SMB Signing not required 安全漏洞
Issue
如何解决第三方安全扫描程序报告的 SMB Signing not required 安全漏洞?
-
已安装并启用 Samba 文件共享服务器。
-
第三方安全扫描程序报告 SMB Signing not required 安全漏洞。
-
nmap
报告 Message signing disabled 或 Message signing enabled but not required:# nmap --script smb-security-mode.nse -p445 127.0.0.1 PORT STATE SERVICE 445/tcp open microsoft-ds Host script results: | smb-security-mode: | Account that was used for smb scripts: guest | User-level authentication | SMB Security: Challenge/response passwords supported |_ Message signing disabled (dangerous, but default)
# nmap --script smb2-security-mode.nse -p445 127.0.0.1 PORT STATE SERVICE 445/tcp open microsoft-ds Host script results: | smb2-security-mode: | 3.11: |_ Message signing enabled but not required
Environment
- Red Hat Enterprise Linux 7
- Red Hat Enterprise Linux 8
- Red Hat Enterprise Linux 9
- samba
Subscriber exclusive content
A Red Hat subscription provides unlimited access to our knowledgebase, tools, and much more.