Misplaced Pages

Badlock

Article snapshot taken from Wikipedia with creative commons attribution-sharealike license. Give it a read and then ask your questions in the chat. We can research this topic together.
Security bug
Badlock
Logo representing Badlock.
CVE identifier(s)CVE-2016-2118
Websitehttps://web.archive.org/web/20170608065927/http://badlock.org/

Badlock (CVE-2016-2118) is a security bug disclosed on April 12, 2016 affecting the Security Account Manager (SAM) and Local Security Authority (Domain Policy) (LSAD) remote protocols supported by Windows and Samba servers.

Both SAM and LSAD are layered onto the DCE 1.1 Remote Procedure Call (DCE/RPC) protocol. As implemented in Samba and Windows, the RPC services allowed an attacker to become man in the middle. Although the vulnerability was discovered during the development of Samba, the namegiving SMB protocol itself is not affected.

References

  1. "Microsoft Security Bulletin MS16-047". Microsoft TechNet. 2016-04-12. Retrieved 2018-02-21.
  2. "Badlock Bug". Archived from the original on 2017-06-08. Retrieved 2018-02-21.
  3. "CVE-2016-2118". Retrieved 2018-02-21.

External links

Hacking in the 2010s
← 2000s Timeline 2020s →
Major incidents
2010
2011
2012
2013
2014
2015
2016
2017
2018
2019
Hacktivism
Advanced
persistent threats
Individuals
Major vulnerabilities
publicly disclosed
Malware
2010
2011
2012
2013
2014
2015
2016
2017
2018
2019
Categories: