Samba Flow sibling of eternalblue for linux

    Apr 11, 2017
    Same as eternalblue exploit for windows which lead in formation of Wanna cry ransomware. we are now getting a huge amount of complaint from Linux user about this samba flow exploit found in linux system which allows hacker to remotely access any linux system

    Samba is an open-source software (re-implementation of SMB networking protocol) that runs on the majority of operating systems available today, including Windows, Linux, UNIX, IBM System 390, and OpenVMS. Samba allows non-Windows operating systems, like GNU/Linux or Mac OS X, to share network shared folders, files, and printers with Windows operating system.
    The newly discovered remote code execution vulnerability (CVE-2017-7494) affects all versions newer than Samba 3.5.0 that was released on March 1, 2010.

    Exploit Code Released! (Bonus: Metasploit Module)

    The flaw actually resided in the way Samba handled shared libraries. A remote attacker could use this Samba arbitrary module loading vulnerability to upload a shared library to a writable share and then cause the server to load and execute malicious code.

    The vulnerability is hell easy to exploit. Just one line of code is required to execute malicious code on the affected system.


    However, the Samba exploit has already been ported to Metasploit, a penetration testing framework, enabling researchers as well as hackers to exploit this flaw easily.


