Saved in:
| Main Authors: | , , , |
|---|---|
| Format: | Preprint |
| Published: |
2024
|
| Subjects: | |
| Online Access: | https://arxiv.org/abs/2401.14979 |
| Tags: |
Add Tag
No Tags, Be the first to tag this record!
|
| _version_ | 1866914654532403200 |
|---|---|
| author | Novokhrestov, Aleksey Kalyakin, Anton Kovalenko, Aleksandr Repkin, Vladimir |
| author_facet | Novokhrestov, Aleksey Kalyakin, Anton Kovalenko, Aleksandr Repkin, Vladimir |
| contents | The creation of a vulnerable node has been demonstrated through the analysis and implementation of the MS17-010 (CVE-2017-0144) vulnerability, affecting the SMBv1 protocol on various Windows operating systems. The principle and methodology of exploiting the vulnerability are described, with a formalized representation of the exploitation in the form of a Meta Attack Language (MAL) graph. Additionally, the attacker's implementation is outlined as the execution of an automated script in Python using the Metasploit Framework. Basic security measures for systems utilizing the SMBv1 protocol are provided. |
| format | Preprint |
| id |
arxiv_https___arxiv_org_abs_2401_14979 |
| institution | arXiv |
| publishDate | 2024 |
| record_format | arxiv |
| spellingShingle | Creating a vulnerable node based on the vulnerability MS17-010 Novokhrestov, Aleksey Kalyakin, Anton Kovalenko, Aleksandr Repkin, Vladimir Cryptography and Security The creation of a vulnerable node has been demonstrated through the analysis and implementation of the MS17-010 (CVE-2017-0144) vulnerability, affecting the SMBv1 protocol on various Windows operating systems. The principle and methodology of exploiting the vulnerability are described, with a formalized representation of the exploitation in the form of a Meta Attack Language (MAL) graph. Additionally, the attacker's implementation is outlined as the execution of an automated script in Python using the Metasploit Framework. Basic security measures for systems utilizing the SMBv1 protocol are provided. |
| title | Creating a vulnerable node based on the vulnerability MS17-010 |
| topic | Cryptography and Security |
| url | https://arxiv.org/abs/2401.14979 |