• Patch Lady – we have an out of band on that SMBv3

    Home » Forums » Newsletter and Homepage topics » Patch Lady – we have an out of band on that SMBv3

    • This topic has 8 replies, 5 voices, and was last updated 5 years ago.
    Viewing 5 reply threads
    Author
    Replies
    • #2190103

      Any idea why it’s Server Core only?

      Seems counterintuitive….

    • #2190111

      Windows server is base on 1809. Only Server Core get updated version to 1903 and 1909. If you want the desktop experience, you can only use the 1809 release.

      2 users thanked author for this post.
    • #2190123

      This old SMB article got updated yesterday, but it’s not specifically related to CVE-2020-0796
      https://support.microsoft.com/en-us/help/3185535/preventing-smb-traffic-from-lateral-connections

    • #2190130

      Because the newer stuff is ending up with SMBv3 bugs.  Windows server with a GUI is LTSB and is several years old in patching age.  Only server core is the equivalent of Windows 10 1903 and 1909.  It’s slightly confusing due to the GUI/not GUI server world we live in.

      Susan Bradley Patch Lady/Prudent patcher

      1 user thanked author for this post.
      • #2190153

        So if you have Server Core, you don’t have GUI.

        I think I’m finally starting to understand.

    • #2190167

      NO ONE should be STUPID enough to have port 445 a SMB file sharing port open to the web

      Except, you know, Microsoft? https://azure.microsoft.com/en-us/services/storage/files/

      SMB3 has encryption and security features that were designed to allow it to be used directly without a VPN.

      So I’m still in don’t panic, don’t install and let’s test mode.

      This is a giant vulnerability, so it shouldn’t be left open, even if it can only occur over your local network. There’s no need to install the patch though, the workaround of disabling SMB compression is enough.

      My opinion is that no one should be stupid enough to have a Windows server open to the web, period.

      1 user thanked author for this post.
    • #2190235

      My Windows 7 x64 sp1 systems show port 445 (and 136,137, or 139) being used (listening) by the Windows System (PID 4). I have remote connections disabled on all my machines. From looking around via Google, it seems that this is normal so that the OS can directly communicate over the internet without going through NetBIOS? Is that supposed to be left that way?

      • #2190347

        Those ports are open for local comms.
        To open them on the internet you need to set your router to allow access – you should not do this.

        cheers, Paul

    Viewing 5 reply threads
    Reply To: Patch Lady – we have an out of band on that SMBv3

    You can use BBCodes to format your content.
    Your account can't use all available BBCodes, they will be stripped before saving.

    Your information: