Live data from Hacker News

Dutch university hit by cyber attack on its Windows systems

maastrichtuniversity.nl

31–37 of 37 posts

Re: Dutch university hit by cyber attack on its Windows systems

#32
post #12

Earlier quoted context omitted.

> chances are very high that some university administrator probably downloaded a shady program from a porn site. Nah, in reality someone probably clicked a link in a malicious email that launched a backdoor on their computer. The likelihood of that approaches 100% on untrained users. And, as this is a university environment, that user likely had local admin. You only need 1 successful click to breach the good ol' "se…

>Nah, in reality someone probably clicked a link in a malicious email that launched a backdoor on their computer. The likelihood of that approaches 100% on untrained users. In 2019 this is actually very unlikely. Driveby exploits have been pretty rare for years now.

exploit office docs are less rare

Re: Dutch university hit by cyber attack on its Windows systems

#33
Interesting to read, the University in Gießen (Germany) is down for weeks with similar issues. https://www.uni-giessen.de/index.html (engl. Version below). They use Instagram and Facebook to organize 38.000 people and distribute passwords offline https://www.instagram.com/jlu.giessen/?hl=en

- https://www.denbi.de/news/763-shut-down-of-de-nbi-services-h... - https://www.instagram.com/jlu.giessen/?hl=en

Re: Dutch university hit by cyber attack on its Windows systems

#34
post #12

Earlier quoted context omitted.

>Nah, in reality someone probably clicked a link in a malicious email that launched a backdoor on their computer. The likelihood of that approaches 100% on untrained users. In 2019 this is actually very unlikely. Driveby exploits have been pretty rare for years now.

It's still one of the top methods. See for example Symantec's report [1] with lots of data. [1] https://www.symantec.com/content/dam/symantec/docs/reports/i...

I'm sorry, I can't seem to find any references to driveby exploits in that report. I see many mentions of malicious office documents with downloader macros and similar attacks that certainly happen regularly today.

I do not see any mentions of attacks fitting the driveby pattern you described earlier. I am aware such targetted attacks do exists, but they're extremely rare these days compared to a few years back.

Almost all attacks today rely on social engineering to trick the victim into handing out their credentials or opening a malicious file, not a link.

Re: Dutch university hit by cyber attack on its Windows systems

#35

Earlier quoted context omitted.

It's still one of the top methods. See for example Symantec's report [1] with lots of data. [1] https://www.symantec.com/content/dam/symantec/docs/reports/i...

I literally just got a call about someone being hit. The avenues used to penetrate are email spam and RDP.

When was the last time you saw email spam linking to a browser driveby exploit?

Re: Dutch university hit by cyber attack on its Windows systems

#36
post #32
post #12

Earlier quoted context omitted.

>Nah, in reality someone probably clicked a link in a malicious email that launched a backdoor on their computer. The likelihood of that approaches 100% on untrained users. In 2019 this is actually very unlikely. Driveby exploits have been pretty rare for years now.

exploit office docs are less rare

They're less rare because they've almost completely replaced the attacks I described as "very unlikely".

In 2019 it's extremely rare that anyone gets owned just by clicking a link, we've moved very far from that.

Re: Dutch university hit by cyber attack on its Windows systems

#37

Are there any documented reports of Linux/Unix systems ever being hit by ransomware? Or files on NAS appliances (NetApp, Isilon, etc) being encrypted in a way that is unrecoverable (especially since snapshots can be scheduled regularly)? Certainly you can steal data from non-Windows systems, so exfiltration attacks are similar on both, but AFAICT, these "we've got your data" style attacks are unique to Windows. If an…

Linux systems are less targeted because they're less commonly used, their userbase on average knows more about technology and they're inherently more secure.

>inherently more secure

What now?

Post reply on HN