{"id":94510,"date":"2020-09-18T01:41:56","date_gmt":"2020-09-17T23:41:56","guid":{"rendered":"https:\/\/prohoster.info\/blog\/novosti-interneta\/realizacziya-kontrollera-domena-v-samba-okazalas-podverzhena-uyazvimosti-zerologin"},"modified":"2020-09-18T01:41:56","modified_gmt":"2020-09-17T23:41:56","slug":"realizacziya-kontrollera-domena-v-samba-okazalas-podverzhena-uyazvimosti-zerologin","status":"publish","type":"post","link":"https:\/\/prohoster.info\/it\/blog\/news\/realizacziya-kontrollera-domena-v-samba-okazalas-podverzhena-uyazvimosti-zerologin","title":{"rendered":"L'implementazione del controller di dominio in Samba si \u00e8 rivelata vulnerabile alla vulnerabilit\u00e0 ZeroLogin","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p>Gli sviluppatori del progetto Samba <noindex><a rel=\"nofollow\" href=\"https:\/\/www.mail-archive.com\/samba-announce@lists.samba.org\/msg00523.html\">hanno avvertito<\/a><\/noindex> utenti, che di recente <noindex><a rel=\"nofollow\" href=\"https:\/\/portal.msrc.microsoft.com\/en-US\/security-guidance\/advisory\/CVE-2020-1472\">\u00e8 stata identificata<\/a><\/noindex> la vulnerabilit\u00e0 ZeroLogin in Windows (<noindex><a rel=\"nofollow\" href=\"https:\/\/security-tracker.debian.org\/tracker\/CVE-2020-1472\">CVE-2020-1472<\/a><\/noindex>) <noindex><a rel=\"nofollow\" href=\"https:\/\/bugzilla.samba.org\/show_bug.cgi?id=14497\">si manifesta<\/a><\/noindex> e nell'implementazione del controller di dominio basata su Samba. La vulnerabilit\u00e0 <noindex><a rel=\"nofollow\" href=\"https:\/\/www.secura.com\/pathtoimg.php?id=2055\">causato<\/a><\/noindex> \u00e8 dovuta a errori nel protocollo MS-NRPC e nell'algoritmo crittografico AES-CFB8 e, se sfruttata con successo, consente a un attaccante di ottenere l'accesso come amministratore al controller di dominio.<\/p>\n<p>La vulnerabilit\u00e0 \u00e8 nel fatto che il protocollo MS-NRPC (Netlogon Remote Protocol) consente, durante lo scambio di dati di autenticazione, di tornare all'uso di una connessione RPC non crittografata. Dopodich\u00e9, un attaccante pu\u00f2 sfruttare una falla nell'algoritmo AES-CFB8 per falsificare un accesso riuscito al sistema. In media, per accedere come amministratore sono necessarie circa 256 tentativi di spoofing. Non \u00e8 richiesta la presenza di un account di lavoro nel controller di dominio: i tentativi di spoofing possono essere effettuati utilizzando una password errata. La richiesta di autenticazione tramite NTLM verr\u00e0 reindirizzata al controller di dominio, che restituir\u00e0 un diniego di accesso, ma l'attaccante pu\u00f2 falsificare questa risposta, e il sistema attaccato considerer\u00e0 l'accesso come riuscito.<\/p>\n<p>In Samba, la vulnerabilit\u00e0 si manifesta solo nei sistemi che non utilizzano l'impostazione \u00abserver schannel = yes\u00bb, che \u00e8 impostata di default a partire da Samba 4.8. In particolare, possono essere compromessi i sistemi con le impostazioni \u00abserver schannel = no\u00bb e \u00abserver schannel = auto\u00bb, che consentono a Samba di utilizzare le stesse lacune nell'algoritmo AES-CFB8 presenti anche in Windows. <\/p>\n<p>Utilizzando un exploit campione preparato per Windows <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/SecuraBV\/CVE-2020-1472\/blob\/master\/zerologon_tester.py\">il prototipo dell'exploit<\/a><\/noindex>, in Samba si attiva solo la chiamata ServerAuthenticate3, mentre l'operazione ServerPasswordSet2 fallisce (l'exploit richiede adattamento per Samba). Non ci sono informazioni sulla funzionalit\u00e0 