{"id":71392,"date":"2022-02-28T09:00:00","date_gmt":"2022-02-28T01:00:00","guid":{"rendered":"https:\/\/blog.trendmicro.com.tw\/?p=71392"},"modified":"2022-02-23T12:21:37","modified_gmt":"2022-02-23T04:21:37","slug":"samba%e6%bc%8f%e6%b4%9e%e4%b9%9f%e6%9c%83%e5%bd%b1%e9%9f%bf%e5%b1%85%e5%ae%b6%e7%b6%b2%e8%b7%af%e5%92%8cnas%e8%a8%ad%e5%82%99%e7%9a%84%e5%ae%89%e5%85%a8%e6%80%a7","status":"publish","type":"post","link":"https:\/\/blog.trendmicro.com.tw\/?p=71392","title":{"rendered":"Samba\u6f0f\u6d1e\u4e5f\u6703\u5f71\u97ff\u5c45\u5bb6\u7db2\u8def\u548cNAS\u8a2d\u5099\u7684\u5b89\u5168\u6027"},"content":{"rendered":"\n<blockquote class=\"wp-block-quote is-layout-flow wp-block-quote-is-layout-flow\"><p> Samba\u6f0f\u6d1e\u53ef\u80fd\u6703\u5f71\u97ff\u5bb6\u5c45\u7db2\u8def\u548cNAS\u8a2d\u5099\u7684\u5b89\u5168\u6027\u3002\u96fb\u5b50\u90f5\u4ef6\u5730\u5740\u3001\u4fe1\u7528\u5361\u8cc7\u8a0a\u7b49\u500b\u4eba\u8cc7\u6599\u53ef\u80fd\u6703\u56e0\u6b64\u6f0f\u6d1e\u6240\u5c0e\u81f4\u7684\u8cc7\u6599\u5916\u6d29\u800c\u6d29\u9732\u3002\u672c\u6587\u63d0\u4f9b\u4e00\u4e9b\u80fd\u5920\u5e6b\u4f60\u4fdd\u8b77\u88dd\u7f6e\u548c\u61c9\u7528\u7a0b\u5f0f\u514d\u65bc\u6b64\u6f0f\u6d1e\u5f71\u97ff\u7684\u5efa\u8b70\u3002 <\/p><\/blockquote>\n\n\n\n<figure class=\"wp-block-image is-resized\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/news.trendmicro.com\/_next\/image\/?url=https%3A%2F%2Fnews.trendmicro.com%2Fapi%2Fwp-content%2Fuploads%2F2022%2F02%2FiStock-1369880775-1.jpg&amp;w=3840&amp;q=75\" alt=\"Samba vulnerability\" width=\"578\" height=\"361\"\/><\/figure>\n\n\n\n<p>\u4e00\u6708\u5e95\u5e38\u7528\u7684\u958b\u6e90\u8edf\u9ad4<a href=\"https:\/\/blog.trendmicro.com.tw\/?p=71235\">Samba<\/a>\u91cb\u51fa\u4e86\u91dd\u5c0d\u4e09\u500b\u6f0f\u6d1e\u7684\u5b89\u5168\u4fee\u88dc\u7a0b\u5f0f\uff0c\u9019\u4e9b\u6f0f\u6d1e\u767c\u751f\u5728\u6240\u6709\u7528\u9810\u8a2d\u503c\u57f7\u884cvfs_fruit\uff08\u7528\u4f86\u8ddfmacOS\u6e9d\u901a\u7684VFS\u6a21\u7d44\uff09\u7684Samba\u7248\u672c\u3002<\/p>\n\n\n\n<p>\u6700\u56b4\u91cd\u7684\u6f0f\u6d1e\u70ba<a href=\"https:\/\/www.samba.org\/samba\/security\/CVE-2021-44142.html\">CVE-2021-44142<\/a>\uff0c\u5b83\u7684<a href=\"https:\/\/www.first.org\/cvss\/\">CVSS<\/a><strong>\u5206\u6578\u70ba9.9<\/strong>\uff0c\u662f\u4e00\u500b\u8d8a\u754c\u8a18\u61b6\u9ad4\u5806\u68e7\u8b80\u5beb\uff08out-of-bounds heap