4.1 and below are out of support, even for security fixes. We strongly advise users to upgrade to a supported release, so that you will not have to make a major version update at the time you need to get the security fix installed.

While there will be no official security releases for Samba 4.1 and below published by the Samba Team or SerNet (for EnterpriseSAMBA) some vendors probably will backport the patches.

When on April 12th will the patches be released?

Patches will be released around 17:00 UTC. That's about the same time the Microsoft Patch Tuesday occurs.

Is there a CVE for Badlock?

Yes. Badlock has an assigned CVE. It will be listed here after the patches are released.

Why announce Badlock before April 12th, 2016?

The main goal of this announcement is to give a heads up and to get you ready to patch all systems as fast as possible and have sysadmin resources available on the day the patch will be released. Vendors and distributors of Samba are being informed before a security fix is released in any case. This is part of any Samba security release process.

Weighting to the respective interests of advance warning and utmost secrecy we chose to warn you beforehand, so that everyone has a chance to be ready to install the fixes as soon as they are available. Once the patch is released to the public, it will point to attack vectors and exploits will be in the wild in no time.

Yet Another Bug With A Logo?

What branded bugs are able to achieve is best said with one word: Awareness. Furthermore names for bugs can serve as unique identifiers, other than different CVE/MS bug IDs.

It is a thin line between drawing attention to a severe vulnerability that should be taken seriously and overhyping it. This process didn't start with the branding - it started a while ago with everyone working on fixes.

Who found the Badlock Bug?

Badlock was discovered by Stefan Metzmacher. He's a member of the international Samba Core Team and works at SerNet on Samba. He reported the bug to Microsoft and has been working closely with them to fix the problem.

Where to find more information?

This page will get updates regularly. Please come back for more information.


Copy/pasta inside
madwi is offline  
Old 04-07-2016, 02:15 PM   #3 (permalink)
A True Z Fanatic
 
Leingod's Avatar
 
Join Date: Mar 2015
Location: Some Place Cold
Posts: 16,060
Drives: In Circles
Rep Power: 2684397
Leingod has a reputation beyond reputeLeingod has a reputation beyond reputeLeingod has a reputation beyond reputeLeingod has a reputation beyond reputeLeingod has a reputation beyond reputeLeingod has a reputation beyond reputeLeingod has a reputation beyond reputeLeingod has a reputation beyond reputeLeingod has a reputation beyond reputeLeingod has a reputation beyond reputeLeingod has a reputation beyond repute
Default

Quote:
Originally Posted by madwi View Post
It has something to do with Windows-Samba doesnt it? Something about an April 12th deadline too. I think I saw something on it a little while ago.
Yea, reading up on it now. MAPolce just sent me an email about it for our equipment with Samba. Evidently they're keeping quite until the 12th and then patching before letting the public know and letting the hackerz go cray-cray
__________________
I AM FLOOF! SOMEBODY FLOOF MY HORN!! ALL HAIL THE FLOOF!!I JUST FLOOFED ON THE FLOOR
Leingod is offline  
Old 04-07-2016, 02:30 PM   #4 (permalink)
A True Z Fanatic
 
Join Date: Aug 2009
Location: N/A
Posts: 76,801
Drives: N/A
Rep Power: 141521
kenchan has a reputation beyond reputekenchan has a reputation beyond reputekenchan has a reputation beyond reputekenchan has a reputation beyond reputekenchan has a reputation beyond reputekenchan has a reputation beyond reputekenchan has a reputation beyond reputekenchan has a reputation beyond reputekenchan has a reputation beyond reputekenchan has a reputation beyond reputekenchan has a reputation beyond repute
Default

Quote:
Originally Posted by Leingod View Post
Anyone heard of this "badlock" vulnerability?
no, but i know for certain getting bumped into my iggylist brings badluck vulnerability..
kenchan is offline  
Closed Thread

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
The New "What did you do with your Z today" (with off topic replies) XXII eastwest2300 The Lounge (Off Topic) 10001 04-05-2016 08:15 PM
The New "What did you do with your Z today" (with off topic replies) XVIV eastwest2300 The Lounge (Off Topic) 10005 09-11-2015 08:57 AM
The New "What did you do with your Z today" (with off topic replies) XVIII eastwest2300 The Lounge (Off Topic) 10000 07-09-2015 07:48 PM
The New "What did you do with your Z today" (with off topic replies) XIII JARblue The Lounge (Off Topic) 10011 08-04-2014 04:16 PM
The New "What did you do with your Z today" (with off topic replies) VIII JARblue The Lounge (Off Topic) 10016 11-10-2013 11:21 AM


All times are GMT -5. The time now is 09:50 AM.


Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2025, Jelsoft Enterprises Ltd.
Search Engine Optimization by vBSEO 3.6.0 PL2