rrrrr Posted May 16, 2017 Posted May 16, 2017 1) It's outdated and it appears Microsoft are looking to get rid of it anyway, at least in later versions of Windows 10. 2) Yes, but it's belt and braces, why have an outdated technology if you don't need it? Some may though. But wasnt ms09-050 a similar vuln in smb2?
jmak Posted May 16, 2017 Posted May 16, 2017 Why is everyone rushing to disable smbv1? Isnt applying ms17-010 patch the fix? For me it's mitigation against someone finding a laptop in a cupboard that's been hiding for too long to have received the patch or where the update has failed to install.
DJ-1701 Posted May 16, 2017 Posted May 16, 2017 Does anyone have the KB number for the XP patch please? (not for me before anyone says anything!) Thanks KB4012598, but the download can be found here. https://blogs.technet.microsoft.com/msrc/2017/05/12/customer-guidance-for-wannacrypt-attacks/
LeMarchand Posted May 16, 2017 Posted May 16, 2017 TL;DR is that more exploits will be released. Including for Win10, etc. Classified data as well. More "Translation please?" rather than "TL;DR".
Dos_Box Posted May 16, 2017 Posted May 16, 2017 I'm quite impressed that so far no schools have been reported as being hit (happy to be corrected btw). Is this down to better patch management, email filtering (if the infection was introduced via an email nasty/link) or another reason I wonder? It will be interesting to see the results of any investigations and enquiries as to how this first started and spread.
Jaan Posted May 16, 2017 Posted May 16, 2017 I'm quite impressed that so far no schools have been reported as being hit (happy to be corrected btw) Welldone! you just jinxed us all!
DJ-1701 Posted May 16, 2017 Posted May 16, 2017 (edited) But wasnt ms09-050 a similar vuln in smb2? Ah, but you can't remove SMB2 without disabling SMB3 in the process. Also https://blogs.technet.microsoft.com/filecab/2016/09/16/stop-using-smb1/ To quote one of the tweets in that blog from September... Ned Pyle (@NerdPyle) MS Principal Program Mgr. Running SMB1 is like taking your grandmother to prom: she means well, but she can't really move anymore. Also, it's creepy and gross Edited May 16, 2017 by DJ-1701
sippo Posted May 16, 2017 Posted May 16, 2017 I'm quite impressed that so far no schools have been reported as being hit (happy to be corrected btw). Is this down to better patch management, email filtering (if the infection was introduced via an email nasty/link) or another reason I wonder? It will be interesting to see the results of any investigations and enquiries as to how this first started and spread. Because we are all brilliant at our jobs... 2
pete Posted May 16, 2017 Posted May 16, 2017 I'm quite impressed that so far no schools have been reported as being hit (happy to be corrected btw). Is this down to better patch management, email filtering (if the infection was introduced via an email nasty/link) or another reason I wonder? It will be interesting to see the results of any investigations and enquiries as to how this first started and spread. I've heard a rumour that someone local-ish had their systems down from ~midday > evening yesterday, but the source is non-technical so I'm waiting on confirmation.
Andycat Posted May 16, 2017 Posted May 16, 2017 I'm quite impressed that so far no schools have been reported as being hit (happy to be corrected btw). Is this down to better patch management, email filtering (if the infection was introduced via an email nasty/link) or another reason I wonder? It will be interesting to see the results of any investigations and enquiries as to how this first started and spread. I heard on the radio that no real reports of personal users either?
Geoff Posted May 16, 2017 Posted May 16, 2017 More "Translation please?" rather than "TL;DR". They've proven everything they've said previously and it could be very likely they're telling the truth again. In which case this is the tip of the iceberg. Oh and code analysis of WeCry shows similarity to Lazarus Group code from 2015. https://blog.comae.io/wannacry-links-to-lazarus-group-dcea72c99d2d So you can assume that WeCry was written by one of Bureau 121 cells. Stituation still developing ofc.
