Sunday, June 19, 2016

How to use workaround solution to hardening Windows XP to against two critical vulnerability (MS16-063) and (MS16-077)?

The vulnerability background:

以黑客教主之名,TK 發現了 Windows 史上最大漏洞

http://www.hksilicon.com/articles/1110674

Workaround:

1. Disable WINS/NetBT name resolution

BF51AA82ED8246C4B1FA6A34067BFEC0

 

2 Edit the hosts file to add the entry – 255.255.255.255 wpad

EFC8ABFDD8734F5590FBC999C245C59D

3. Disable Windows Scripting Host ( WSH )

By using Symantec noscript (Download: http://www.symantec.com/avcenter/noscript.exe)

8916F1789635411AACCEC8C2BF29059A

FABE24A2897F4085BD2B986380E09BDD

 

Or change the registry set the “Enabled” = 0 under HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings (Refer: http://www.thewindowsclub.com/windows-script-host-access-is-disabled-on-this-machine)

Remark: It is highly recommend to upgrade your machine to Windows 7 or above (The Windows 10 free upgrade from 7/8.1 will be end at 29 July 2016 – Don’t miss it)

 

There are some useful material to hardening Windows XP to minimal the security risk on continuous using Windows XP

http://www.nccst.nat.gov.tw/xpendofsupportintro

 

Reference:

https://technet.microsoft.com/en-us/library/security/ms16-077.aspx

https://technet.microsoft.com/en-us/library/security/ms16-063.aspx

http://www.windowsnetworking.com/kbase/WindowsTips/WindowsXP/AdminTips/Customization/DisableWindowsScriptingHostWSH.html

 http://www.thewindowsclub.com/windows-script-host-access-is-disabled-on-this-machine Print Friendly and PDF
Share/Bookmark

No comments:

Post a Comment