News about Badlock vulnerability affecting Windows computers and Samba servers started showing up on Twitter and media around three weeks ago. The site badlock[.]org was registered on March 11 according to WHOIS, a secure domain search engine. There has been a lot of guessing and speculation around this vulnerability. It’s time for reality check: just how bad actually is Badlock?
Named vulnerabilities have resulted in being clichéd very quickly. Being a named vulnerability doesn’t qualify it as a serious widespread vulnerability. Badlock is somewhere in between. In this entry, we demystify the hype of Badlock with questions that measure it as a vulnerability. We also pin it up against a noteworthy case to see how it compares.
Post from: Trendlabs Security Intelligence Blog – by Trend Micro