Arthur Posted May 22, 2017 Posted May 22, 2017 (edited) What's unclear is why many websites claim that Windows 10 wasn't targeted, yet Microsoft did release a patch in March 2017 for it also. If you look in the Eternalblue-2.2.0.0.xml file in the Shadow Broker's GitHub repo and you'll see that Windows 10 isn't listed. https://github.com/misterch0c/shadowbroker/blob/master/windows/specials/Eternalblue-2.2.0.0.xml Also: https://twitter.com/hackerfantastic/status/852999174631170048 Edited May 22, 2017 by Arthur
Arthur Posted May 25, 2017 Posted May 25, 2017 (edited) https://arstechnica.com/security/2017/05/a-wormable-code-execution-bug-has-lurked-in-samba-for-7-years-patch-now/ Maintainers of the Samba networking utility just patched a critical code-execution vulnerability that could pose a severe threat to users until the fix is widely installed. The seven-year-old flaw, indexed as CVE-2017-7494, can be reliably exploited with just one line of code to execute malicious code, as long as a few conditions are met. Those requirements include vulnerable computers that (a) make file- and printer-sharing port 445 reachable on the Internet, (b) configure shared files to have write privileges, and © use known or guessable server paths for those files. When those conditions are satisfied, remote attackers can upload any code of their choosing and cause the server to execute it, possibly with unfettered root privileges, depending on the vulnerable platform. "All versions of Samba from 3.5.0 onwards are vulnerable to a remote code execution vulnerability, allowing a malicious client to upload a shared library to a writable share, and then cause the server to load and execute it," Samba maintainers wrote in an advisory published Wednesday. They urged anyone using a vulnerable version to install a patch as soon as possible. Edited May 25, 2017 by Arthur 1
Arthur Posted May 30, 2017 Posted May 30, 2017 Alert: Microsoft Tech-Support Scammers using WannaCry attack to lure victims Action Fraud has received the first reports of Tech-Support scammers claiming to be from Microsoft who are taking advantage of the global WannaCry ransomware attack. One victim fell for the scam after calling a ‘help’ number advertised on a pop up window. The window which wouldn’t close said the victim had been affected by WannaCry Ransomware. The victim granted the fraudsters remote access to their PC after being convinced there wasn’t sufficient anti-virus protection. The fraudsters then installed Windows Malicious Software Removal Tool, which is actually free and took £320 as payment.
Matt_Renato Posted May 31, 2017 Posted May 31, 2017 Apparently the latest 1703 is immune, but I'm not sure if that's true either!? That's correct, if you are running the Creators Update (1703) it comes with the required updated files. Anniversary Update (1607) needs to be at least build 14393.953 Fall Update (1511) needs to be at least build 10586.839 RTM (1507) needs to be at least build 10240.17319
Arthur Posted June 13, 2017 Posted June 13, 2017 The BBC made a Horizon programme about WannaCry and the NHS. It's now on iPlayer. www.bbc.co.uk/iplayer/episode/b08vfzm0/horizon-2017-cyber-attack-the-day-the-nhs-stopped A few weeks ago, the National Health Service was hit by a widespread and devastating cyber attack - Horizon tells the inside story of one of the most challenging days in the history of the NHS. On the morning of 12 May the attack started. Appointment systems, pathology labs, x-rays and even CT scanners were infected - putting not just data but patients lives at risk, and on every screen a simple - some may even say polite - message appeared. 'Ooops, your files have been encrypted!' But what followed was far from civilised. It was very clear that all the data on an infected machine was now scrambled and only the hackers could unscramble it. For a price - and with an extra twist - after a few days the ransom money doubled, and if nothing was paid within a week, the hackers threatened to destroy all the data - forever. 1
jmak Posted June 14, 2017 Posted June 14, 2017 I thought this was a good watch and quite interesting (well, everyone reading this is a self declared geek!) and informative about the story behind the virus and people trying to deal with it, even if you've been staying on top of information about fixing it from a technical point of view. My wife didn't leave the room while I watched it....
