Jump to content

Recommended Posts

Posted
The second tweet there sums up my reaction.

 

+1

 

I mean it takes some special kind of [rudies] to write ransomware anyway, but to attack hospitals is just.. sociopathic.

Have a vaguely-friend-acquaintance who's an IT tech in the NHS. I'll have to check in, see if her hospital's been hit.. Not that I could do anything anyway.

  • Thanks 1
Posted
I'm at work right now and it is complete mayhem!

 

Ah yeah, you've moved to the NHS recently haven't you..

Blimey. Baptism by fire, 'eh?!

Best of luck!

Posted

Time to start taking bets: which political party will be the first to politicise...

 

That's got to have been going undetected for a while to spread throughout the whole NHS. Or are some Trusts down to protect themselves from other Trusts I wonder

  • Thanks 2
Posted

We've had a rumor it is something to do with RDP

 

Our local systems don't seem to have been hit thus far, we're killing off most links to other community sites though (all 140+ of them!)

  • Thanks 1
Posted

If you want a laugh the BBC have a 'live report' on the news site, with lots of doctors writing in to moan they can't access their email or whatever...

 

I'm just waiting for one to write in pondering when the systems will be back online

  • Thanks 1
Posted

This has just been posted on the JISC Uk Security Mailing List

 

 

I'm sure that by now most of you are aware of the issues affecting

several NHS trusts.

 

The malware in question appears to be a new variant of wcry.

 

Early indications are showing that this is exploiting MS17-010 which is

a vulnerability in Microsoft Server Message Block 1.0 SMBv1.

 

Further information on this particular issue is available here

https://technet.microsoft.com/en-us/library/security/ms17-010.aspx

 

Recommended best practice is not to expose your infrastructure to these

services, if you are concerned that you are vulnerable to this then

disabling SMBv1 is recommended.

 

https://blogs.technet.microsoft.com/filecab/2016/09/16/stop-using-smb1/

 

There is a thread covering the issue on the CISP website.

 

Posted
And NHS staff starting their PC up to show journalists and take pictures for Twitter. You're helping spread the virus! You know what a virus is don't you doctor
  • Thanks 1
Posted

My Oh works for the NHS - not in IT#They have been getting messages for some time reminding them not to open dodgy emails

- they have been also getting phone calls 'from IT' trying to get access to their PC via Teamviewer and such like

 

 

she hasn't seen/heard any herself but there have been many waarnings which implies that a lot of people have had such calls and reported them

 

seems like someone has been after at least part of the NHS for a while

Posted

In our Trust we have about 100 XP PCs left, then 2/3 Server 2003, about 15 Server 2008 then the rest Server 2008 R2 / 2012 / 2016 although by the sounds of things this attack could affect any of those operating systems we took down most of the pre 2008 R2 stuff initially.

 

The problem will have been some idiot opening a dodgy email with an 'invoice' or similar and boom infection starts spreading, we can put notice after notice on the intranet, the staff bulletins etc but most users won't pay a blind bit of attention! Doesn't help when the emails have become so clever they can now appear to originate from a genuine user with a genuine NHS address.

 

To be honest I left the scene quite early as there wasn't much I could do, in education you could probably just knock off the entire server room for a bit but it is a bit more tricky in healthcare sadly. I know we knocked the VEEAM box off to help prevent the chance of the backups becoming infected.

 

No doubt there is going to be a good few weeks of aftershock...

Posted

Got it in one there googlemad, I spent 8 years in the NHS and I've seen it all.

 

Further up the topic there was mention of the N3 backbone, the ACL's on this network are quite strict which would prevent spread, it just happens to be a coincidence this. Also the network isn't as open as you think!

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...