Joanne Posted January 9, 2017 Posted January 9, 2017 Caught the server being encrypted, so switched it off and called our LA support. It was halfway through staff home drives (hadn't got to mine) so hopefully the NAS backup will be OK. Non-attached backup was done in December, so if it is affected then not too much lost. Welcome back to work! Hahahah!
Patrick Posted January 9, 2017 Posted January 9, 2017 Did Sophos not catch it? Assuming you're using LA sophos? Worrying.
FN-GM Posted January 9, 2017 Posted January 9, 2017 Wowsers. Do you know how it happened? I am guessing it was via an admin account. If it was a standard user account it wouldn't have been able to encrypt everyones area (assuming permissions are setup correctly). Thanks
3s-gtech Posted January 9, 2017 Posted January 9, 2017 Do a permissions and account audit alongside the cleanup - the only accounts that should be able to access all staff home drives should be under the control of the IT team (or just you!) That's why many of us also don't use these accounts for day-to-day work.
Joanne Posted January 9, 2017 Author Posted January 9, 2017 OK - latest. It DID NOT affect staff home, that was my mistake whilst in a fizz about it. If affected staff shared, pupil shared and pupil home drives. It did not affect slt shared, office data (drives that have limited access) which I guess means that a staff account was used. I've scanned all staff laptops and all are coming up clear on Sophos. How else could it have happened?
ITBadger Posted January 9, 2017 Posted January 9, 2017 Do you use RDS? We were targeted through RDS last year with a generic staff account. Sounds very similar.
dry Posted January 9, 2017 Posted January 9, 2017 +1. Check which accounts have access via RDP. The tales I've heard on edugeek and from local techie friends suggests RDP is a popular method of attack currently. Check your password policies for all accounts too, especially those who have RDP access.
Joanne Posted January 9, 2017 Author Posted January 9, 2017 we do, but it's all through cleo with super secure passwords. I'm gonna be locking things down and changing some passwords I think...
Mr_Jiminy Posted January 9, 2017 Posted January 9, 2017 (edited) We were able to cross check events/ dates in our antivirus management console against our filter logs, both of which started a breadcrumb trail that pinpointed a computer account and user account. Edited January 9, 2017 by Mr_Jiminy
Joanne Posted January 9, 2017 Author Posted January 9, 2017 I've scanned all staff laptops and they are all clear... so confused.
DJ-1701 Posted January 9, 2017 Posted January 9, 2017 I've scanned all staff laptops and they are all clear... so confused. How about a pupil device that staff may have logged onto?
Joanne Posted January 9, 2017 Author Posted January 9, 2017 I think I'm going to disable this account and change our WiFi password.
3s-gtech Posted January 9, 2017 Posted January 9, 2017 Yeah a generic 'supply' account is not a good idea. I keep getting asked to enable 'the guest account' for people - the answer is no. Sign AUP, audit trail of who's using what account.
Joanne Posted January 9, 2017 Author Posted January 9, 2017 I'm trying to delete all of the encrypted stuff now... struggling though. I've taken ownership and it still won't let me... hmmm. On a bit of a tangent... were the files affected or effected BTW? I struggle with stuff like that
clareq Posted January 9, 2017 Posted January 9, 2017 If you must use a supply account, only give it read access to shared areas - supply staff have no need to edit files on a shared drive.
Mr_Jiminy Posted January 9, 2017 Posted January 9, 2017 Yeah a generic 'supply' account is not a good idea. I keep getting asked to enable 'the guest account' for people - the answer is no. Sign AUP, audit trail of who's using what account. Or lock it down so they can't blow a snot - USB device control, no internet. Makes having the account pointless
6Foot2 Posted January 9, 2017 Posted January 9, 2017 ...On a bit of a tangent... were the files affected or effected BTW? I struggle with stuff like that In that case, I believe it would be affected. ...the affected files... ...the files affected... 1
Mark182 Posted January 9, 2017 Posted January 9, 2017 I know the horse has bolted but we have asked BTLS to look into this Intercept X along with our current sub from them. Good luck in getting it sorted. 1
3s-gtech Posted January 9, 2017 Posted January 9, 2017 'the effect of the attack was to affect the files' Those scenes have amazing effects vs I have been affected by losing my dog
Joanne Posted January 9, 2017 Author Posted January 9, 2017 Now I have the issue of getting onto my zone director to change the wifi password.... hahahahah!! Damn you cipher mismatch!
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now