read\/write\uff09\u6f0f\u6d1e\uff0c\u80fd\u5920\u8b93\u9060\u7aef\u653b\u64ca\u8005\u5728\u53d7\u5f71\u97ff\u7cfb\u7d71\u4ee5root\u6b0a\u9650\u57f7\u884c\u4efb\u610f\u7a0b\u5f0f\u78bc\u3002<\/p>\n\n\n\n<p>\u4e0d\u80fd\u4e0d\u63d0\u7684\u662f\uff0cSamba\u6f0f\u6d1e\u662f\u5728\u6211\u5011\u7684Pwn2Own Austin 2021\u99ed\u5ba2\u677e\u6d3b\u52d5\u4e2d\u767c\u73fe\u3002\u6b63\u5982\u8da8\u52e2\u79d1\u6280\u5a01\u8105\u60c5\u5831\u526f\u7e3dJon Clay<a href=\"https:\/\/www.taiwannews.com.tw\/en\/news\/4434318\">\u6240\u8aaa<\/a>\uff1a<\/p>\n\n\n\n<p><em>\u300c\u597d\u6d88\u606f\u662f\u9019\u662f\u5728\u6211\u5011\u7684Pwn2Own<\/em><em>\u6d3b\u52d5\u4e2d\u767c\u73fe\uff0c\u9019\u4ee3\u8868\u6211\u5011\u6709\u6a5f\u6703\u8207\u958b\u767c\u8005\u5408\u4f5c\uff0c\u8ca0\u8cac\u4efb\u5730\u4fee\u88dc\u548c\u62ab\u9732\u6f0f\u6d1e\u3002\u300d<\/em><\/p>\n\n\n\n<div style=\"height:100px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Samba<\/strong><strong>\u662f\u4ec0\u9ebc? <\/strong><strong>\u70ba\u4f55\u5b83\u5f88\u91cd\u8981\uff1f<\/strong><\/h2>\n\n\n\n<!--more-->\n\n\n\n<p><br>Samba\u9019\u5957\u958b\u6e90\u8edf\u9ad4\u91cd\u65b0\u5be6\u4f5c\u4e86<strong>\u63d0\u4f9b\u6a94\u6848\u548c\u5217\u5370\u670d\u52d9<\/strong>\u7684SMB\uff08\u4f3a\u670d\u5668\u8a0a\u606f\u5340\u584a\uff09\u7db2\u8def\u5354\u5b9a\u3002\u5b83\u88ab\u7528\u5728Unix\u548c\u985eUnix\u7cfb\u7d71\uff0c\u4ee5\u53ca\u5404\u7a2e\u4f7f\u7528SMB\/\u7db2\u8def\u6a94\u6848\u5206\u4eab\u7cfb\u7d71\uff08CIFS\uff09\u5354\u5b9a\u7684\u4f5c\u696d\u7cfb\u7d71\u3002<\/p>\n\n\n\n<p>\u5b83\u8b93\u7db2\u8def\u7ba1\u7406\u54e1\u53ef\u4ee5\u8a2d\u5b9a\u3001\u6574\u5408\u548c\u5efa\u7f6e\u8a2d\u5099\u6210\u70ba\u7db2\u57df\u63a7\u5236\u5668\uff08DC\uff09\u6216\u7db2\u57df\u6210\u54e1\uff0c\u4e26\u4e14\u80fd\u5920\u548cWindows\u5ba2\u6236\u7aef\u6e9d\u901a\u3002<\/p>\n\n\n\n<div style=\"height:100px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>Samba \u6f0f\u6d1e\u7684\u5f71\u97ff\u9762\uff1f<\/strong><\/h2>\n\n\n\n<p><br>\u6b64\u6f0f\u6d1e\u5f71\u97ffSamba 4.13.17\u524d\u6240\u6709\u7684\u7248\u672c\uff0c\u800cSamba 4.13.17\u30014.14.12\u548c4.15.5\u7684\u5b89\u5168\u4fee\u88dc\u7a0b\u5f0f\u5df2\u7d93\u767c\u5e03\u3002\u5efa\u8b70\u7ba1\u7406\u54e1\u99ac\u4e0a<strong>\u5347\u7d1a\u4e26\u90e8\u7f72\u4fee\u88dc\u7a0b\u5f0f<\/strong>\u3002\u6b64\u5916\uff0c\u7db2\u8def\u5132\u5b58\u8a2d\u5099\uff08NAS\uff09\u4e5f\u53ef\u80fd\u53d7\u5230\u9019\u500b\u6f0f\u6d1e\u5f71\u97ff\uff0c\u9810\u8a08\u5404\u5bb6\u5ee0\u5546\u6703\u70ba\u81ea\u5df1\u7684\u8a2d\u5099\u63a8\u51fa\u66f4\u65b0\u3002<\/p>\n\n\n\n<p>\u56e0\u70ba\u6709\u8a31\u591a<a