di exploit alternativi (<noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/blackarrowsec\/redteam-research\/tree\/master\/CVE-2020-1472\">1<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/dirkjanm\/CVE-2020-1472\">2<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/nccgroup\/nccfsas\/tree\/main\/Tools\/SharpZeroLogon\">3<\/a><\/noindex>, <noindex><a rel=\"nofollow\" href=\"https:\/\/github.com\/gentilkiwi\/mimikatz\/releases\">4<\/a><\/noindex>). \u00c8 possibile monitorare i tentativi di attacco ai sistemi analizzando la presenza di registrazioni che menzionano ServerAuthenticate3 e ServerPasswordSet nei log di audit di Samba.<\/p>\n<p><noindex><a rel=\"nofollow\" name=\"link\"><\/a><\/noindex><\/p>\n<p>Fonte: <a \ncontent=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/www.opennet.ru\/opennews\/art.shtml?num=53728\">opennet.ru<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u0420\u0430\u0437\u0440\u0430\u0431\u043e\u0442\u0447\u0438\u043a\u0438 \u043f\u0440\u043e\u0435\u043a\u0442\u0430 Samba \u043f\u0440\u0435\u0434\u0443\u043f\u0440\u0435\u0434\u0438\u043b\u0438 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u0435\u0439, \u0447\u0442\u043e \u043d\u0435\u0434\u0430\u0432\u043d\u043e \u0432\u044b\u044f\u0432\u043b\u0435\u043d\u043d\u0430\u044f \u0432 Windows \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c ZeroLogin (CVE-2020-1472) \u043f\u0440\u043e\u044f\u0432\u043b\u044f\u0435\u0442\u0441\u044f \u0438 \u0432 \u0440\u0435\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u0438 \u043a\u043e\u043d\u0442\u0440\u043e\u043b\u043b\u0435\u0440\u0430 \u0434\u043e\u043c\u0435\u043d\u0430 \u043d\u0430 \u0431\u0430\u0437\u0435 Samba. \u0423\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u044c \u0432\u044b\u0437\u0432\u0430\u043d\u0430 \u043d\u0435\u0434\u043e\u0440\u0430\u0431\u043e\u0442\u043a\u0430\u043c\u0438 \u0432 \u043f\u0440\u043e\u0442\u043e\u043a\u043e\u043b\u0435 MS-NRPC \u0438 \u043a\u0440\u0438\u043f\u0442\u043e\u0430\u043b\u0433\u043e\u0440\u0438\u0442\u043c\u0435 AES-CFB8, \u0438 \u043f\u0440\u0438 \u0443\u0441\u043f\u0435\u0448\u043d\u043e\u0439 \u044d\u043a\u0441\u043f\u043b\u0443\u0430\u0442\u0430\u0446\u0438\u0438 \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u0435\u0442 \u0437\u043b\u043e\u0443\u043c\u044b\u0448\u043b\u0435\u043d\u043d\u0438\u043a\u0443 \u043f\u043e\u043b\u0443\u0447\u0438\u0442\u044c \u0434\u043e\u0441\u0442\u0443\u043f \u0430\u0434\u043c\u0438\u043d\u0438\u0441\u0442\u0440\u0430\u0442\u043e\u0440\u0430 \u0432 \u043a\u043e\u043d\u0442\u0440\u043e\u043b\u043b\u0435\u0440\u0435 \u0434\u043e\u043c\u0435\u043d\u0430. \u0421\u0443\u0442\u044c \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 \u0432 \u0442\u043e\u043c, \u0447\u0442\u043e \u043f\u0440\u043e\u0442\u043e\u043a\u043e\u043b MS-NRPC (Netlogon Remote Protocol) \u043f\u043e\u0437\u0432\u043e\u043b\u044f\u0435\u0442 \u043f\u0440\u0438 [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-94510","post","type-post","status-publish","format-standard","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.1.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"\u0420\u0430\u0437\u0440\u0430\u0431\u043e\u0442\u0447\u0438\u043a\u0438 \u043f\u0440\u043e\u0435\u043a\u0442\u0430 Samba \u043f\u0440\u0435\u0434\u0443\u043f\u0440\u0435\u0434\u0438\u043b\u0438 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u0435\u0439, \u0447\u0442\u043e \u043d\u0435\u0434\u0430\u0432\u043d\u043e\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/it\/blog\/news\/realizacziya-kontrollera-domena-v-samba-okazalas-podverzhena-uyazvimosti-zerologin\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.1.