Insecure Service
SMB Service Availability to Internet or Other Unauthorized Users

TCM-KB-EXT-001
Last Updated: 6/26/2023

Microsoft Windows Server

The recommended remediation steps and configurations described in this response would primarily affect systems running Microsoft Windows Server.

SMB

SMB refers to Server Message Block.


A small message block refers to a compact unit of data transmission used in communication protocols. It typically contains a limited amount of information, such as a command, status update, or a small portion of a larger message, allowing for efficient and rapid exchange of data between devices or systems.

Contributor

Joe Helle

Joe Helle

Chief Hacking Officer

This Knowledge Base Article was submitted by: Joe Helle.

Recent Blogs

NIST Guidelines for Incident Response: Best Practices

NIST Guidelines for Incident Response: Best Practices

Introduction With the evolving sophistication and persistence of threat actors, there is no excuse for organizations to be unprepared to strategically and quickly respond to the inevitable—cybersecurity incidents. Among its many documented standards, the National...

Issue

The SMB service on the domain-joined endpoint is available to the Internet. This could permit information disclosure of internal network identities (i.e., fully-qualified domain names of internal domains) and accessibility of an external entry point for brute force attacks.

SMB Service Availability

Recommended Remediation

The following outlines the recommended steps that the systems and network administrators should take in order to secure the environment.

Utilizing a user account with administrative privileges, open Windows Defender Firewall with Advanced Security.

Advanced Firewall Security Windows Defender

Right-click inbound Rules and select New Rule.

Windows Defender New Rule

In the Rule Type window, click Port and select next.

Windows Defender New Inbound Rule Wizard

Select the TCP option, and below, the Specific local ports option. Enter ports 135, 139, 445 and click Next.

Windows Defender Protocols and Ports

On the next screen, select Block the connection and press Next.

Windows Defender Connection Types

In the next window, deselect Domain and Private, and select Public. If you prefer to only allow domain-connected devices to access the SMB service, deselect only Domain, and select Private and Public. Press Next when complete.

Windows Defender Applying Rules

In the next window, specify a name for the new firewall rule, and enter a description if desired. Press Finish when complete.

Naming Rules Windows Defender

 

 

sample penetration test report

Sample Pentest Report

See The Results We Can Deliver To You. No Email Required.

See How We Can Secure Your Assets

Let’s talk about how TCM Security can solve your cybersecurity needs. Give us a call, send us an e-mail, or fill out the contact form below to get started.

 

tel: (877) 771-8911 | email: info@tcm-sec.com