HomeSecurityWindows 11: Provides better protection against SMB brute-force attacks

Windows 11: Provides better protection against SMB brute-force attacks

Following the release of Insider Preview Build 25206 to the Dev Channel, Microsoft announced that Windows 11 's SMB server is now better protected against brute-force attacks.

See also: Windows 11 blocks RDP brute-force attacks by default

SMB

The company has enabled the SMB authentication rate limiter by default to 2 seconds between each failed inbound NTLM authentication attempt and has tweaked some of settings to make such attacks less effective, starting with the latest Windows 11 Insider developer build. This means that if an attacker previously made 300 brute-force attempts per second on a client for 5 minutes (90,000 passwords), the same number of attempts would now take at least 50 hours.

Once enabled, this feature adds a delay between each failed NTLM authentication check as an additional protection for the SMB server service.

This makes a Windows an unattractive target either when it is in a workgroup or for its local accounts when it is connected to a domain.

Although the SMB server will start automatically in all versions of Windows, it will only be exposed to the Internet if the firewall is manually opened or if a client SMB share is created to open it.

See also: Raspberry Pi: Removes default user to prevent brute-force attacks

brute force

The SMB authentication rate limiter was first introduced in March in Windows Server, Windows Server Azure Edition , and Windows 11 Insider, although it is not enabled by default.

To benefit from enhanced brute-force attack protection on systems running Windows Server, administrators must manually enable it using the following PowerShell (where n is the delay time between each failed NTLM authentication attempt):

Set-SmbServerConfiguration -InvalidAuthenticationDelayTimeInMs n

“This behavior change has no impact on Kerberos, which verifies authentication before an application protocol like SMB connects. It is designed to be an additional layer of defense in depth, especially for devices that are not joined to domains like home users,” Microsoft says.

See also: Microsoft: Blocked billions of brute-force and phishing attacks in 2021

Today's announcement comes after the company revealed several other SMB security improvements in recent years, including switching the 30-year-old SMBv1 file sharing protocol by default (for some users) and making SMB over QUIC generally available in Windows 11 and Windows Server 2022 .

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Absentee Mia
Absentee Miahttps://www.secnews.gr/politiki-syntaxis/
Member of the Editorial Team of SecNews. He writes about cybersecurity, online fraud, privacy and technology. All articles follow the SecNews Editorial Policy.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS