Jump to content

Recommended Posts

Posted
If the March update fixes the exploit is there any need to rush around disabling SMB1 ? Of course there is no harm doing so and a good precaution
Posted (edited)

If you click the "Server storage at Microsoft" link at the bottom of that KB article and then scroll down to the comments section, Microsoft mention that setting those registry values for later operating systems is not optimal. I guess the belt and braces approach is a good idea if there's a chance someone else might re-enable the SMB1 feature. :)

 

https://blogs.technet.microsoft.com/filecab/2016/09/16/stop-using-smb1/#div-comment-106065

 

7NIFTc.png

Edited by Arthur
  • Thanks 1
Posted
The following will run a PowerShell command directly without a script. You could give this a try?

 

Powershell.exe -ExecutionPolicy Bypass -NoProfile -Command "Disable-WindowsOptionalFeature -Online -FeatureName smb1protocol -NoRestart"

 

Getting closer. Client is no longer giving eventlog errors that GPO did not run correctly, but it isn't actually removing the feature!

 

More playing to do

Posted

I've ran windows update on all my servers which had the latest roll up of patches so I'm assuming the March patch was included? Each server was rebooted.

 

I've then ran the command to remove SMB1 on each server which also required another restart.

 

All done remotely and thankfully all have have come back up including the cluster which sometimes gets a bit funny after updates.

 

We're mostly Windows 10 but have a handful of Win7 clients. I've created a GPO that tweaks the registry to turn off SMB1 for Win7 but need to do something for the Win10 clients. I'll look at WSUS to see what has and has not been applied and follow up on Monday.

 

I've also emailed all staff that link from Kent Uni which gives excellent advice for staff and in staff briefing tomorrow will make clear what has happened and what staff should look for.

 

Anything I've missed?

 

Pete

Posted
let's hope Cunningham's have a solution also?

What are the chances they will want to send an engineer out (chargeable visit) rather than run some commands remotely? Easy money for them! :(

Posted
Getting closer. Client is no longer giving eventlog errors that GPO did not run correctly, but it isn't actually removing the feature!

 

More playing to do

 

Ah this is annoying me now. Even entered an Out-File pipe and that file gets created but never populated, like the command doesn't run but it must be running to create the Out-File.....

 

Manually entering command works so command is correct.

 

I can't seem to put a Start-Transcript command in as this can't be piped to then run the command

Posted (edited)
If the March update fixes the exploit is there any need to rush around disabling SMB1?

The SMB1 vulnerability used by the self-propagating worm part of WannaCrypt has been patched, but you never know what could be coming next. :(

 

Next cyber-attack could be imminent, warn experts « BBC News

 

Another major cyber-attack could be imminent after Friday's global hit that infected more than 125,000 computer systems, security experts have warned.

 

UK security researcher "MalwareTech", who helped to limit the ransomware attack, predicted "another one coming... quite likely on Monday".

 

MalwareTech, who wants to remain anonymous, was hailed as an "accidental hero" after registering a domain name to track the spread of the virus, which actually ended up halting it.

 

The 22-year-old told the BBC: "It's very important that people patch their systems now.

 

"We have stopped this one, but there will be another one coming and it will not be stoppable by us.

 

"There's a lot of money in this. There's no reason for them to stop. It's not really much effort for them to change the code and then start over.

 

"So there's a good chance they are going to do it... maybe not this weekend, but quite likely on Monday morning."

 

On Sunday he warned hackers could upgrade the virus to remove the "kill switch" that helped to stop it.

 

"Version 1 of WannaCrypt was stoppable but version 2.0 will likely remove the flaw. You're only safe if you patch ASAP," he tweeted.

 

Fellow security researcher Darien Huss, from tech firm Proofpoint, echoed MalwareTech's view.

 

"I highly suspect that, with the amount of coverage that this incident is getting, there are probably already people that are working to incorporate the exploit that was used for spreading," he said.

 

He said his research experience on targeted attacks made him doubt a nation state was involved here.

 

"This attack was so simple and unsophisticated, that leads me to believe the people or person involved, even though they are quite capable, they're more along the lines of an amateur," he said.

Edited by Arthur
Posted

I have found some info on the MS website about disabling SMBv1 on Windows 7 clients as follows:

 

To disable SMBv1 on the SMB client, run the following commands:

sc.exe config lanmanworkstation depend= bowser/mrxsmb20/nsi

sc.exe config mrxsmb10 start= disabled

 

Would it be possible to put this into a batch file that runs at login just in case I have any machines across the network that haven't been patched?

