The vulnerability background:
以黑客教主之名,TK 發現了 Windows 史上最大漏洞
http://www.hksilicon.com/articles/1110674
Workaround:
1. Disable WINS/NetBT name resolution
2 Edit the hosts file to add the entry – 255.255.255.255 wpad
3. Disable Windows Scripting Host ( WSH )
By using Symantec noscript (Download: http://www.symantec.com/avcenter/noscript.exe)
Or change the registry set the “Enabled” = 0 under HKEY_LOCAL_MACHINE\Software\Microsoft\Windows Script Host\Settings (Refer: http://www.thewindowsclub.com/windows-script-host-access-is-disabled-on-this-machine)
Remark: It is highly recommend to upgrade your machine to Windows 7 or above (The Windows 10 free upgrade from 7/8.1 will be end at 29 July 2016 – Don’t miss it)
There are some useful material to hardening Windows XP to minimal the security risk on continuous using Windows XP
http://www.nccst.nat.gov.tw/xpendofsupportintro
Reference:
https://technet.microsoft.com/en-us/library/security/ms16-077.aspx
https://technet.microsoft.com/en-us/library/security/ms16-063.aspx
http://www.thewindowsclub.com/windows-script-host-access-is-disabled-on-this-machine
No comments:
Post a Comment