Rising Threat Of SMB Vulnerabilities And Their Effect On Business Continuity
“85% of MSPs report attack against SMBs in the last two years” read a report title few months ago
“Average cost of downtime due to SMB vulnerabilities attacks was $1,41,000 “ was a fact from the same report.
These two headlines paint a gray picture of how SMB is under persistent threat from attackers all over the globe. Maybe because of a lot of 0-days and public exploits targeting SMBs are easily available or due to the widespread usage of SMB, hackers have found their Goldmine!
A simple ‘smb’ search on Shodan.io returns more than 1.5 million results. This is enough to assume how largely and globally this protocol is used. Needless to say, what’s more prevalent is what’s more targeted.
Just recently arrived SMBleed vulnerability quickly gained momentum for it can result in Remote Code Execution (RCE) on SMB 1.1 under certain circumstances and when combined with a previously reported SMBGhost vulnerability. The issue lay in the Srv2DecompressData function in the srv2.sys SMB server driver. Considering the grave situation of more than a million active usages of SMB, Microsoft released a patch, but will that be enough?
Considering a best practice of installing security patches as soon as they arrive, we observe security misconfigurations where developers are adamant to update to latest versions owing to instability, added work or sometimes even negligence. This creates a perfect opportunity for hacker to infiltrate the systems and compromise the data or install ransomware.
Coming to Ransomwares, Wannacry or Eternal Blue wreaked havoc in the industry and this is not hidden from anyone. But very few are aware of the damages that other ransomwares are making by leveraging the SMB protocol. Four out of five MSPs are stating that they are increasingly targeted by Ransomwares and 89% are concerned about this increasing threats. The hackers have found various ways which even include social engineering attacks to intrude into the organizations and install ransomwares. The options left at that point are quite a few since not all ransomwares can be decrypted and there is always a possibility of data loss even after data is decrypted.
The best solution is always to go for preventing these attacks and investing on business saving instead of business recovery from such attacks
We at Detox, suggest the following practices in general to follow to avoid attacks through SMB. Definitely, this is not an exhaustive list since not curated for a specific business. These are generic but quite effective.
We responsibly and through experience suggest that coping with a compromised system should be the last resort since what has been done cannot be undone. Also, most organizations take years to recover from a single hack, sometimes Never!
So, do consult experts when planning the security architecture and conduct routine security audits & pentests because as they say, Security is not an implementation, it is a process.
Ransomware attacks have emerged as one of the most challenging cybersecurity threats facing businesses today. With attackers constantly evolving their…
In the realm of Cybersecurity, vulnerability scanning tools play a pivotal role in identifying and addressing potential weaknesses within an…
Dark web monitoring serves as a critical component within the broader spectrum of cybersecurity solutions, playing a proactive role in…
In the fast-paced digital landscape of today, mobile applications have become an integral part of our lives. From social networking…
In the ever-evolving landscape of cybersecurity, penetration testing plays a crucial role in identifying vulnerabilities within an organization's systems and…
Understanding VAPT (Vulnerability Assessment and Penetration Testing) Vulnerability Assessment and Penetration Testing (VAPT) is a proactive approach to security evaluation.…