 

It has to run as administrator in order to work ....how would that happen if it were part of login script?

 

Or is this a bad idea to start with?!

Posted
Has anyone seen any case of this in any schools yet ?

 

Hopefully none but would suspect its effected someone somewhere. Monday might be the day people are hit with potentially staff using unpatched laptops over the weekend and bringing them in to infect the rest of the network.

Posted
I agree, just a bit concerned everyone rushing to disable this not knowing if it has any possible knock on effects especially with older legacy stuff without testing.

Well in a Windows environment, if you have moved from XP and 2003, then SMB2 and SMB3 should be fine... If not, damn good reason to tip the powers that be's hands to upgrade NOW!

Posted (edited)

Deploying the March/May update to just shy of 300 Windows 10 Laptops tomorrow morning will be painful

 

Laptops are normally put on ring2 of our Update schedule and we do this during half terms when we just roll in turn them all on and walk away to the next set and come back later.

 

Shame there isn't (unless I've missed it) a single smaller KB just for this vulnerability.

Edited by Asgard
Posted

Tomorrow is going to be D-day for a lot people.

 

I've deployed out removing SMBv1 from all devices using this

 

https://www.techwhisperer.ca/2017/03/04/disable-smb1-with-powershell-and-sccm/

 

Most devices are already patched with the March patch but there will be student devices which haven't been booted up in a while no doubt so need to get everything switched on tomorrow.

Trouble is for everyone tomorrow, will be trying to ensure stuff is on and ready for patching while people are going to be using equipment.

 

Fingers crossed for everyone tomorrow.

Posted

WannaCry — New Variants Detected!

 

Today (14 May 2017), 2 new variants appeared. One working which I blocked by registering the new domain name, and the second which is only partially working because it only spreads and does *not* encrypt files due to a corrupted archive.

 

  1. A new variant had been caught by @benkow_ in the wild and sent to me for analysis. I reversed it and found a new kill-switch (ifferfsodp9ifjaposdfjhgosurijfaewrwergwea.com) which I immediately registered to stop the new wave of global attacks. Then, I synchronized with @MalwareTechBlog and @2sec4u to map the new domain to sinkhole name servers to feed the live interactive infection map. This is 32f24601153be0885f11d62e0a8a2f0280a2034fc981d8184180c5d3b1b9e8cf.
     
     
  2. A new variant with no kill-switch recovered by Kaspersky as a virustotal.com upload — not detected in the Wild. Although, this build does only work *partially* as the ransomware archive is corrupted — the spreading still works though. This is 07c44729e2c570b37db695323249474831f5861d45318bf49ccf5d2f5c8ea1cd.

[...]

 

The fact the no kill-switch variant is only partially working is most likely a temporary mistake from the attackers. Remember, even though the ransomware decompression is not working — the spreading through ETERNALBLUE & DOUBLEPULSAR is still working.

 

The fact I registered the new kill-switch today to block the new waves of attacks (sinkhole.tech reported to me they are receiving hits) is only a temporarily relief which does not resolve the real issue which is that many companies and critical infrastructures are still dependent on legacy and out of support Operating Systems.

  • Thanks 2
Posted

Such a lot of information here. Can anybody help by summarising the steps I need to take tomorrow and what to check for and where?

I'm going to ask for all class laptops in - teachers have MacBooks - so servers and laptops and suite machine will need looking at and I guess ops units on the boards in class.

Posted

Just read an update from our Trust.

 

Asked all staff to fully turn off all PCs / laptops etc then boot them back up (presumably the Microsoft patch has been rolled out).

 

No use of VPN, NHS Mail, asked to keep Internet usage to a minimum, internal Exchange off until Wednesday at the earliest.

  • Thanks 1
Posted
Just read an update from our Trust.

 

Asked all staff to fully turn off all PCs / laptops etc then boot them back up (presumably the Microsoft patch has been rolled out).

 

No use of VPN, NHS Mail, asked to keep Internet usage to a minimum, internal Exchange off until Wednesday at the earliest.

Ouch you must have been hit bad. [emoji51]

 

We are back up and running barring some non-essential servers.

 

Big thing for us is the GPs we support as well, so tomorrow is going to be busy.

 

I drew the short straw of being on call all weekend... [emoji58]

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...