Tin tức và thông báoVietPN




H??ng d?n cch phng trnh Ransomware WannaCry chi ti?t nh?t - Giảm PING VietPN

Tin khác


?i?m nguy hi?m nh?t d?n ??n vi?c c th? b? t?n cng t? ngoi LAN chnh l vi?c cc my khng b?t Firewall, ch?n port 445 c?a smb ho?c disable File sharing service. Attacker c th? t?o m?t h? th?ng t? ??ng scan theo d?i ip public ?? tm cc my m? port 445 ? th?c hi?n exploit.
M?t nhm Hacker tn l Shadow Broker ? hack vo h? th?ng c?a NSA v ko ra m?t m? d? li?u c?a m?t t? ch?c do NSA qu?n l g?i l Equation Group. Trong m? d? li?u ny c ch?a r?t nhi?u cc exploit 0-days ?u?c NSA s? d?ng ?? t?n cng, do thm v ?nh c?p d? li?u c?a r?t nhi?u ng??i dng, t? ch?c, chnh ph? ? kh?p n?i trn th? gi?i ?? ph?c v? cho ho?t ??ng tnh bo.



Trong ? c m?t 0-days ??c bi?t nguy hi?m m?i ???c public ??t thng 4 v?a r?i nh?m vo t?t c? cc phin b?n t? XP ??n Windows 10. L?i ny nh?m t?i d?ch v? SMB (file sharing) c?a Windows cho php attacker th?c hi?n remote execution, ni m?t cch nm na, attacker c th? ?i?u khi?n my tnh t? xa, ch?ng h?n nh? g?i ln m?t cmd v?i quy?n SYSTEM, v thao tc ? ? m ng??i dng khng h? hay bi?t.

WannaCry t?n d?ng exploit ny,khi n ly nhi?m vo ???c m?t my, n seth?c hi?n scan cc my khc trong cng LAN, v th?c hi?n exploit. M?t khi exploitdc r?i,no ? c quy?n ki?m sot v thao tc trn my m?i, n s? t? ??ng copy b?n thn n sang my m?i ki?m sot ???c v ch?y -> ti?p t?c th?c hi?n ??n v?i t?t c? cc my cn l?i.
?i?m nguy hi?m nh?t d?n ??n vi?c c th? b? t?n cng t? ngoi LAN chnh l vi?c cc my khng b?t Firewall, ch?n port 445 c?a smb ho?c disable File sharing service. Attacker c th? t?o m?t h? th?ng t? ??ng scan theo d?i ip public ?? tm cc my m? port 445 ? th?c hi?n exploit.


Ho?c attacker c th? dng email phising ?nh l?a ng??i dng b?m vo link, ho?c m? file ?nh km ch?a m?t dropper, dropper ny download code exploit v? v ch?y ?? t?o ra m?t backdoor, t? ? attacker ung dung ti?n vo, ho?c ??n gi?n h?n n down lun WannaCry v? v ch?y.
?i?m khc bi?t khi?n WannaCry nguy hi?m chnh l vi?c n dng exploit ?? m? r?ng ph?m vi ly nhi?m, V c?ng c?n nh?n m?nh l exploit ny c th? t?o ra m?t backdoor v?i quy?n SYSTEM ( t??ng ???ng v?i root trong Linux) nn n c ton quy?n ??i v?i h? th?ng, t? vi?c disable AV, disable Firewall, s?a ho?c xo file h? th?ng, v hi?u ho hon ton cc c? ch? b?o v?.

Ch? c?n m?t node b? nhi?m l t?t c? cc my trong cng m?ng n?u ch?a ???c update s? dnh theo. L?i cng nguy hi?m h?n ? VN kh ng??i dng xi Win l?u, khng update, disable Firewall, v cc b?n win c? nh? XP (MS ? ng?ng support cho XP, tuy nhin l?n ny v?n ph?i tung m?t b?n v ?? s?a l?i ny cho XP)

Tin liên quan




Messenger Hỗ trợ