TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

Samba: Authenticated users can change other users' password

96 pointsby f2nabout 7 years ago

5 comments

loegabout 7 years ago
Good news: Only affects the AD / LDAP component. Bad news: That component is enabled by default. Good news: If you don't use Samba LDAP, an effective mitigation is to just disable the ldap service (search the fine article for "Disable LDAP").
cm2187about 7 years ago
Does synology use samba for SMB drives?
评论 #16584059 未加载
评论 #16583493 未加载
评论 #16583256 未加载
NKCSSabout 7 years ago
This is pretty major and can go right in your exploiter's toolbag for privilege escalation scenarios.
评论 #16583418 未加载
sebazzzabout 7 years ago
This does not apply when the Samba server is a domain member instead of domain controller, right?
评论 #16583602 未加载
jessaustinabout 7 years ago
Haven't used samba much; this is enlightening. Previously I had assumed it just used the same auth system (e.g. PAM) as the host. That would entail its own complications but would probably have prevented this bug.
评论 #16585062 未加载