Jump to content

Recommended Posts

Posted
1) It's outdated and it appears Microsoft are looking to get rid of it anyway, at least in later versions of Windows 10.

2) Yes, but it's belt and braces, why have an outdated technology if you don't need it? Some may though.

 

But wasnt ms09-050 a similar vuln in smb2?

Posted
Why is everyone rushing to disable smbv1?

Isnt applying ms17-010 patch the fix?

For me it's mitigation against someone finding a laptop in a cupboard that's been hiding for too long to have received the patch or where the update has failed to install.

Posted

I'm quite impressed that so far no schools have been reported as being hit (happy to be corrected btw).

Is this down to better patch management, email filtering (if the infection was introduced via an email nasty/link) or another reason I wonder?

It will be interesting to see the results of any investigations and enquiries as to how this first started and spread.

Posted
I'm quite impressed that so far no schools have been reported as being hit (happy to be corrected btw)

 

Welldone! you just jinxed us all!

Posted (edited)
But wasnt ms09-050 a similar vuln in smb2?

 

Ah, but you can't remove SMB2 without disabling SMB3 in the process.

 

Also https://blogs.technet.microsoft.com/filecab/2016/09/16/stop-using-smb1/

 

To quote one of the tweets in that blog from September...

 

Ned Pyle‏ (@NerdPyle) MS Principal Program Mgr.

 

Running SMB1 is like taking your grandmother to prom: she means well, but she can't really move anymore. Also, it's creepy and gross

Edited by DJ-1701
Posted
I'm quite impressed that so far no schools have been reported as being hit (happy to be corrected btw).

Is this down to better patch management, email filtering (if the infection was introduced via an email nasty/link) or another reason I wonder?

It will be interesting to see the results of any investigations and enquiries as to how this first started and spread.

 

Because we are all brilliant at our jobs...

  • Thanks 2
Posted
I'm quite impressed that so far no schools have been reported as being hit (happy to be corrected btw).

Is this down to better patch management, email filtering (if the infection was introduced via an email nasty/link) or another reason I wonder?

It will be interesting to see the results of any investigations and enquiries as to how this first started and spread.

 

I've heard a rumour that someone local-ish had their systems down from ~midday > evening yesterday, but the source is non-technical so I'm waiting on confirmation.

Posted
I'm quite impressed that so far no schools have been reported as being hit (happy to be corrected btw).

Is this down to better patch management, email filtering (if the infection was introduced via an email nasty/link) or another reason I wonder?

It will be interesting to see the results of any investigations and enquiries as to how this first started and spread.

 

I heard on the radio that no real reports of personal users either?

Posted
More "Translation please?" rather than "TL;DR".

 

They've proven everything they've said previously and it could be very likely they're telling the truth again. In which case this is the tip of the iceberg.

 

Oh and code analysis of WeCry shows similarity to Lazarus Group code from 2015.

 

https://blog.comae.io/wannacry-links-to-lazarus-group-dcea72c99d2d

 

So you can assume that WeCry was written by one of Bureau 121 cells.

 

Stituation still developing ofc.

Posted
It could be that on the whole education and personal users deploy the monthly windows updates to clients on a faster turnaround that larger establishments such as NHS trusts.
  • Thanks 1
Posted
sc.exe config lanmanworkstation depend= bowser/mrxsmb20/nsi

 

Ensures only the Computer Browser, SMBv2 (and by extension v3 on those that support it), Network Store Interface Service are started as part of the Workstation Service.

 

 

 

sc.exe config mrxsmb10 start= disabled

 

Ensures the SMBv1 service is disabled from running.

 

 

These commands can be run on Windows Vista+

 

Is "bowser" a typo?

bowser.jpg

  • Thanks 2
Posted
Is "bowser" a typo?

[ATTACH=CONFIG]43231[/ATTACH]

 

Na, it's just what they shorten the service name to. Though that Bowser did pop into my mind as well. ;)

Posted
It's possible because this was propagated over SMB and not via email, so if anyone had the SMB ports open to the outside world you would've been hit?
Posted
I heard on the radio that no real reports of personal users either?

 

It all comes down to the attack vector I suppose. Once we have found out how it got in we can then draw comclusions as to why certain areas had not been affected.

As regards to home users (there may have been some but too embaressed to make it public) it may be that many were at work when the outbreak occured and bosses had their workforces briefed about not clicking on emails with content like 'Your giraffe has been impounded. Please click here for more information on how to free your tree grazing mammal'.

Basically, home users found out about it before they got home from work.

As I said though, until we find out exactly how it got into the various networks it's all supposition.

Posted
Home users will likely have had ports 139/445 blocked at ISP level both in/out since 2008's Sasser outbreak. I know VM for sure did that back then.
Posted
Yes the fact that we don't know the way 'patient zero' in the infected orgs got it is quite worrying. We do know that no one has seen anything in their spam traps that looks like WeCry. So we know it wasn't an email attachment clickfest like most other ransomware.
Posted

Kill switch for WeCry 3.0

 

ayylmaotjhsstasdfasdfasdfasdfasdfasdfasdf.com 

 

Seems to be a bit of a taunt with the 'lmao' in there. :)

 

As mentioned, working theory that this is nation state ransomware created by the DPKR.

Posted (edited)

Oh I get that, but I would of thought the targets would have secured SMB on their edge. It is utter madness to expose SMB to the internet.

 

or36jnaBJi_98fjP3MwXJn0MdDIshf9PbLMMxx14BCVkOpmFBaZUUlrchOuxWjymyYWHW64B-zmcw1z4xQyf0pcWN0Z2zE1x.jpg

Edited by Geoff

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...