Boredguy Posted May 16, 2017 Posted May 16, 2017 It could be that on the whole education and personal users deploy the monthly windows updates to clients on a faster turnaround that larger establishments such as NHS trusts. 1
Alis_Klar Posted May 16, 2017 Posted May 16, 2017 Have found a really great blog from the authors of MetaSploit which gives some sensible advice and says not to go out and panic buy a snake oil solution https://community.rapid7.com/community/services/blog/2016/07/01/prepare-yourself-for-ransomware-no-more-snake-oil-please
Alis_Klar Posted May 16, 2017 Posted May 16, 2017 sc.exe config lanmanworkstation depend= bowser/mrxsmb20/nsi Ensures only the Computer Browser, SMBv2 (and by extension v3 on those that support it), Network Store Interface Service are started as part of the Workstation Service. sc.exe config mrxsmb10 start= disabled Ensures the SMBv1 service is disabled from running. These commands can be run on Windows Vista+ Is "bowser" a typo? 2
DJ-1701 Posted May 16, 2017 Posted May 16, 2017 Is "bowser" a typo? [ATTACH=CONFIG]43231[/ATTACH] Na, it's just what they shorten the service name to. Though that Bowser did pop into my mind as well.
caffrey Posted May 16, 2017 Posted May 16, 2017 It's possible because this was propagated over SMB and not via email, so if anyone had the SMB ports open to the outside world you would've been hit?
Garacesh Posted May 16, 2017 Posted May 16, 2017 The Shadow Brokers have released a statement. https://steemit.com/shadowbrokers/@theshadowbrokers/oh-lordy-comey-wanna-cry-edition TL;DR is that more exploits will be released. Including for Win10, etc. Classified data as well. That grammar is being atrocious, but if they are being not lying, dark times ahead.
Dos_Box Posted May 16, 2017 Posted May 16, 2017 I heard on the radio that no real reports of personal users either? It all comes down to the attack vector I suppose. Once we have found out how it got in we can then draw comclusions as to why certain areas had not been affected. As regards to home users (there may have been some but too embaressed to make it public) it may be that many were at work when the outbreak occured and bosses had their workforces briefed about not clicking on emails with content like 'Your giraffe has been impounded. Please click here for more information on how to free your tree grazing mammal'. Basically, home users found out about it before they got home from work. As I said though, until we find out exactly how it got into the various networks it's all supposition.
DrCheese Posted May 16, 2017 Posted May 16, 2017 Home users will likely have had ports 139/445 blocked at ISP level both in/out since 2008's Sasser outbreak. I know VM for sure did that back then.
dry Posted May 16, 2017 Posted May 16, 2017 The Shadow Brokers have released a statement. https://steemit.com/shadowbrokers/@theshadowbrokers/oh-lordy-comey-wanna-cry-edition TL;DR is that more exploits will be released. Including for Win10, etc. Classified data as well. Some interesting theories there. Worth a read if you get a spare 10 minutes.
Geoff Posted May 16, 2017 Posted May 16, 2017 Yes the fact that we don't know the way 'patient zero' in the infected orgs got it is quite worrying. We do know that no one has seen anything in their spam traps that looks like WeCry. So we know it wasn't an email attachment clickfest like most other ransomware.
Geoff Posted May 16, 2017 Posted May 16, 2017 Kill switch for WeCry 3.0 ayylmaotjhsstasdfasdfasdfasdfasdfasdfasdf.com Seems to be a bit of a taunt with the 'lmao' in there. As mentioned, working theory that this is nation state ransomware created by the DPKR.
Arthur Posted May 16, 2017 Posted May 16, 2017 we know it wasn't an email attachment clickfest like most other ransomware. There are a lot of Windows devices with SMB and RDP accessible via the Internet. It wouldn't surprise me if it was either of those. https://www.shodan.io/search?query=port%3A445 www.shodan.io/search?query=port%3A445+country%3A%22GB%22 https://www.shodan.io/search?query=port%3A3389 https://www.shodan.io/search?query=port%3A3389+country%3A%22GB%22
Geoff Posted May 16, 2017 Posted May 16, 2017 (edited) Oh I get that, but I would of thought the targets would have secured SMB on their edge. It is utter madness to expose SMB to the internet. Edited May 16, 2017 by Geoff
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now