AnsweredAssumed Answered

Qualys Inventory Check - Badlock Bug Preperation, Possible?

Question asked by Ronan Dunne on Mar 23, 2016
Latest reply on Apr 4, 2016 by Martin Walker

Hey,

 

So the Badlock bug that is being released April 12th affecting SMB & Samba. SANS published a post around preparation with regards inventory checks.

Short summary: What should you do before April 12th

Getting Ready for Badlock - SANS Internet Storm Center

Short summary: What should you do before April 12th

  • Inventory SMB servers
  • Verify firewall rules to block SMB inbound AND outbound
  • Order some donuts/pizza for the patch team for April 12th. It could be a busy day.!! - Probably the best approach!

 

Any recommendations around using a Qualys QID, all I have seen so far is QID 70028?

SMB Signing - The value identifies whether SMB signing is Enabled or Disabled on the host.

Outcomes