Jump to content
EduGeek EdSec 2026 is Go! 27th Oct in Derby! Join us for a day of EdTech security focused talks, networking, and an evening social ×

Geoff

Edu Supporters
  • Posts

    13,543
  • Joined

Everything posted by Geoff

  1. I built a W2k16, SQL 2k16, SCCM 1702 VM in my dev environment for the purposes of doing a site migration off my old production W2k8 R2, SQL 2k8 SP2, SCCM 1610 install (OS / SQL not supported any more). However I can't add the distribution point role to it. It simply doesn't exist in the list of available roles. AFAIK I've not missed any dependencies.
  2. There's a Metasploit support for this exploit now. So you can test that way with Kali Linux or whatever. Here's a demo video: https://youtu.be/GyH2vcC6P-8
  3. No, it will do what the backup software tells it to do (IIRC because this is required by specs). So you need to turn it off in the backup client.
  4. If you select 'hardware compression' in the backup utility then the VTL will compress. So turn that off there. Other possibility is that you have dedupe enabled in your storage pool. You can turn that off in the VTL settings for the Storage Pool.
  5. Yes. That's possible, although not recommended.
  6. bindings / application pool / etc
  7. Very pretty, what is it written in?
  8. Switched to scan to email here. Had a vast mish mash of Kyoceras and Ricohs so I wasn't going to entertain testing them all then arguing with the leasing company.
  9. It appears to randomly barf on IPC$ unavailable, Guest account being disabled or SMB signing not being valid depending on the host involved.
  10. Can't get this to work.
  11. More fuel for the conspiracy fire. The WinXP patches Microsoft created were built in February. https://www.theregister.co.uk/2017/05/16/microsoft_stockpiling_flaws_too/
  12. switch google to korean and try again.
  13. EULA didn't download WARNING: Fail to download eula file http://xxx:8530/Content/13/33D8A4B81...DAB713E713.txt with error 0x80246003 No EULA clicky no update.
  14. Oh I get that, but I would of thought the targets would have secured SMB on their edge. It is utter madness to expose SMB to the internet.
  15. Kill switch for WeCry 3.0 ayylmaotjhsstasdfasdfasdfasdfasdfasdfasdf.com  Seems to be a bit of a taunt with the 'lmao' in there. As mentioned, working theory that this is nation state ransomware created by the DPKR.
  16. Yes the fact that we don't know the way 'patient zero' in the infected orgs got it is quite worrying. We do know that no one has seen anything in their spam traps that looks like WeCry. So we know it wasn't an email attachment clickfest like most other ransomware.
  17. They've proven everything they've said previously and it could be very likely they're telling the truth again. In which case this is the tip of the iceberg. Oh and code analysis of WeCry shows similarity to Lazarus Group code from 2015. https://blog.comae.io/wannacry-links-to-lazarus-group-dcea72c99d2d So you can assume that WeCry was written by one of Bureau 121 cells. Stituation still developing ofc.
  18. The Shadow Brokers have released a statement. https://steemit.com/shadowbrokers/@theshadowbrokers/oh-lordy-comey-wanna-cry-edition TL;DR is that more exploits will be released. Including for Win10, etc. Classified data as well.
  19. @ZeroHour The patches page makes no mention of the win2k8r2 patches.
  20. Has all the content in the update group downloaded and been distributed?
  21. I'm pleased to see WCry 2.0 is Linux compatible.
  22. Well, performance would be another reason.
  23. You can run this powershell as admin (with the AD Powershell module installed, so on a DC) and it will scan your domain and tell you what state the machines are in: https://github.com/kieranwalsh/PowerShell/blob/master/Get-WannaCryPatchState/Get-WannaCryPatchState.ps1
  24. Sorry (Powershell): Set-ItemProperty -Path "HKLM:\SYSTEM\CurrentControlSet\Services\LanmanServer\Parameters" SMB1 -Type DWORD -Value 0 -Force Set-ItemProperty -Path "HKLM:\SYSTEM\CurrentControlSet\Services\LanmanServer\Parameters" SMB2 -Type DWORD -Value 1 -Force
  25. I would disable it on your clients too. Also make sure that your clients have SMBv2 and v3 enabled too.
×
×
  • Create New...