href=\"https:\/\/www.samba.org\/samba\/vendors\/\">\u5ee0\u5546<\/a>\u90fd\u6709\u5728\u5176\u7522\u54c1\u4e2d\u4f7f\u7528Samba\uff0c\u6240\u4ee5\u53ef\u80fd\u53d7\u5230\u5f71\u97ff\u7684\u5305\u62ec\u88fd\u9020\u696d\u3001\u96fb\u4fe1\u696d\u3001\u80fd\u6e90\u7522\u696d\u3001\u653f\u5e9c\u548c\u79d1\u6280\u696d\uff0c\u4ee5\u53ca\u5bb6\u96fb\u548c<a href=\"http:\/\/blog.trendmicro.com.tw\/?p=8802\">\u7269\u806f\u7db2\uff08IoT ,Internet of Thing\uff09<\/a>\u88dd\u7f6e\u7b49\u6d88\u8cbb\u6027\u7522\u54c1\u3002<\/p>\n\n\n\n<div style=\"height:100px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<h2 class=\"wp-block-heading\"><strong>\u5982\u4f55\u4fdd\u8b77\u81ea\u5df1\u514d\u65bcSamba<\/strong><strong>\u6f0f\u6d1e\u5f71\u97ff?<\/strong><\/h2>\n\n\n\n<p><br>\u6b64\u6f0f\u6d1e\u53ef\u80fd\u6703\u5f71\u97ff\u5bb6\u5c45\u7db2\u8def\u548cNAS\u8a2d\u5099\u7684\u5b89\u5168\u6027\u3002\u96fb\u5b50\u90f5\u4ef6\u5730\u5740\u3001\u4fe1\u7528\u5361\u8cc7\u8a0a\u7b49\u500b\u4eba\u8cc7\u6599\u53ef\u80fd\u6703\u56e0\u6b64\u6f0f\u6d1e\u6240\u5c0e\u81f4\u7684\u8cc7\u6599\u5916\u6d29\u800c\u6d29\u9732\u3002\u4ee5\u4e0b\u662f\u4e00\u4e9b\u80fd\u5920\u5e6b\u4f60\u4fdd\u8b77\u88dd\u7f6e\u548c\u61c9\u7528\u7a0b\u5f0f\u514d\u65bc\u6b64\u6f0f\u6d1e\u5f71\u97ff\u7684\u5efa\u8b70\u3002<\/p>\n\n\n\n<p>&#x1f4cc;1.<strong>\u66f4\u65b0\u61c9\u7528\u7a0b\u5f0f\uff08\u4fee\u88dc\u5230\u6700\u65b0\u7248\u672c\uff09<\/strong><\/p>\n\n\n\n<p>Samba 4.13.17\u524d\u53d7\u5f71\u97ff\u7248\u672c\u7684\u4f7f\u7528\u8005\u61c9\u6aa2\u67e5\u767c\u884c\u5546\u6240\u63d0\u4f9b\u7684\u66f4\u65b0\u5957\u4ef6\u4e26\u90e8\u7f72\u53ef\u7528\u7684\u6700\u65b0\u4fee\u88dc\u7a0b\u5f0f\u3002\u800c\u7db2\u8def\u5132\u5b58\u8a2d\u5099\uff08NAS\uff09\u7684\u4f7f\u7528\u8005\u61c9\u806f\u7d61\u5ee0\u5546\u4f86\u4e86\u89e3\u662f\u5426\u6709\u4fee\u88dc\u7a0b\u5f0f\uff0c\u53ef\u4ee5\u7684\u8a71\u8acb\u555f\u7528\u81ea\u52d5\u66f4\u65b0\u3002<\/p>\n\n\n\n<p><br>&#x1f4cc;2.