██████╗ ███████╗████████╗██╗██████╗ ███████╗██████╗ ██╗ █████╗
██╔══██╗██╔════╝╚══██╔══╝██║██╔══██╗██╔════╝██╔══██╗██║██╔══██╗
██████╔╝█████╗ ██║ ██║██████╔╝█████╗ ██║ ██║██║███████║
██╔══██╗██╔══╝ ██║ ██║██╔═══╝ ██╔══╝ ██║ ██║██║██╔══██║
██║ ██║███████╗ ██║ ██║██║ ███████╗██████╔╝██║██║ ██║
╚═╝ ╚═╝╚══════╝ ╚═╝ ╚═╝╚═╝ ╚══════╝╚═════╝ ╚═╝╚═╝ ╚═╝
- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b- `b
¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯¯
EternalBlue
──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────
top
mwbqEternalBlue, a volte stilizzato in mwbgETERNALBLUE,cite-ref-ars-1-0[1] è il nome di un mwcwexploit sviluppato dalla mwdaNational Security Agency (NSA). Il mondo informatico è venuto a conoscenza dell'esistenza di questo exploit dopo che il gruppo di hacker chiamato The Shadow Brokers lo ha illegalmente diffuso il 14 aprile 2017. Il 12 maggio 2017, l'exploit è stato poi sfruttato per realizzare un attacco informatico attraverso il mwdgransomware mwdwWannaCry, che, tramite questo exploit, sfrutta una vulnerabilità del protocollo mweaServer Message Block (SMB).cite-ref-ars-1-1[1]cite-ref-2[2]cite-ref-3[3]cite-ref-0-4-0[4]cite-ref-5[5]
Contents
• Dettagli
• Note
──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────
Dettagli
EternalBlue sfrutta una vulnerabilità nell'implementazione del protocollo mwjwServer Message Block (SMB) presente in alcuni sistemi operativi mwkaMicrosoft. Questa vulnerabilità è oggi elencata come la numero CVE-2017-0144 nel catalogo mwkqCommon Vulnerabilities and Exposures (CVE) (un dizionario di vulnerabilità e falle di sicurezza pubblicamente note). Tale vulnerabilità esiste poiché la versione 1 del protocollo SMB (SMBv1) presente in diverse versioni del sistema operativo mwkgMicrosoft Windows accetta pacchetti di dati opportunamente prodotti inviati alla macchina da chi sta eseguendo un attacco remoto, permettendo a tali utenti remoti di eseguire codice arbitrario sulla macchina bersaglio dell'attacco.cite-ref-6[6]
Il servizio di aggiornamento standard per Windows consente di risolvere questo problema attraverso la mwmapatch di sicurezza rilasciata da Microsoft in data 14 marzo 2017 e chiamata MS17-010, usufruibile per tutte le versioni del mwmqsistema operativo supportate a quella data, ossia mwmgWindows Vista, mwmwWindows 7, mwnaWindows 8.1, mwnqWindows 10, mwngWindows Server 2008, mwnwWindows Server 2012, e mwoaWindows Server 2016.cite-ref-7[7]cite-ref-8[8]
Purtroppo molti utilizzatori delle suddette versioni del sistema operativo non avevano ancora installato la patch MS17-010 quando, meno di due mesi più tardi, il 12 maggio 2017, un gruppo di hacker non ancora noto ha portato a termine un attacco con il ransomware WannaCry, che usa proprio le possibilità date dall'exploit EternalBlue per diffondersi.cite-ref-microsoft-com-9-0[9]cite-ref-10[10]cite-ref-11[11]
Il 13 maggio 2017, un giorno dopo l'attacco, Microsoft ha inusualmente fornito, tramite un mwtwdownload dal Microsoft Update Catalog, un aggiornamento di sicurezza volto a eliminare la sopraccitata vulnerabilità anche da versioni di Microsoft Windows non più supportate, ossia mwuqWindows XP, mwugWindows 8, e mwuwWindows Server 2003.cite-ref-12[12]cite-ref-13[13]
Note
cite-note-ars-11. ↑ mwzamwzqmwzgNSA-leaking Shadow Brokers just dumped its most damaging release yet, su mwzwarstechnica.com, mwaaArs Technica. mwaqURL consultato il 17 maggio 2017.
cite-note-33. ↑ mwdqmwdgmwdwAn NSA-derived ransomware worm is shutting down computers worldwide, su mweaarstechnica.com, mweqArs Technica. mwegURL consultato il 17 maggio 2017.
cite-note-0-44. ↑ mwfgAgamoni Ghosh, mwfwmwgamwgq'President Trump what the f**k are you doing' say Shadow Brokers and dump more NSA hacking tools, International Business Times UK, 9 aprile 2017. mwgwURL consultato il 17 maggio 2017.
cite-note-66. ↑ mwkamwkqmwkgVulnerability CVE-2017-0144 in SMB exploited by WannaCryptor ransomware to spread over LAN, su mwkwsupport.eset.com, ESET North America. mwlaURL consultato il 17 maggio 2017.
cite-note-77. ↑ mwmaCatalin Cimpanu, mwmqmwmgMicrosoft Releases Patch for Older Windows Versions to Protect Against Wana Decrypt0r, su mwmwbleepingcomputer.com, Bleeping Computer, 13 maggio 2017. mwnqURL consultato il 17 maggio 2017.
cite-note-microsoft-com-99. ↑ mwqgmwqwmwraMicrosoft Security Bulletin MS17-010 — Critical, su mwrqtechnet.microsoft.com. mwrgURL consultato il 17 maggio 2017.
cite-note-1010. ↑ mwsgLily Hay Newman, mwswmwtaThe Ransomware Meltdown Experts Warned About Is Here, su mwtqwired.com. mwtgURL consultato il 17 maggio 2017.
cite-note-1111. ↑ mwugmwuwmwvaWanna Decryptor: The NSA-derived ransomware worm shutting down computers worldwide, Ars Technica UK. mwvqURL consultato il 17 maggio 2017.
cite-note-1212. ↑ mwwqSurur, mwwgmwwwMicrosoft release Wannacrypt patch for unsupported Windows XP, Windows 8 and Windows Server 2003, 13 maggio 2017. mwxaURL consultato il 17 maggio 2017.
cite-note-1313. ↑ mwyaMSRC Team, mwyqmwygCustomer Guidance for WannaCrypt attacks, su mwywblogs.technet.microsoft.com, Microsoft. mwzaURL consultato il 17 maggio 2017.
Collegamenti esterni
• mw0aMicrosoft Security Bulletin MS17-010, su technet.microsoft.com.
• mw0gAggiornamenti contro EternalBlue sul Microsoft Update Catalog, su catalog.update.microsoft.com.
• mw1aVulnerabilità numero CVE-2017-0144 sul catalogo CVE, su cve.mitre.org (archiviato dall'url originale il 30 giugno 2017).