JJonas Posted June 14, 2017 Posted June 14, 2017 It was a good watch but the person at the BBC in charge of program schedule's is clearly not a geek because they put it on at the same time as Ubisofts E3 show. 1
admars Posted June 14, 2017 Posted June 14, 2017 looks like more XP patches available.... Microsoft warns of 'destructive cyberattacks,' issues new Windows XP patches | ZDNet
Simcfc73 Posted June 14, 2017 Posted June 14, 2017 The kettle IOS device with the network password hack was interesting.
ollyyllo Posted June 14, 2017 Posted June 14, 2017 (edited) I caught about 5 mins of the program. Did they say that the nhs's n3 network wasn't affected, just unpatched pc's? Why did it affect multiple NHS organisations then, how were they targeted? Edited June 14, 2017 by ollyyllo
Metallet Posted June 16, 2017 Posted June 16, 2017 Kaspersky Lab security researchers have found that critical errors in WannaCry code can help to recover some of the encrypted files for free: https://securelist.com/wannacry-mistakes-that-can-help-you-restore-files-after-infection/78609/ https://malwareless.com/wannacry-code-critical-errors-can-help-recover-locked-files/ 1
themightymrp Posted June 16, 2017 Posted June 16, 2017 It is a Netgear ReadyNAS NV+ Not a major appliance by any standards, just a simple backup device. But looks like I need SMB1 to access it :-/ Thought I'd mention, Netgear released an updated firmware today for this older NAS which patches the samba system So I should be able to switch off SMBv1 now and still access the NAS! 1
3s-gtech Posted June 16, 2017 Posted June 16, 2017 (edited) Thought I'd mention, Netgear released an updated firmware today for this older NAS which patches the samba system So I should be able to switch off SMBv1 now and still access the NAS! Just checked, and they've also released an update for my lovely ReadyNAS Pro 2 which seems to focus on the same thing. Will see if it works - would be nice to access it again via SMB (it only works via NFS now). Edit: it's alive! Won't join AD any more, but that's not an issue in this role. Edited June 16, 2017 by 3s-gtech
Popular Post GuyJD Posted June 19, 2017 Popular Post Posted June 19, 2017 (edited) Well on Friday afternoon I had a real world test of our network security, and I'm happy to say it passed with flying colours. A teacher came in to me at about 4pm saying she couldn't copy her reports to her memory stick at first I thought it was just another dead memory stick but when I put it in my PC Sophos went crazy, turns out it was infected with Cryptoguard malware, Sophos Central dealt with it before I even knew what was going on and it initiated a scan on hers and my computer and killed it dead before it could do any damage. I only just upgraded to Sophos Central with Intercept X at the end of last term and I'm so glad I did because I'm fairly confident the standard Sophos enterprise endpoint protection would not have dealt with it quite so well. There was me thinking I'd be working late on a Friday but Sophos stepped up and was like "Chill bruv, I got this!" Edited June 19, 2017 by GuyJD 9
forkies Posted June 19, 2017 Posted June 19, 2017 Well on Friday afternoon I had a real world test of our network security, and I'm happy to say it passed with flying colours. A teacher came in to me at about 4pm saying she couldn't copy her reports to her memory stick at first I thought it was just another dead memory stick but when I put it in my PC Sophos went crazy, turns out it was infected with Cryptoguard malware, Sophos Central dealt with it before I even knew what was going on and it initiated a scan on hers and my computer and killed it dead before it could do any damage. I only just upgraded to Sophos Central with Intercept X at the end of last term and I'm so glad I did because I'm fairly confident the standard Sophos enterprise endpoint protection would not have dealt with it quite so well. There was me thinking I'd be working late on a Friday but Sophos stepped up and was like "Chill bruv, I got this!" This is why I don't plug users USB sticks into my pc. Glad your software dealt with it though.