<strong>\u6383\u63cf\u5bb6\u5c45\u7db2\u8def\u5167\u7684\u88dd\u7f6e<\/strong><\/p>\n\n\n\n<p>\u5bb6\u5c45\u7db2\u8def\u6383\u63cf\u80fd\u5920\u4fdd\u8b77\u81ea\u5df1\u514d\u65bc\u6b64\u985e\u5b89\u5168\u6f0f\u6d1e\u7684\u5f71\u97ff\u3002\u3010<strong><a href=\"https:\/\/t.rend.tw\/?i=MTEzNTQ\">\u8da8\u52e2\u79d1\u6280\u667a\u6167\u7db2\u5b89\u7ba1\u5bb6<\/a><\/strong>\u3011\u8f15\u9b06\u4fdd\u8b77\u5bb6\u5ead<em>\u7db2<\/em>\u8def\u548c\u9023<em>\u7db2<\/em>\u88dd\u7f6e\u514d\u906d\u99ed\u5ba2\u653b\u64ca\u3001\u96b1\u79c1\u5916\u6d29\uff0c\u963b\u64cb\u60e1\u610f\/\u8a50\u9a19<em>\u7db2\u7ad9<\/em>\u3002 \u88dd\u7f6e\u63a7\u7ba1\u3002\u9632\u7bc4\u88dd\u7f6e\u906d\u5165\u4fb5\u3002\u8a3a\u65b7\u88dd\u7f6e\u5b89\u5168\u6027\u3002\u5c01\u9396\u60e1\u610f<em>\u7db2\u7ad9<\/em>\u3002\u96a8\u63d2\u5373\u7528\u3002<a href=\"https:\/\/blog.trendmicro.com.tw\/?p=65196\"> \u70ba\u5bb6\u4e2d\u5927\u5927\u5c0f\u5c0f\u6240\u6709\u9023\u7db2\u88dd\u7f6e\u4e0a\u4e00\u9053\u5b89\u5168\u7db2<strong>\u3002<\/strong><\/a><\/p>\n\n\n\n<p><br>&#x1f4cc;3.<strong>\u5b89\u88dd\u53ef\u4fe1\u8cf4\u7684\u9632\u6bd2\u7a0b\u5f0f<\/strong><\/p>\n\n\n\n<p>\u8da8\u52e2\u79d1\u6280<a href=\"https:\/\/t.rend.tw\/?i=MTExNzM\">PC-cillin<\/a>\u80fd\u5920\u5075\u6e2c\u5c0d\u6b64\u6f0f\u6d1e\u9032\u884c\u7684\u653b\u64ca\u3002\u8da8\u52e2\u79d1\u6280\u7db2\u9801\u4fe1\u8b7d\u8a55\u6bd4\u670d\u52d9\uff08WRS\uff09\u80fd\u5920\u5c01\u9396\u5df2\u77e5\u6f0f\u6d1e\u653b\u64ca\u6240\u7528\u7684\u60e1\u610f\u9023\u7dda\u548c\u5a01\u8105\u8f09\u9ad4\u3002<\/p>\n\n\n\n<p>\u8ddf\u5f80\u5e38\u4e00\u6a23\uff0c\u5e0c\u671b\u4f60\u89ba\u5f97\u9019\u7bc7\u6587\u7ae0\u6709\u7528\u6216\u611f\u8208\u8da3\u3002\u5982\u679c\u662f\u9019\u6a23\uff0c\u8acb<strong>\u5206\u4eab<\/strong>\u7d66\u4f60\u7684\u5bb6\u4eba\u548c\u670b\u53cb\uff0c\u5171\u540c\u8b93\u7db2\u8def\u793e\u7fa4\u66f4\u52a0\u5b89\u5168\u548c\u5f97\u5230\u4fdd\u8b77\u3002<\/p>\n\n\n\n<p><\/p>\n\n\n\n<div style=\"height:100px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n<figure class=\"wp-block-image size-large\"><a href=\"https:\/\/t.rend.tw\/?i=MTEyOTE\n\"><img decoding=\"async\" src=\"https:\/\/blog.trendmicro.com.tw\/wp-content\/uploads\/2015\/08\/Windows10Banner-540x90v5.gif\" alt=\"\"\/><\/a><figcaption>  PC-cillin \u9632\u8a50\u9632\u6bd2\u3001\u5b88\u8b77\u500b\u8cc7,\u652f\u63f4Windows11 \u2713\u624b\u6a5f\u2713\u96fb\u8166\u2713\u5e73\u677f\uff0c\u8de8\u5e73\u53f0\u9632\u8b77\uff13\u5230\u4f4d\u2794<a href=  https:\/\/t.rend.tw\/?i=MTExNzM\n> \u300b\u5373\u523b\u514d\u8cbb\u4e0b\u8f09\u8a66\u7528 <\/a><\/figcaption><\/figure>\n<div style=\"height:100px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n\n<div style=\"height:100px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n\n<p>&#x25fe;\u539f\u6587\u51fa\u8655\uff1a<a href=\"https:\/\/news.trendmicro.com\/2022\/02\/15\/what-is-the-samba-bug-and-why-should-i-be-concerned\/\">What Is the Samba Bug and Why Should I Be Concerned?