NETGEAR is aware of a growing number of phone and online scams. To learn how to stay safe click here.
Forum Discussion
Platypus69
May 15, 2017Luminary
SMB 1.0 (Given Wanna Cry)
Out of curiosity in the latest 6.7.1 firmware is SMB 1.0 disabled?
Can we control SMB so that it ONLY used 3.0 or 2.0-3.0 for example?
- May 24, 2017
The Wanna Cry issue used an attack vendor to attack Windows machines that hadn't had a security update installed. Our NAS units don't run Windows.
The latest RAIDiator 4.1.x and RAIDiator-arm uses samba 3.5.x. The latest RAIDiator-x86 4.2.x uses samba 3.6.x
Experimental SMB2 support was added in samba 3.5.x, but really you should be using a newer version of samba to use it. 3.6 isn't much newer. I'd be wanting to use newer than that. To my knowledge we don't have any plans to update samba on these old OSes.
I think SMB2 support is turned off by default on all those models.
OS6 currently uses samba 4.4.x, a much newer samba series.
I've passed on the feature request to be able to disable SMB1 support from the GUI for OS6 devices.
Retired_Member
May 15, 2017Installing SMB plus will force SMB3 to be used as default to my knowledge.
Platypus69
May 16, 2017Luminary
Thanks all.
Am using latest version of SMB Plus (1.0.6).
It says:
ReadyNAS supports SMB protocol 3.0 by default. Some Windows applications will not work with SMB 3. For example, Microsoft System Image Backup for Windows 8/Server 2012 will not work with anything higher than SMB 2.0. Adjust the maximum protocol version ReadyNAS will support by changing the setting below.
New SMB connections will adopt the new settings. Establish connections will remain connected as the previous setting. To force existing connections to change settings, the ReadyNAS or the client should be restarted.
So it would be good if there was also a Minimum Protocol Version option.
- sotrackMay 16, 2017Luminary
Disable SMBv1 and enable SMBv2 on your PC (Windows7 or Windows8 or Windows10, 32-bit or 64-bit.):
a) Open command prompt with administrator rights (press "Win" button, type “cmd”, right-click "cmd.exe" and select "Run as administrator"
b) copy the text below, paste it into command prompt and press Enterreg add "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\LanmanServer\Parameters" /v SMB1 /t reg_dword /d 0 /f reg add "HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\LanmanServer\Parameters" /v SMB2 /t reg_dword /d 1 /f sc.exe config lanmanworkstation depend= bowser/mrxsmb20/nsi sc.exe config mrxsmb10 start= disabled
c) reboot PC
- Platypus69May 16, 2017Luminary
Thanks. I know.
Here is the full KB from Microsoft for others:
- sotrackMay 17, 2017Luminary
In addition for others a list of Windows WannaCry patches:
Related Content
NETGEAR Academy
Boost your skills with the Netgear Academy - Get trained, certified and stay ahead with the latest Netgear technology!
Join Us!