Jump to content

Recommended Posts

Posted
Kill switch for WeCry 3.0

 

ayylmaotjhsstasdfasdfasdfasdfasdfasdfasdf.com 

 

Seems to be a bit of a taunt with the 'lmao' in there. :)

 

As mentioned, working theory that this is nation state ransomware created by the DPKR.

 

I recognise 'ayy lmao' as one o' them internet maymay's and asdf is clearly padding, but I have no idea what 'tjhsst' is. Google tells me that it's the Thomas Jefferson High School for Science and Technology in Alexandria, Virginia. Tinfoil hat time!

Posted

If any of us had to cancel or postpone maintenance because of lessons or revision sessions, that is an example of management failure.

 

Lessons and Revision sessions should be known in advance and planned around. A member of SLT (probably the business manager) should have control of teacher's access to resources, and be able to ring fence time for maintenance. This might not quite be when the Network Manager wanted, but scheduling access to resources is critical to managing them.

 

Management failure.

 

(I've had to cancel maintenance this year for exactly the above, before anyone thinks I live in an ivory tower. Improvements to management process are being implemented... we shall see what happens next time.)

 

If an NHS Trust does not treat the scheduling of IT works with the same care and attention it gives other maintenance works, it is their fault that important things don't get done.

Posted
Well yeah, probably. If they fixed it for 7/8.1/10 back in March, it makes sense that they'd make a fix for XP since they're still supporting some XP users.

 

MS have been begging people to get off SMBv1 for several years. They *know* it is wide open to attack. They probably don't want to look too hard because they'd end up having to back port to XP and put it on general release, as they did for this one.

 

I wouldn't be surprised if some of those who pay for extended support include organisations who might have seen this exploited before the NSA tools were leaked, hence the February date on the XP hotfix, a month before the 7+ Security Updates. Also interesting that Vista's final (so far) update patched it.

Posted

Given that it seems that its primary method for spreading was SMBv1 it requires local LAN access, so spreading was limited to broadcast domains, and then to devices that moved between broadcast domains, the physical spread of humans and their VPNs.

 

From what I have read in the mainstream tech media, no evidence of website/mail distribution has been seen. If they'd managed to get an initial delivery mechanism via the web that could dodge traditional AV it would probably have hit a greater number of users.

 

It was only spreading for a few hours before the kill switch was activated. It could have been much worse.

Posted (edited)
MS have been begging people to get off SMBv1 for several years. They *know* it is wide open to attack. They probably don't want to look too hard because they'd end up having to back port to XP and put it on general release, as they did for this one.

 

I wouldn't be surprised if some of those who pay for extended support include organisations who might have seen this exploited before the NSA tools were leaked, hence the February date on the XP hotfix, a month before the 7+ Security Updates. Also interesting that Vista's final (so far) update patched it.

 

In mitigation, they know that it has issues however, there are still customers out there running legacy hardware/systems which may rely on it.

Lets face it, there is more than one post on here where people are running legacy OS's to support expensive CNC and other machines in their schools.

They have been warning customers for quite some time, but I suppose there is a division between having to run it and deciding wether to remove/disable it by the end users. And who here was still running it when they didn't have to even though they knew there were issues?

It's been a lesson learnt by everyone this past few days.

And it will happen again down the line with some other hole being found and exploited.

Edited by Dos_Box
Posted (edited)
From what I have read in the mainstream tech media, no evidence of website/mail distribution has been seen.

 

So how did it begin, then? Do we have any solid indication of how 'patient zero' was initially infected?

 

Lets face it, there is more than one post on here where people are running legacy OS's to support expensive CNC and other machines in their schools.

Is true. Our laser cutter/engraver is powered by an XP laptop. But because we're unable to adequately secure it, it's airgapped.

Edited by Garacesh
Posted
Can't get this to work.

Unfortunately I'm not an expert on nmap - it worked for me when scanning clients. (It didn't work for my servers, but I know they're all up-to-date - there was a message about not being able to access IPC or some such).

Sorry.

Posted
Unfortunately I'm not an expert on nmap - it worked for me when scanning clients. (It didn't work for my servers, but I know they're all up-to-date - there was a message about not being able to access IPC or some such).

Sorry.

 

It appears to randomly barf on IPC$ unavailable, Guest account being disabled or SMB signing not being valid depending on the host involved.

Posted
Windows XP POS 2009 is still supported so might well have been.

And you can still pay for support for XP at escalating rates each year I believe which according to the article the NHS stopped paying for after year 1 to save money.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...