Jump to content

Recommended Posts

Posted (edited)
What's unclear is why many websites claim that Windows 10 wasn't targeted, yet Microsoft did release a patch in March 2017 for it also.

If you look in the Eternalblue-2.2.0.0.xml file in the Shadow Broker's GitHub repo and you'll see that Windows 10 isn't listed.

 

https://github.com/misterch0c/shadowbroker/blob/master/windows/specials/Eternalblue-2.2.0.0.xml

 

Also: https://twitter.com/hackerfantastic/status/852999174631170048

Edited by Arthur
Posted (edited)

https://arstechnica.com/security/2017/05/a-wormable-code-execution-bug-has-lurked-in-samba-for-7-years-patch-now/

 

Maintainers of the Samba networking utility just patched a critical code-execution vulnerability that could pose a severe threat to users until the fix is widely installed.

 

The seven-year-old flaw, indexed as CVE-2017-7494, can be reliably exploited with just one line of code to execute malicious code, as long as a few conditions are met. Those requirements include vulnerable computers that (a) make file- and printer-sharing port 445 reachable on the Internet, (b) configure shared files to have write privileges, and © use known or guessable server paths for those files. When those conditions are satisfied, remote attackers can upload any code of their choosing and cause the server to execute it, possibly with unfettered root privileges, depending on the vulnerable platform.

 

"All versions of Samba from 3.5.0 onwards are vulnerable to a remote code execution vulnerability, allowing a malicious client to upload a shared library to a writable share, and then cause the server to load and execute it," Samba maintainers wrote in an advisory published Wednesday. They urged anyone using a vulnerable version to install a patch as soon as possible.

Edited by Arthur
  • Thanks 1
Posted

Alert: Microsoft Tech-Support Scammers using WannaCry attack to lure victims

 

Action Fraud has received the first reports of Tech-Support scammers claiming to be from Microsoft who are taking advantage of the global WannaCry ransomware attack.

 

One victim fell for the scam after calling a ‘help’ number advertised on a pop up window. The window which wouldn’t close said the victim had been affected by WannaCry Ransomware.

 

The victim granted the fraudsters remote access to their PC after being convinced there wasn’t sufficient anti-virus protection. The fraudsters then installed Windows Malicious Software Removal Tool, which is actually free and took £320 as payment.

Posted
Apparently the latest 1703 is immune, but I'm not sure if that's true either!?

 

That's correct, if you are running the Creators Update (1703) it comes with the required updated files.

 

Anniversary Update (1607) needs to be at least build 14393.953

Fall Update (1511) needs to be at least build 10586.839

RTM (1507) needs to be at least build 10240.17319

  • 2 weeks later...
Posted

The BBC made a Horizon programme about WannaCry and the NHS. It's now on iPlayer.

 

www.bbc.co.uk/iplayer/episode/b08vfzm0/horizon-2017-cyber-attack-the-day-the-nhs-stopped

 

A few weeks ago, the National Health Service was hit by a widespread and devastating cyber attack - Horizon tells the inside story of one of the most challenging days in the history of the NHS.

 

On the morning of 12 May the attack started. Appointment systems, pathology labs, x-rays and even CT scanners were infected - putting not just data but patients lives at risk, and on every screen a simple - some may even say polite - message appeared. 'Ooops, your files have been encrypted!'

 

But what followed was far from civilised. It was very clear that all the data on an infected machine was now scrambled and only the hackers could unscramble it. For a price - and with an extra twist - after a few days the ransom money doubled, and if nothing was paid within a week, the hackers threatened to destroy all the data - forever.

  • Thanks 1
Posted
I thought this was a good watch and quite interesting (well, everyone reading this is a self declared geek!) and informative about the story behind the virus and people trying to deal with it, even if you've been staying on top of information about fixing it from a technical point of view. My wife didn't leave the room while I watched it....
Posted
It was a good watch but the person at the BBC in charge of program schedule's is clearly not a geek because they put it on at the same time as Ubisofts E3 show.
  • Thanks 1
Posted (edited)

I caught about 5 mins of the program.

Did they say that the nhs's n3 network wasn't affected, just unpatched pc's?

Why did it affect multiple NHS organisations then, how were they targeted?

Edited by ollyyllo
Posted
It is a Netgear ReadyNAS NV+

 

Not a major appliance by any standards, just a simple backup device. But looks like I need SMB1 to access it :-/

 

Thought I'd mention, Netgear released an updated firmware today for this older NAS which patches the samba system :) So I should be able to switch off SMBv1 now and still access the NAS!

