Jump to content

Recommended Posts

Posted

You'll have to bear with me as this one part of our server set up I rarely get involved on. Three years ago the school moved to Server 2102, there were 2 key reasons behind this, one was to the whole school on 1 network rather than 2 (1 for curriculum and 1 for admin), this also cut down on hardware cost, the second was to have remote access for teachers instead of using the offline files option.

This morning I noticed on Hyper-V a high cpu usage on the RDS Gateway server, so decided to connect using server manager....odd had an option to use the local admin account...so logged in, to be greeted with ransomware, contact us, pay this get encryption key.

Ok fired an email to our main sever support, they have shut down that server and renamed it and restoring from a back prior to the infection. The one question I have asked is how? has it come from outside, from an infected teacher laptop, via something that has been updated. None of the other VM's have been infected just this one.

The server support are suggesting that we should look at further protection.....in essence I agree, but first I would like to know how this has possibly happened.

 

I would appreciate any thoughts or direction I should take.

Posted

If your RDS Gateway server is setup to share drives when a user logs in, then this is probably how. E.g.

 

If a user has the ransomware virus infected on their computer, it is always looking for drives to encrypt. When they logon to your RDS server the drives are mapped and the ransomware virus gets to work encrypting all the files on the RDS server.

 

There are settings you can change on the RDS server to stop drives getting mapped. We only alway clipboard to access our RDS server.

 

Ad.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...