Link to home
Start Free TrialLog in
Avatar of sunhux
sunhux

asked on

NSA exploit leveraging on NetBT (& SMB)

http://www.pcworld.com/article/3190204/security/leaked-nsa-exploits-plant-a-bulls-eye-on-windows-server.html

Refer to above link.
Is this a legit vulnerability & which versions of Windows are affected (as the link did not say)
& that "Microsoft has yet to release a patch for it" ie MS ack it's a vulnerability ?

Can cite any authoritative & MS links that support the legitimacy of the above claims of vulnerability
& specifically NetBT protocol could be exploited by the above NSA exploit ?
Avatar of sunhux
sunhux

ASKER

The link quoted WIn 2008 R2 could be exploited;  so starting from which version of Windows this
is non-exploitable?  Besides firewalls, what other mitigations can we deploy?   Does McAfee NIDS provide
any mitigation & which signature?

Can we stop creation of certain IOC files/extensions (eg: block known ransomwares extensions) &
what's the extensions or IOCs?
SOLUTION
Avatar of Seth Simmons
Seth Simmons
Flag of United States of America image

Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
ASKER CERTIFIED SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial
SOLUTION
Link to home
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Start Free Trial