<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>پچ printnightmare &#8211; Peneter.com</title>
	<atom:link href="https://blog.peneter.com/tag/%D9%BE%DA%86-printnightmare/feed/" rel="self" type="application/rss+xml" />
	<link>https://blog.peneter.com</link>
	<description>Penetration Tester</description>
	<lastBuildDate>Thu, 08 Jul 2021 20:17:23 +0000</lastBuildDate>
	<language>fa-IR</language>
	<sy:updatePeriod>
	hourly	</sy:updatePeriod>
	<sy:updateFrequency>
	1	</sy:updateFrequency>
	<generator>https://wordpress.org/?v=6.9</generator>
	<item>
		<title>پچ امنیتی برای آسیب پذیری CVE-2021-34527 / Print Nightmare</title>
		<link>https://blog.peneter.com/printnightmare-patched/</link>
					<comments>https://blog.peneter.com/printnightmare-patched/#respond</comments>
		
		<dc:creator><![CDATA[Peneter]]></dc:creator>
		<pubDate>Tue, 06 Jul 2021 23:20:34 +0000</pubDate>
				<category><![CDATA[اخبار امنیت]]></category>
		<category><![CDATA[KB5004945]]></category>
		<category><![CDATA[KB5004946]]></category>
		<category><![CDATA[KB5004947]]></category>
		<category><![CDATA[KB5004949]]></category>
		<category><![CDATA[KB5004950]]></category>
		<category><![CDATA[KB5004951]]></category>
		<category><![CDATA[KB5004953]]></category>
		<category><![CDATA[KB5004954]]></category>
		<category><![CDATA[KB5004955]]></category>
		<category><![CDATA[KB5004958]]></category>
		<category><![CDATA[KB5004959]]></category>
		<category><![CDATA[patch CVE-2021-34527]]></category>
		<category><![CDATA[pritnnightmare patch]]></category>
		<category><![CDATA[پچ CVE-2021-34527]]></category>
		<category><![CDATA[پچ printnightmare]]></category>
		<guid isPermaLink="false">https://blog.peneter.com/?p=633</guid>