  • Thanks 1
Posted (edited)
Thought I'd mention, Netgear released an updated firmware today for this older NAS which patches the samba system :) So I should be able to switch off SMBv1 now and still access the NAS!

 

Just checked, and they've also released an update for my lovely ReadyNAS Pro 2 which seems to focus on the same thing. Will see if it works - would be nice to access it again via SMB (it only works via NFS now).

 

Edit: it's alive! Won't join AD any more, but that's not an issue in this role.

Edited by 3s-gtech
Posted
Well on Friday afternoon I had a real world test of our network security, and I'm happy to say it passed with flying colours.

 

A teacher came in to me at about 4pm saying she couldn't copy her reports to her memory stick at first I thought it was just another dead memory stick but when I put it in my PC Sophos went crazy, turns out it was infected with Cryptoguard malware, Sophos Central dealt with it before I even knew what was going on and it initiated a scan on hers and my computer and killed it dead before it could do any damage.

 

I only just upgraded to Sophos Central with Intercept X at the end of last term and I'm so glad I did because I'm fairly confident the standard Sophos enterprise endpoint protection would not have dealt with it quite so well.

 

There was me thinking I'd be working late on a Friday but Sophos stepped up and was like "Chill bruv, I got this!"

 

This is why I don't plug users USB sticks into my pc. Glad your software dealt with it though.

Posted
This is why I don't plug users USB sticks into my pc. Glad your software dealt with it though.

 

And this is why we don't allow USB sticks at all. +1 for your AV tho'

Posted

Honda plant in Japan briefly stops making cars after fresh WannaCrypt outbreak

 

Honda said today that it had briefly halted operations at a car plant in Sayama, Japan earlier this week because of the infamous WannaCrypt ransomware.

 

The Japanese car maker halted production for one day at a domestic vehicle plant on Monday after finding samples of the WannaCrypt ransomware in its computer network, Reuters reports.

 

The Renault-Nissan alliance had similar problems at five of their jointly operated plants in the immediate aftermath of the original WannaCrypt outbreak last month. Problems at another carmaker's plant are only surprising because of the timing – weeks after the original outbreak.

 

Hours after the original highly virulent WannaCrypt outbreak, security researcher Marcus Hutchins registered a domain found in the code that acted as a kill-switch and stopped the original ransomware spreading any further. It could be that Honda has blocked access to this domain internally, some experts have speculated.

 

It's not immediately clear if the original WannaCrypt, which hobbled systems at multiple NHS trusts and numerous enterprises worldwide last month, or one of many subsequent variants lies behind Honda's problem. Security experts said that as long as the underlying fault remains unresolved, then WannaCrypt variants will remain an issue.

Posted

The NHS IT department in my wife's hospital are absolutely shocking.

 

They are trying to move her to an @nhs.net address and are really struggling.

 

Is it due to lack of investment in IT?

Posted
The NHS IT department in my wife's hospital are absolutely shocking.

 

They are trying to move her to an @nhs.net address and are really struggling.

 

Is it due to lack of investment in IT?

 

Yes. My brother-in-law has been working in the local hospital IT since he lost his job at Marconi when it folded some years ago. He was quite high up and has knowledge of infrastructure etc and he is horrified by the situation he is now in. No money, little or no expertise, and permanently blocked by people not allowing things to be done - such as consultants never bringing laptops in for updates etc.

Posted
permanently blocked by people not allowing things to be done - such as consultants never bringing laptops in for updates etc.

 

They are very busy and important people, you know. Those golf rounds don't just play themselves!

Posted
The NHS IT department in my wife's hospital are absolutely shocking.

They are trying to move her to an @nhs.net address and are really struggling.

Is it due to lack of investment in IT?

 

As Witch said - yes.

 

The same old story with IT: Centralised IT Systems so they can cut down staff, cut down expenditure which usually means something will give way. There's not often a plan B and certainly no plan C. Reminds me of education if it wasn't for all you guys who put in remote shifts and go the extra 100 miles even when given no money, no staff and no time.

 

I was watching a lot of live tweets at the time from NHS IT people and even their other half's didn't know when they would be home. Funnily enough the ones who got touchy and aggressive were the IT consultants who seemed to think this could have easily been avoided if "IT did their job". They will be the ones on high salaries and don't actually see the challenges of trying to update systems when no one will give you the time or money. How many times have we been moaned at by SLT for doing our job with security, updates and latest OS's...

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...