Conversation:
Notices
-
GeniusMusing (geniusmusing)'s status on Monday, 21-Sep-2020 17:42:57 EDT GeniusMusing Samba Security Announcement Archivehttps://www.samba.org/samba/security/CVE-2020-1472.html >== Subject: Unauthenticated domain takeover via netlogon ("ZeroLogon") >== CVE ID#: CVE-2020-1472 >== Versions: Samba 4.0 and later >== Summary: An unauthenticated attacker on the network can gain administrator access by exploiting a netlogon protocol flaw. >Description >The following ap… - LinuxWalt (@lnxw48a1) {3EB165E0-5BB1-45D2-9E7D-93B31821F864} repeated this.
-
LinuxWalt (@lnxw48a1) {3EB165E0-5BB1-45D2-9E7D-93B31821F864} (lnxw48a1)'s status on Monday, 21-Sep-2020 18:02:03 EDT LinuxWalt (@lnxw48a1) {3EB165E0-5BB1-45D2-9E7D-93B31821F864} @geniusmusing That's really bad. Unauthenticated domain takeover is just about the worst possible flaw for #AD / #LDAP.