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"it_IT\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0420\u0435\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u044f \u043a\u043e\u043d\u0442\u0440\u043e\u043b\u043b\u0435\u0440\u0430 \u0434\u043e\u043c\u0435\u043d\u0430 \u0432 Samba \u043e\u043a\u0430\u0437\u0430\u043b\u0430\u0441\u044c \u043f\u043e\u0434\u0432\u0435\u0440\u0436\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 ZeroLogin | ProHoster\" \/>\n\t\t<meta property=\"og:description\" content=\"\u0420\u0430\u0437\u0440\u0430\u0431\u043e\u0442\u0447\u0438\u043a\u0438 \u043f\u0440\u043e\u0435\u043a\u0442\u0430 Samba \u043f\u0440\u0435\u0434\u0443\u043f\u0440\u0435\u0434\u0438\u043b\u0438 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u0435\u0439, \u0447\u0442\u043e \u043d\u0435\u0434\u0430\u0432\u043d\u043e\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/it\/blog\/news\/realizacziya-kontrollera-domena-v-samba-okazalas-podverzhena-uyazvimosti-zerologin\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2020-09-17T23:41:56+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2020-09-17T23:41:56+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47L'implementazione del controller di dominio in Samba si \u00e8 rivelata vulnerabile alla vulnerabilit\u00e0 ZeroLogin | ProHoster","description":"Gli sviluppatori del progetto Samba hanno avvisato gli utenti che di recente","canonical_url":"https:\/\/prohoster.info\/it\/blog\/news\/realizacziya-kontrollera-domena-v-samba-okazalas-podverzhena-uyazvimosti-zerologin","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"it_IT","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0420\u0435\u0430\u043b\u0438\u0437\u0430\u0446\u0438\u044f \u043a\u043e\u043d\u0442\u0440\u043e\u043b\u043b\u0435\u0440\u0430 \u0434\u043e\u043c\u0435\u043d\u0430 \u0432 Samba \u043e\u043a\u0430\u0437\u0430\u043b\u0430\u0441\u044c \u043f\u043e\u0434\u0432\u0435\u0440\u0436\u0435\u043d\u0430 \u0443\u044f\u0437\u0432\u0438\u043c\u043e\u0441\u0442\u0438 ZeroLogin | ProHoster","og:description":"\u0420\u0430\u0437\u0440\u0430\u0431\u043e\u0442\u0447\u0438\u043a\u0438 \u043f\u0440\u043e\u0435\u043a\u0442\u0430 Samba \u043f\u0440\u0435\u0434\u0443\u043f\u0440\u0435\u0434\u0438\u043b\u0438 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u0435\u0439, \u0447\u0442\u043e \u043d\u0435\u0434\u0430\u0432\u043d\u043e","og:url":"https:\/\/prohoster.info\/it\/blog\/news\/realizacziya-kontrollera-domena-v-samba-okazalas-podverzhena-uyazvimosti-zerologin","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2020-09-17T23:41:56+00:00","article:modified_time":"2020-09-17T23:41:56+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"94510","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":null,"breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-02-28 11:25:23","updated":"2022-09-29 04:02:07","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts\/94510","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/comments?post=94510"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/posts\/94510\/revisions"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/media?parent=94510"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/categories?post=94510"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/it\/wp-json\/wp\/v2\/tags?post=94510"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}