A computer components & hardware forum. HardwareBanter

If this is your first visit, be sure to check out the FAQ by clicking the link above. You may have to register before you can post: click the register link above to proceed. To start viewing messages, select the forum that you want to visit from the selection below.

Go Back   Home » HardwareBanter forum » General Hardware & Peripherals » Homebuilt PC's
Site Map Home Register Authors List Search Today's Posts Mark Forums Read Web Partners

OOOHHH!! SCARY HALLOWEEN STORY!! Microsoft US election warning:Attackers hit Windows 10 Netlogon flaw



 
 
Thread Tools Display Modes
  #1  
Old October 30th 20, 08:59 PM posted to alt.privacy.anon-server, alt.comp.os.windows-10,comp.os.linux.advocacy, alt.hacker, alt.comp.hardware.pc-homebuilt
mail.zip2.in Anonymous Remailer
external usenet poster
 
Posts: 1
Default OOOHHH!! SCARY HALLOWEEN STORY!! Microsoft US election warning:Attackers hit Windows 10 Netlogon flaw

Microsoft has warned Windows 10 customers that it has received
"a small number of reports" about attacks on its Netlogon
protocol, which it patched in August.

The Windows maker issued another alert on Thursday following its
warning in September that attackers were exploiting the
elevation of privilege vulnerability affecting the Netlogon
Remote Protocol (MS-NRPC).

It's a protocol used by admins for authenticating Windows Server
as a domain controller. The flaw it contained was serious enough
for the Department of Homeland Security's Cybersecurity and
Infrastructure Security Agency (CISA) to order US government
agencies to apply Microsoft's patch for the bug – tracked as CVE-
2020-1472 but also called Zerologon – within three days of its
release in the August Patch Tuesday update.

SEE: Security Awareness and Training policy (TechRepublic
Premium)

Defensive security researchers found that the bug was easy to
exploit, making it a prime target for more opportunistic
attackers. But when Microsoft released the patch on Tuesday,
August 11, some system admins were not aware of its severity.

Attackers could exploit the flaw to run malware on a device on
the network after spoofing Active Directory domain controller
accounts. As a weapon, it had the added bonus of publicly
available proof-of-concept Zerologon exploits soon after
Microsoft released its patch.

CISA warned agencies to patch the flaw swiftly because Windows
Server domain controllers are widely used in US government
networks, and the bug had a rare severity rating of 10 out of
10. It prompted CISA to direct agencies to apply the patch on
the same week as Microsoft's August 11 patch was released.

Microsoft has updated its support document for the bug to
provide further clarity. It recommends that admins update Domain
Controllers with the patch, monitor logs for devices making
connections to the server, and to enable enforcement mode.

Microsoft and CISA are particularly concerned that the flaw
could be used to by cyber attackers to disrupt the US elections.
The company in September warned that Chinese, Iranian, and
Russian hackers had targeted the Biden and Trump campaigns.

"We contacted CISA, which has issued an additional alert to
remind state and local agencies, including those involved in the
US elections, about applying steps necessary to address this
vulnerability," Microsoft said.

The bug was serious enough for Microsoft to issue a registry key
that helped admins enable 'enforcement mode' before the company
makes that mode mandatory on February 9, 2021.

https://www.zdnet.com/article/micros...ction-warning-
attackers-hit-windows-10-netlogon-flaw/

  #2  
Old October 31st 20, 04:53 PM posted to alt.privacy.anon-server,alt.comp.os.windows-10,comp.os.linux.advocacy,alt.hacker,alt.comp.hardware.pc-homebuilt
Big Bad Bob
external usenet poster
 
Posts: 16
Default OOOHHH!! SCARY HALLOWEEN STORY!! Microsoft US election warning:Attackers hit Windows 10 Netlogon flaw

On 2020-10-30 13:59, mail.zip2.in Anonymous Remailer wrote:
CVE-2020-1472


also affects SAMBA domain controllers, FYI


--
(aka 'Bombastic Bob' in case you wondered)

'Feeling with my fingers, and thinking with my brain' - me

'your story is so touching, but it sounds just like a lie'
"Straighten up and fly right"
 




Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
WTB: URGENT NEED - MICROSOFT OFFICE SOFTWARE ALL VERSIONS/TYPES -MICROSOFT WINDOWS XP PRO, WINDOWS 2000 PRO, WINDOWS HOME ALL VERSIONS/TYPES- NEED AS MANY AS YOU CAN SELL US none Homebuilt PC's 0 April 16th 09 02:18 PM
(OT) Attacks on cursor flaw rise, says Microsoft S.Lewis Dell Computers 1 April 2nd 07 03:23 PM
Awesomely Scary! FACES OF DEATH VCD for Halloween! HALLOWEEN! Storage (alternative) 0 October 16th 04 07:17 AM
Awesomely Scary! FACES OF DEATH VCD for Halloween! HALLOWEEN! General 0 October 16th 04 07:17 AM
NEWS:'Critical' flaw found in Windows trappeduser Homebuilt PC's 14 July 27th 03 01:18 PM


All times are GMT +1. The time now is 03:30 AM.


Powered by vBulletin® Version 3.6.4
Copyright ©2000 - 2024, Jelsoft Enterprises Ltd.
Copyright ©2004-2024 HardwareBanter.
The comments are property of their posters.