					<description><![CDATA[ساعتی پیش مایکروسافت  پچ  امنیتی برای رفغ آسیب پذیری CVE-2021-34527 را  منتشر کرد در پست قبلی به آسیب پذیری Printnightmare اشاره کردیم . برای جلوگیری...]]></description>
										<content:encoded><![CDATA[<p>ساعتی پیش مایکروسافت  پچ  امنیتی برای رفغ آسیب پذیری CVE-2021-34527 را  منتشر کرد در<a href="https://blog.peneter.com/printnightmare-0day/"> پست قبلی</a> به آسیب پذیری Printnightmare اشاره کردیم .</p>
<p>برای جلوگیری از نفوذ به سیستم عامل ویندوز شما با اکسپلویت 0day printnightmare در سریع ترین زمان ممکن سرورها و کلاینت های خود را پچ کنید . قابلیت اجرا اکسپلویت به صورت ریموت و محلی دسترسی SYSTEMلینک :<br />
<code>https://msrc.microsoft.com/update-guide/vulnerability/CVE-2021-34527</code><br />
Windows 10, version 21H1 (<a href="https://support.microsoft.com/help/5004945">KB5004945</a>)<br />
Windows 10, version 20H1 (<a href="https://support.microsoft.com/help/5004945">KB5004945</a>)<br />
Windows 10, version 2004 (<a href="https://support.microsoft.com/help/5004945">KB5004945</a>)<br />
Windows 10, version 1909 (<a href="https://support.microsoft.com/help/5004946">KB5004946</a>)<br />
Windows 10, version 1809 and Windows Server 2019 (<a href="https://support.microsoft.com/help/5004947">KB5004947</a>)<br />
Windows 10, version 1803 (<a href="https://support.microsoft.com/help/5004949">KB5004949</a>)<br />
Windows 10, version 1507 (<a href="https://support.microsoft.com/help/5004950">KB5004950</a>)<br />
Windows 8.1 and Windows Server 2012 (Monthly Rollup <a href="https://support.microsoft.com/help/5004954">KB5004954</a> / Security only <a href="https://support.microsoft.com/help/5004958">KB5004958</a>)<br />
Windows 7 SP1 and Windows Server 2008 R2 SP1 (Monthly Rollup <a href="https://support.microsoft.com/help/5004953">KB5004953</a> / Security only <a href="https://support.microsoft.com/help/5004951">KB5004951</a>)<br />
Windows Server 2008 SP2 (Monthly Rollup <a href="https://support.microsoft.com/help/5004955">KB5004955</a> / Security only <a href="https://support.microsoft.com/help/5004959">KB5004959</a>)</p>
<h1>این پچ فقط روی RCE تاثیر داره و نکته که وجود داره بایپس برای RCE restriction روی UNC PATH برای لود payload وجود داره که توسط <a href="https://twitter.com/gentilkiwi/status/1412771434452164610?s=20">سازنده</a> mimikatz در توییتر اولین بار اعلام شد.</h1>
<p>تنها راه شما در حال حاظر mitigation هست :</p>
<p>https://github.com/gentilkiwi/mimikatz/releases/tag/2.2.0-20210704<br />
mimkatz bypass UNC path for new PATCH!</p>
<p>After I set ACL Exploit did not work any more .<br />
بعد از تغییر پرمیشن فولدر درایورها دیگه اکسپلویت کار نمیکنه</p>
<blockquote class="wp-embedded-content" data-secret="4c3kVM5zZc"><p><a href="https://blog.peneter.com/printnightmare-0day/">آسیب پذیری  Printnightmare و وصله امنیتی (Patch)</a></p></blockquote>
<p><iframe class="wp-embedded-content" sandbox="allow-scripts" security="restricted"  title="&#8220;آسیب پذیری  Printnightmare و وصله امنیتی (Patch)&#8221; &#8212; Peneter.com" src="https://blog.peneter.com/printnightmare-0day/embed/#?secret=4c3kVM5zZc" data-secret="4c3kVM5zZc" width="600" height="338" frameborder="0" marginwidth="0" marginheight="0" scrolling="no"></iframe></p>
<blockquote class="wp-embedded-content" data-secret="0mS6TwQMhC"><p><a href="https://blog.peneter.com/printnightmare-patched/">پچ امنیتی برای آسیب پذیری CVE-2021-34527</a></p></blockquote>
<p><iframe class="wp-embedded-content" sandbox="allow-scripts" security="restricted"  title="&#8220;پچ امنیتی برای آسیب پذیری CVE-2021-34527&#8221; &#8212; Peneter.com" src="https://blog.peneter.com/printnightmare-patched/embed/#?secret=0mS6TwQMhC" data-secret="0mS6TwQMhC" width="600" height="338" frameborder="0" marginwidth="0" marginheight="0" scrolling="no"></iframe><br />
Microsoft Patch does not fix LPE , RCE also for mitigate this issue :</p>
<p>برای کاهش مخاطره به لینک زیر مراجعه کنید :<br />
<code>https://doublepulsar.com/zero-day-for-every-supported-windows-os-version-in-the-wild-printnightmare-b3fdb82f840c</code><br />
<code>https://www.bleepingcomputer.com/news/microsoft/microsofts-incomplete-printnightmare-patch-fails-to-fix-vulnerability/</code></p>
<p>در ویدیو زیر ما تست گرفتیم کل فرایند رو :<br />
<code><br />
https://www.youtube.com/watch?v=kO_um6uWEZ4</code></p>
]]></content:encoded>
					
					<wfw:commentRss>https://blog.peneter.com/printnightmare-patched/feed/</wfw:commentRss>
			<slash:comments>0</slash:comments>
		
		
			</item>
	</channel>
</rss>
