绿盟 - nsfocus - CVE-2016-2183 - Windows 2008 R2
问题:Windows 2008 R2 系统,提示 CVE-2016-2183 高危漏洞。已经打全Windows补丁。
尝试:
- 禁用 TLS 1.0, TLS 1.1,启用 TLS 1.2
- 禁用 Triple DES 168
- 仅允许使用网络级别身份验证的远程桌面的计算机连接远程桌面
参考:
- http://www.nsfocus.net/vulndb/34880
- https://gallery.technet.microsoft.com/scriptcenter/Solve-SWEET32-Birthday-d2df9cf1
- https://qualys-secure.force.com/discussions/s/question/0D52L00004Tnz7BSAR/birthday-attacks-on-different-port
- https://social.technet.microsoft.com/Forums/Azure/zh-CN/cea898dc-9088-4169-b6c0-8af27086521a/windows-server-2016-28431279343838239064?forum=winserver8zhcn
- https://kb.iweb.com/hc/en-us/articles/230268628-SSL-TLS-issues-POODLE-BEAST-SWEET32-attacks-and-the-End-of-SSLv3-OpenSSL-Security-Advisory