Menu
Prepare to patch a critical flaw in Windows and Samba file sharing in 3 weeks

Prepare to patch a critical flaw in Windows and Samba file sharing in 3 weeks

The Badlock vulnerability is severe and likely to be exploited soon after disclosure

Systems administrators should get ready to fix a critical vulnerability on April 12 that affects the Windows and Samba implementations of the Server Message Block (SMB) protocol.

The vulnerability was discovered by Stefan Metzmacher, a core developer of the Samba software, which is a popular open-source implementation of the SMB/CIFS (Server Message Block/Common Internet File System) networking protocol.

SMB/CIFS is implemented by default in Windows, where it's used for network file and printer sharing. Linux and other Unix-like systems can interoperate and share resources with Windows systems over the same protocol using the Samba software.

"On April 12th, 2016, SerNet, the Samba Team and Microsoft will disclose a severe bug that affects almost all versions of Microsoft Windows and Samba," said SerNet, the company where Metzmacher works, in an announcement on its website. "The bug is called 'Badlock'."

The company, which offers Samba consulting, support and development services, has even set up an website at badlock.org where more details will be released about the flaw on the disclosure date, which coincides with Microsoft's Patch Tuesday -- the day when Microsoft releases its monthly security updates.

"Please get yourself ready to patch all systems on this day," a warning on the badlock.org website reads. "We are pretty sure that there will be exploits soon after we publish all relevant information."

There's been a bit of speculation on Twitter from members of the security community about where the flaw might be. The name itself seems to suggest that it's related to the client lock-handling mechanism, and there's actually file in the Samba source code called lock.c that has a copyright  by Stefan Metzmacher.

Because the vulnerability affects both Samba and Windows, which are separate implementations of the protocol, there's a good chance that it's actually a protocol design flaw.

"With both vendors apparently offering patches, it suggests the vulnerability is either within the integration between the two vendors, the separate implementations by each vendor, or in the SMB/CIFS protocol itself (we’re betting on the latter)," said Brian Martin, director of vulnerability intelligence at security firm Risk Based Security, in a blog post.

As far as the impact of the vulnerability goes, Johannes Loxen, the CEO of SerNet, said on Twitter that "#badlock means admin accounts for everyone on the same LAN." The message appears to have since been deleted, but a CSO article on the controversy over SerNet's use of the flaw for marketing purposes includes a screenshot of it.

The disclosure of the bug's existence, even without specific technical details, three weeks in advance has also been criticized by some members of the security community because it gives potential hackers ample time to find it on their own.

"Odds on the details of Badlock leaking (or being independently discovered) before April 12th? 15/1," said renowned security researcher David Litchfield in a Twitter message.


Follow Us

Join the New Zealand Reseller News newsletter!

Error: Please check your email address.

Featured

Slideshows

Tight lines as Hooked on Lenovo catches up at Great Barrier Island

Tight lines as Hooked on Lenovo catches up at Great Barrier Island

​Ingram Micro’s Hooked on Lenovo incentive programme recently rewarded 28 of New Zealand's top performing resellers with a full-on fishing trip at Great Barrier Island for the third year​ in a row.

Tight lines as Hooked on Lenovo catches up at Great Barrier Island
Inside the AWS Summit in Sydney

Inside the AWS Summit in Sydney

As the dust settles on the 2017 AWS Summit in Sydney, ARN looks back an action packed two-day event, covering global keynote presentations, 80 breakout sessions on the latest technology solutions, and channel focused tracks involving local cloud stories and insights.

Inside the AWS Summit in Sydney
Channel tees off on the North Shore as Ingram Micro hosts annual Cure Kids Charity golf day

Channel tees off on the North Shore as Ingram Micro hosts annual Cure Kids Charity golf day

Ingram Micro hosted its third annual Cure Kids Charity Golf Tournament at the North Shore Golf Club in Auckland. In total, 131 resellers, vendors and Ingram Micro suppliers enjoyed a round of golf consisting of challenges on each of the 18 sponsored holes, with Team Philips taking out the top honours.

Channel tees off on the North Shore as Ingram Micro hosts annual Cure Kids Charity golf day
Show Comments