TwistedHelixis Posted May 15, 2017 Posted May 15, 2017 Can someone post up a script that will disable SMBv1 on Win7, Win8, Win8.1 & Windows 10 clients and make sure that SMBv2 & 3 is enabled. Thanks
ADMaster Posted May 15, 2017 Posted May 15, 2017 Does applocker / SRP prevent this? Since it spreads via vulnerability and not reliant on user action does it run elevated and bypass these restrictions? I've rolled out the SCCM script to disable smbv1 too so here is hoping I don't break anything.
jthompson Posted May 15, 2017 Posted May 15, 2017 Does applocker / SRP prevent this? Since it spreads via vulnerability and not reliant on user action does it run elevated and bypass these restrictions? I've rolled out the SCCM script to disable smbv1 too so here is hoping I don't break anything. I was just about to post a similar question. We have an SRP in place that disallows execution by default, and I've included path rules that specifically disallow cmd and powershell. Watching through which was shared earlier in this thread, it looks like WannaCry relies on executing from within a user's AppData folder, so I think our SRP would prevent that for non-admins. Reluctant to ever be 100% with this stuff, though.
Arthur Posted May 15, 2017 Posted May 15, 2017 I've ran this on a few 2012 R2 and 2016 boxes, given them a reboot and then running Get-SMBServerConfiguration in powershell still says its set to true. Am I missing something, I get a success message before I reboot. I remember reading something saying that was a bug. 1
kevin_lane Posted May 15, 2017 Posted May 15, 2017 https://blog.comae.io/wannacry-new-variants-detected-b8908fefea7e WannaCry — New Variants Detected!
caffrey Posted May 15, 2017 Posted May 15, 2017 Broke my (admittedly) old version of Dameware NT Utilities, renabled SMBv1 on my workstation and the browser works again - I should really update
HorridHenry Posted May 15, 2017 Posted May 15, 2017 Apologies if this is a numpty question but.......if all the windows update security patches/roll up's are up to date, doesn't that mean that the problem is patched (thus we can leave SMBv1 enabled)? There's so much advice rolling around I'm getting a little drowned.
HorridHenry Posted May 15, 2017 Posted May 15, 2017 Apologies if this is a numpty question but....if all the windows update security patches/roll up's are up to date, doesn't that mean the problem is plugged (thus we can leave SMBv1 enabled)? With all the advice flowing I'm getting a little drowned.
Arthur Posted May 15, 2017 Posted May 15, 2017 https://blog.comae.io/wannacry-new-variants-detected-b8908fefea7e WannaCry — New Variants Detected! Already posted earlier in this thread. www.edugeek.net/forums/windows/184209-nhs-hit-hard-ransomware-wannacry-patching-7.html#post1575927
Michael Posted May 15, 2017 Posted May 15, 2017 Apologies if this is a numpty question but.......if all the windows update security patches/roll up's are up to date, doesn't that mean that the problem is patched (thus we can leave SMBv1 enabled)? There's so much advice rolling around I'm getting a little drowned. Yes that's correct.
themightymrp Posted May 15, 2017 Posted May 15, 2017 I disabled it on my Win 8.1 machine and lost access to my NAS shares I guess it uses SMB1/CIFS
Arthur Posted May 15, 2017 Posted May 15, 2017 SMB1 is also going to be disabled by default in the Windows 10 Fall Creators Update (Redstone 3). The sooner you get rid of it the better! https://twitter.com/NerdPyle/status/863520227576791040 - - - Updated - - - I disabled it on my Win 8.1 machine and lost access to my NAS shares I guess it uses SMB1/CIFS Which NAS?
Michael Posted May 15, 2017 Posted May 15, 2017 Exactly as I predicted earlier. This is the only real way it will force developers to update code to newer versions.
mthomas08 Posted May 15, 2017 Posted May 15, 2017 Has any Schools been hit by this? It's been some years since I've heard the word outbreaks and education is usually in the mix. Seems this time around not the case?
localzuk Posted May 15, 2017 Posted May 15, 2017 Has any Schools been hit by this? It's been some years since I've heard the word outbreaks and education is usually in the mix. Seems this time around not the case? I think, weirdly, we are generally better protected than the NHS now! 2
Michael Posted May 15, 2017 Posted May 15, 2017 I think the Cyber Attack may have actually disabled Jeremey Hunt…… anyone heard anything from him yet? Apparently they're going to have a Cobra meeting according to the BBC. I'm sure that always ends with a refreshing outcome! 4
themightymrp Posted May 15, 2017 Posted May 15, 2017 @Arthur - It is a Netgear ReadyNAS NV+ Not a major appliance by any standards, just a simple backup device. But looks like I need SMB1 to access it :-/
jthompson Posted May 15, 2017 Posted May 15, 2017 Can I ask - If I apply the May or April roll-ups - does this include the fix for the issue? Or do I also need to specifically install the Windows update from March? I think you'll need the March update specifically. If I look in WSUS at the KB4012212 update for Windows 7 (the March update) it shows that we have no updates that supersede it.
Arthur Posted May 15, 2017 Posted May 15, 2017 This is the only real way it will force developers to update code to newer versions. Let's hope so! The most ironic thing is that most of the devices still requiring SMB1 are Linux-based devices like printers, NASs etc. https://twitter.com/NerdPyle/status/863520227576791040 Companies like Sophos and Ricoh should have sorted this a long time ago.
TechMonkey Posted May 15, 2017 Posted May 15, 2017 @Arthur - It is a Netgear ReadyNAS NV+ Not a major appliance by any standards, just a simple backup device. But looks like I need SMB1 to access it :-/ Check in the settings, I know Synology boxes have an option of a minimum and maximum SMB level. It may be the minimum is SMBv1 and so it settled on that.
theo_logical Posted May 15, 2017 Posted May 15, 2017 Would it thwart the progress of the ransomware bug if we were to store our data on a Linux server?
Michael Posted May 15, 2017 Posted May 15, 2017 Let's hope so! The most ironic thing is that most of the devices still requiring SMB1 are Linux-based devices like printers, NASs etc. https://twitter.com/NerdPyle/status/863520227576791040 Companies like Sophos and Ricoh should have sorted this a long time ago. But I suspect it'll still be there, just switched off by default. A bit like .NET Framework 3.5 in that respect. I doubt Microsoft will just remove it completely.
Garacesh Posted May 15, 2017 Posted May 15, 2017 Would it thwart the progress of the ransomware bug if we were to store our data on a Linux server? This particular one? Probably. But security by obscurity inevitable fails in the end.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now