mikkydoos Posted June 20, 2017 Posted June 20, 2017 This is why I don't plug users USB sticks into my pc. Glad your software dealt with it though. And this is why we don't allow USB sticks at all. +1 for your AV tho'
Arthur Posted June 21, 2017 Posted June 21, 2017 Honda plant in Japan briefly stops making cars after fresh WannaCrypt outbreak Honda said today that it had briefly halted operations at a car plant in Sayama, Japan earlier this week because of the infamous WannaCrypt ransomware. The Japanese car maker halted production for one day at a domestic vehicle plant on Monday after finding samples of the WannaCrypt ransomware in its computer network, Reuters reports. The Renault-Nissan alliance had similar problems at five of their jointly operated plants in the immediate aftermath of the original WannaCrypt outbreak last month. Problems at another carmaker's plant are only surprising because of the timing – weeks after the original outbreak. Hours after the original highly virulent WannaCrypt outbreak, security researcher Marcus Hutchins registered a domain found in the code that acted as a kill-switch and stopped the original ransomware spreading any further. It could be that Honda has blocked access to this domain internally, some experts have speculated. It's not immediately clear if the original WannaCrypt, which hobbled systems at multiple NHS trusts and numerous enterprises worldwide last month, or one of many subsequent variants lies behind Honda's problem. Security experts said that as long as the underlying fault remains unresolved, then WannaCrypt variants will remain an issue.
sippo Posted June 22, 2017 Posted June 22, 2017 The NHS IT department in my wife's hospital are absolutely shocking. They are trying to move her to an @nhs.net address and are really struggling. Is it due to lack of investment in IT?
witch Posted June 22, 2017 Posted June 22, 2017 The NHS IT department in my wife's hospital are absolutely shocking. They are trying to move her to an @nhs.net address and are really struggling. Is it due to lack of investment in IT? Yes. My brother-in-law has been working in the local hospital IT since he lost his job at Marconi when it folded some years ago. He was quite high up and has knowledge of infrastructure etc and he is horrified by the situation he is now in. No money, little or no expertise, and permanently blocked by people not allowing things to be done - such as consultants never bringing laptops in for updates etc.
LeMarchand Posted June 22, 2017 Posted June 22, 2017 permanently blocked by people not allowing things to be done - such as consultants never bringing laptops in for updates etc. They are very busy and important people, you know. Those golf rounds don't just play themselves!
Lonix Posted June 22, 2017 Posted June 22, 2017 The NHS IT department in my wife's hospital are absolutely shocking. They are trying to move her to an @nhs.net address and are really struggling. Is it due to lack of investment in IT? As Witch said - yes. The same old story with IT: Centralised IT Systems so they can cut down staff, cut down expenditure which usually means something will give way. There's not often a plan B and certainly no plan C. Reminds me of education if it wasn't for all you guys who put in remote shifts and go the extra 100 miles even when given no money, no staff and no time. I was watching a lot of live tweets at the time from NHS IT people and even their other half's didn't know when they would be home. Funnily enough the ones who got touchy and aggressive were the IT consultants who seemed to think this could have easily been avoided if "IT did their job". They will be the ones on high salaries and don't actually see the challenges of trying to update systems when no one will give you the time or money. How many times have we been moaned at by SLT for doing our job with security, updates and latest OS's...
ollyyllo Posted June 23, 2017 Posted June 23, 2017 Microsoft will be removing SMBv1 from Windows 10. Insider Build 16226 - SMB1 server removed from Home and Pro, SMB1 server and client removed from Enterprise and Education. https://www.theregister.co.uk/2017/06/22/latest_windows_10_build_kills_exploited_smb1/
jonspurs Posted June 27, 2017 Posted June 27, 2017 Not again... http://www.edugeek.net/forums/news/185854-many-firms-hit-global-cyber-attacks-bbc-news.html
TechMonkey Posted June 27, 2017 Posted June 27, 2017 Not again... http://www.edugeek.net/forums/news/185854-many-firms-hit-global-cyber-attacks-bbc-news.html Seperate thread 1
googlemad Posted June 27, 2017 Posted June 27, 2017 This made me laugh the other day, never thought I would have to wait for a disk check to complete before seeing when my bus was due! 4
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now