Jump to content

Recommended Posts

Posted

Caught the server being encrypted, so switched it off and called our LA support. It was halfway through staff home drives (hadn't got to mine) so hopefully the NAS backup will be OK. Non-attached backup was done in December, so if it is affected then not too much lost.

 

Welcome back to work! Hahahah!

Posted
Wowsers. Do you know how it happened?

 

I am guessing it was via an admin account. If it was a standard user account it wouldn't have been able to encrypt everyones area (assuming permissions are setup correctly).

 

Thanks

Posted
Do a permissions and account audit alongside the cleanup - the only accounts that should be able to access all staff home drives should be under the control of the IT team (or just you!) That's why many of us also don't use these accounts for day-to-day work.
Posted

OK - latest. It DID NOT affect staff home, that was my mistake whilst in a fizz about it. If affected staff shared, pupil shared and pupil home drives. It did not affect slt shared, office data (drives that have limited access) which I guess means that a staff account was used.

 

I've scanned all staff laptops and all are coming up clear on Sophos.

 

How else could it have happened?

Posted
+1. Check which accounts have access via RDP. The tales I've heard on edugeek and from local techie friends suggests RDP is a popular method of attack currently. Check your password policies for all accounts too, especially those who have RDP access.
Posted
we do, but it's all through cleo with super secure passwords. I'm gonna be locking things down and changing some passwords I think...
Posted (edited)
We were able to cross check events/ dates in our antivirus management console against our filter logs, both of which started a breadcrumb trail that pinpointed a computer account and user account. Edited by Mr_Jiminy
Posted
Yeah a generic 'supply' account is not a good idea. I keep getting asked to enable 'the guest account' for people - the answer is no. Sign AUP, audit trail of who's using what account.
Posted

I'm trying to delete all of the encrypted stuff now... struggling though. I've taken ownership and it still won't let me... hmmm.

 

On a bit of a tangent... were the files affected or effected BTW? I struggle with stuff like that ;)

Posted
If you must use a supply account, only give it read access to shared areas - supply staff have no need to edit files on a shared drive.
Posted
Yeah a generic 'supply' account is not a good idea. I keep getting asked to enable 'the guest account' for people - the answer is no. Sign AUP, audit trail of who's using what account.

 

Or lock it down so they can't blow a snot - USB device control, no internet. Makes having the account pointless ;)

Posted
...On a bit of a tangent... were the files affected or effected BTW? I struggle with stuff like that ;)

In that case, I believe it would be affected.

 

...the affected files...

 

...the files affected...
  • Thanks 1
Posted
Now I have the issue of getting onto my zone director to change the wifi password.... hahahahah!! Damn you cipher mismatch!

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...