Badlock

Security bug
Badlock
Logo representing Badlock.
CVE identifier(s)CVE-2016-2118
Websitehttps://web.archive.org/web/20170608065927/http://badlock.org/

Badlock (CVE-2016-2118) is a security bug disclosed on April 12, 2016 affecting the Security Account Manager (SAM) and Local Security Authority (Domain Policy) (LSAD) remote protocols[1] supported by Windows and Samba servers.[2]

Both SAM and LSAD are layered onto the DCE 1.1 Remote Procedure Call (DCE/RPC) protocol. As implemented in Samba and Windows, the RPC services allowed an attacker to become man in the middle.[3] Although the vulnerability was discovered during the development of Samba, the namegiving SMB protocol itself is not affected.

References

  1. ^ "Microsoft Security Bulletin MS16-047". Microsoft TechNet. 2016-04-12. Retrieved 2018-02-21.
  2. ^ "Badlock Bug". Archived from the original on 2017-06-08. Retrieved 2018-02-21.
  3. ^ "CVE-2016-2118". Retrieved 2018-02-21.

External links

  • Badlock Bug at the Wayback Machine (archived 2017-06-08)
  • v
  • t
  • e
Hacking in the 2010s
← 2000s Timeline 2020s →
Major incidents
2010
  • Operation Aurora (publication of 2009 events)
  • Australian cyberattacks
  • Operation Olympic Games
  • Operation ShadowNet
  • Operation Payback
2011
  • Canadian government
  • DigiNotar
  • DNSChanger
  • HBGary Federal
  • Operation AntiSec
  • PlayStation network outage
  • RSA SecurID compromise
2012
2013
2014
2015
2016
2017
2018
2019
HacktivismAdvanced
persistent threatsIndividualsMajor vulnerabilities
publicly disclosed
Malware
2010
2011
2012
2013
2014
2015
2016
2017
2018
2019