I-Exchange Vulnerability: Ungakuthola Kanjani Ukuphakama Kwamalungelo Kumlawuli Wesizinda

Kutholwe kulo nyaka ubungozi ku-Exchange ivumela noma yimuphi umsebenzisi wesizinda ukuthi athole amalungelo omphathi wesizinda futhi afake engozini Uhla Lwemibhalo Olusebenzayo (AD) nabanye ababungazi abaxhunyiwe. Namuhla sizokutshela ukuthi lokhu kuhlasela kusebenza kanjani nokuthi ungakuthola kanjani.

I-Exchange Vulnerability: Ungakuthola Kanjani Ukuphakama Kwamalungelo Kumlawuli Wesizinda

Nakhu ukuthi lokhu kuhlasela kusebenza kanjani:

  1. Umhlaseli uthatha i-akhawunti yanoma yimuphi umsebenzisi wesizinda ngebhokisi leposi elisebenzayo ukuze abhalisele isici sesaziso sohlelo lokusebenza oluvela ku-Exchange.
  2. Umhlaseli usebenzisa i-NTLM edluliselwe ukukhohlisa iseva ye-Exchange: ngenxa yalokho, iseva ye-Exchange ixhuma kukhompuyutha yomsebenzisi eyonakele kusetshenziswa indlela ye-NTLM ngokusebenzisa indlela ye-HTTP, umhlaseli abe eseyisebenzisa ukuze aqinisekise isilawuli sesizinda nge-LDAP enemininingwane ye-akhawunti ye-Exchange.
  3. Umhlaseli ugcina esebenzisa lezi mininingwane ze-akhawunti ye-Exchange ukuze andise amalungelo akhe. Lesi sinyathelo sokugcina singenziwa futhi umlawuli onobutha osevele enokufinyelela okusemthethweni ukuze enze ushintsho oludingekayo lwemvume. Ngokwenza umthetho wokuthola lo msebenzi, uzovikeleka kulokhu nokuhlasela okufanayo.

Ngokulandelayo, umhlaseli angakwazi, isibonelo, ukusebenzisa i-DCSync ukuze athole amaphasiwedi asheshayo abo bonke abasebenzisi esizindeni. Lokhu kuzomvumela ukuthi enze izinhlobo ezahlukene zokuhlasela - kusukela ekuhlaselweni kwamathikithi egolide kuya ekudlulisweni kwe-hashi.

Ithimba labacwaningi be-Varonis liye lacwaninga ngokuningiliziwe le vector yokuhlasela futhi lalungiselela umhlahlandlela ukuze amakhasimende ethu ayibone futhi ngesikhathi esifanayo ahlole ukuthi asevele esengozini yini.

Ukutholwa Kokwenyuka Kwelungelo Lesizinda

Π’ DataAlert Dala umthetho wangokwezifiso ukuze ulandelele izinguquko ezimvumeni ezithile entweni. Izoqaliswa lapho wengeza amalungelo nezimvume entweni onentshisekelo kuyo esizindeni:

  1. Cacisa igama lomthetho
  2. Setha isigaba ku-"Elevation of Privilege"
  3. Setha uhlobo lwensiza kokuthi "Zonke izinhlobo zensiza"
  4. Isiphakeli Sefayela = Izinsizakalo Zemibhalo
  5. Cacisa isizinda onentshisekelo kuso, isibonelo, ngegama
  6. Engeza isihlungi ukuze wengeze izimvume entweni ye-AD
  7. Futhi ungakhohlwa ukushiya inketho ethi "Sesha ezintweni zengane" ingakhethiwe.

I-Exchange Vulnerability: Ungakuthola Kanjani Ukuphakama Kwamalungelo Kumlawuli Wesizinda

Futhi manje umbiko: ukutholwa kwezinguquko kumalungelo ento yesizinda

Ushintsho kuzimvume entweni ye-AD aluvamile, ngakho-ke noma yini ebangele lesi sexwayiso kufanele futhi kufanele iphenywe. Kungaba umqondo omuhle futhi ukuhlola ukubukeka nokuqukethwe kombiko ngaphambi kokwethula umthetho ngokwawo empini.

Lo mbiko uzophinde ubonise uma ngabe usuvele ufakwe ebucayini ngalokhu kuhlasela:

I-Exchange Vulnerability: Ungakuthola Kanjani Ukuphakama Kwamalungelo Kumlawuli Wesizinda

Uma umthetho usucushiwe, ungaphenya zonke ezinye izehlakalo zokukhuphuka kwelungelo usebenzisa isixhumi esibonakalayo sewebhu se-DatAlert:

I-Exchange Vulnerability: Ungakuthola Kanjani Ukuphakama Kwamalungelo Kumlawuli Wesizinda

Uma usulungiselele lesi simiso, ungakwazi ukuqapha futhi uvikele kulokhu kanye nezinhlobo ezifanayo zobungozi bokuphepha, uphenye izehlakalo ngezinto zohla lwemibhalo ye-AD, futhi unqume ukuthi ungaba sengozini yini kulobu bungozi obubalulekile.

Source: www.habr.com

Engeza amazwana