TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Samba: Authenticated users can change other users' password

96 点作者 f2n大约 7 年前

5 条评论

loeg大约 7 年前
Good news: Only affects the AD / LDAP component. Bad news: That component is enabled by default. Good news: If you don't use Samba LDAP, an effective mitigation is to just disable the ldap service (search the fine article for "Disable LDAP").
cm2187大约 7 年前
Does synology use samba for SMB drives?
评论 #16584059 未加载
评论 #16583493 未加载
评论 #16583256 未加载
NKCSS大约 7 年前
This is pretty major and can go right in your exploiter's toolbag for privilege escalation scenarios.
评论 #16583418 未加载
sebazzz大约 7 年前
This does not apply when the Samba server is a domain member instead of domain controller, right?
评论 #16583602 未加载
jessaustin大约 7 年前
Haven't used samba much; this is enlightening. Previously I had assumed it just used the same auth system (e.g. PAM) as the host. That would entail its own complications but would probably have prevented this bug.
评论 #16585062 未加载