Presenting the vulnerability in the SMBv1 protocol, identified by the fix released by Microsoft: MS17-010, using the EternalBlue/DoublePulsar exploit, this vulnerability had its propagation through WannaCry that using the flaw had its spread on May 12, 2017. No system is 100% secure, information security rule, however in the field of intrusion testing most of the flaws exploited by CVE (Common Vulnerabilities and Exposures ) have already been corrected and released correction path, but without updating by users . The methodology used was research applied in a field study, through the analysis of this vulnerability and description of the entire process of exploiting the security flaw. Bibliographic research was also used to give theoretical support to the study. With this study, it was possible to present real cases of the risk existing in outdated systems, which allow access and exploitation by malicious people. The exploitation of vulnerabilities by ethical researchers is a safe way to help information security in organizations that rely on science to guarantee their computing assets. The research presents the problem and the solution to guarantee information security in organizations that are vulnerable to the studied attack method, thus helping Information Security for IT managers.
scite is a Brooklyn-based organization that helps researchers better discover and understand research articles through Smart Citations–citations that display the context of the citation and describe whether the article provides supporting or contrasting evidence. scite is used by students and researchers from around the world and is funded in part by the National Science Foundation and the National Institute on Drug Abuse of the National Institutes of Health.