<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Samba\u6f0f\u6d1e\u53ef\u80fd\u6703\u5f71\u97ff\u5bb6\u5c45\u7db2\u8def\u548cNAS\u8a2d\u5099\u7684\u5b89\u5168\u6027\u3002\u96fb\u5b50\u90f5\u4ef6\u5730\u5740\u3001\u4fe1\u7528\u5361\u8cc7\u8a0a\u7b49\u500b\u4eba\u8cc7\u6599\u53ef\u80fd\u6703\u56e0\u6b64\u6f0f\u6d1e\u6240\u5c0e\u81f4\u7684 [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","_wpscppro_dont_share_socialmedia":false,"_wpscppro_custom_social_share_image":0,"_facebook_share_type":"","_twitter_share_type":"","_linkedin_share_type":"","_pinterest_share_type":"","_linkedin_share_type_page":"","_instagram_share_type":"","_medium_share_type":"","_threads_share_type":"","_google_business_share_type":"","_selected_social_profile":[],"_wpsp_enable_custom_social_template":false,"_wpsp_social_scheduling":{"enabled":false,"datetime":null,"platforms":[],"status":"template_only","dateOption":"today","timeOption":"now","customDays":"","customHours":"","customDate":"","customTime":"","schedulingType":"absolute"},"_wpsp_active_default_template":true},"categories":[3654],"tags":[5046,452,5056],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/blog.trendmicro.com.tw\/index.php?rest_route=\/wp\/v2\/posts\/71392"}],"collection":[{"href":"https:\/\/blog.trendmicro.com.tw\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.trendmicro.com.tw\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.trendmicro.com.tw\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.trendmicro.com.tw\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=71392"}],"version-history":[{"count":3,"href":"https:\/\/blog.trendmicro.com.tw\/index.php?rest_route=\/wp\/v2\/posts\/71392\/revisions"}],"predecessor-version":[{"id":71396,"href":"https:\/\/blog.trendmicro.com.tw\/index.php?rest_route=\/wp\/v2\/posts\/71392\/revisions\/71396"}],"wp:attachment":[{"href":"https:\/\/blog.trendmicro.com.tw\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=71392"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.trendmicro.com.tw\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=71392"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.trendmicro.com.tw\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=71392"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}