I'm afraid that this attack demonstrates that the old PC architecture: Side-loading any app, userspace, privilege escalation, low level file sharing functionality just isn't for purpose. If malware can exploit a 0-day, 100-day, 1000-day security hole in a corporate network of 2000 machines, its too easy for that malware to share itself across the network and send emails attachments to AllUsers (every single company I…
Another Ransomware Outbreak Is Going Global
161–170 of 435 posts
Re: Another Ransomware Outbreak Is Going Global
#162Re: Another Ransomware Outbreak Is Going Global
#163As someone affected by the ransomware - did anyone else notice empty console windows popping up from time to time the days before the ransomware triggered the encryption?
Re: Another Ransomware Outbreak Is Going Global
#164Can someone provide a simple (but not overly so) explanation of how the current generation of ransomware operate i.e., A) spread and B) lock up the computer? Does it always require human intervention for A. ? Thank you.
Depends on The ransomware. Usually if it says "0-Day" assume that it can be exploited without human intervention a-la stuxnet
Re: Another Ransomware Outbreak Is Going Global
#165FYI to Sysadmins: Paying the ransom at this point will be a waste of money, as the contact e-mail address has been blocked. https://posteo.de/blog/info-zur-ransomware-petrwrappetya-bet... (German) https://posteo.de/en/blog/info-on-the-petrwrappetya-ransomwa... (English)
All the competent ransomware authors are probably quite unhappy whenever a defective ransomware strain pops up.
Re: Another Ransomware Outbreak Is Going Global
#166Earlier quoted context omitted.
Probably via their smart phones
So a smartphone is not a computer anymore? The world we live in..
In this context "computer" means "desktop computer" or "laptop computer".
Re: Another Ransomware Outbreak Is Going Global
#167Earlier quoted context omitted.
There is no proof of means or motivation to use 0-days at scale. In fact, using EternalBlue "at-scale" would have caused it to not stay a 0-day for very long.
That's not true. When an exploit shows up on a computer, "How did it get there?" is often the hardest question. There's no way to know short of capturing it in a lab environment. If you're talking about "at scale" being "the entire world," then yes. But usually the NSA tends to target their operations regionally, e.g. Iran.
Re: Another Ransomware Outbreak Is Going Global
#168Maybe this is the year of Linux on desktop.
Re: Another Ransomware Outbreak Is Going Global
#169Earlier quoted context omitted.
Yeah, and the Department of Defense is capable of nuking major cities. And it's about as relevant to this discussion.
It's relevant because it's like the nukes were stolen and that it will continue to happen
Re: Another Ransomware Outbreak Is Going Global
#170FYI to Sysadmins: Paying the ransom at this point will be a waste of money, as the contact e-mail address has been blocked. https://posteo.de/blog/info-zur-ransomware-petrwrappetya-bet... (German) https://posteo.de/en/blog/info-on-the-petrwrappetya-ransomwa... (English)