Live data from Hacker News

Another Ransomware Outbreak Is Going Global

forbes.com

401–410 of 435 posts

Re: Another Ransomware Outbreak Is Going Global

#401

(Sorry for the repost but I feel the pain of sysadmins so it might be useful to some people as everything melts down around them this evening)... Hey, FWIW we had to do some response for ransomware cases recently. There was a lack of decent stuff out there for how IT teams should deal with it. So we contributed to putting together this quick checklist: https://github.com/0xswap/guides/blob/master/ransomware-tria... W…

A minor nit: if you convert this over to markdown or ReStructuredText, it'll display more nicely on the page and be easier to move over to GitHub pages or the like.

Re: Another Ransomware Outbreak Is Going Global

#402

Earlier quoted context omitted.

Thanks. So to go back to these two points: > They don't need to deploy 0days if the vendor (willingly or unwillingly) cooperates. > I don't understand how that would be possible. Such a change would be detected and very loudly discussed, making it pretty useless. It would seem to me that these things are happening. 0days are being added (often to look like simple bugs) and security companies are detecting them and we…

> So you're both right, but there's a period of sometimes years following the addition of a backdoor to it being discovered. And the NSA doesn't care too much if it's found as you can be sure it's not the only one as the ShadowBrokers showed. EternalBlue was a vulnerability, not a backdoor, as a backdoor would imply it was intentionally inserted. Again, any proof of malicious code being intentionally inserted would b…

The theory is that back doors are designed to look like bugs, precisely so you can make the argument you just made - that they are not back doors.

Re: Another Ransomware Outbreak Is Going Global

#403

Earlier quoted context omitted.

If you back your files up on the usb drive on Tuesday, remove the drive after back u the files, and get infected on Wednesday, the files on the drive obviously are not going to be infected.

If you remove the drive. Lots of backups are done on to always-connected devices.

So, if my external drive was connected to the computer during encryption, will it also be encrypted?

Re: Another Ransomware Outbreak Is Going Global

#404

Earlier quoted context omitted.

It's like saying best way to fight heroin addicts is to supply market with poisoned heroin. No heroin users - no problems!

except that getting malware isn't addictive...

Your information is tho

Re: Another Ransomware Outbreak Is Going Global

#405

Maersk is down. Their main site says: Maersk IT systems are down We can confirm that Maersk IT systems are down across multiple sites and business units due to a cyber attack. We continue to assess the situation. The safety of our employees, our operations and customer's business is our top priority. We will update when we have more information.[1] Maersk is the largest shipping company in the world. 600 ships, with…

It seems fitting that the top comment on such a big congestion issue be posted by Animats :-)

Re: Another Ransomware Outbreak Is Going Global

#406
post #135

Earlier quoted context omitted.

Aide is a popular utility to monitor for changes to files on Linux systems. http://aide.sourceforge.net You could also use the built in audit subsystem if you wanted to watch a specific canary file, directory, filesysyem, etc. https://www.linux.com/learn/customized-file-monitoring-audit...

what a horrible interface aide Couldn't open file /var/lib/aide/please-dont-call-aide-without-parameters/aide.db for reading aide -i Couldn't open file /var/lib/aide/please-dont-call-aide-without-parameters/aide.db.new for writing

[deleted]

Re: Another Ransomware Outbreak Is Going Global

#407

Maersk is down. Their main site says: Maersk IT systems are down We can confirm that Maersk IT systems are down across multiple sites and business units due to a cyber attack. We continue to assess the situation. The safety of our employees, our operations and customer's business is our top priority. We will update when we have more information.[1] Maersk is the largest shipping company in the world. 600 ships, with…

The parallels with the "Daemon" in Daniel Suarez' novel are scary.

small spoiler ahead

This Daemon is an AI that keeps data of big companies hostage - it will destroy all that company's data if the company does not pay protection money, or if the company involves law enforcement.

Because a lot of companies in the novel don't stick to the AI's rules, these companies go down with the exact same symptoms as Maersk is now having:

  - unable to do business
  - unclear what happened
  - declining stock prices
https://en.wikipedia.org/wiki/Daemon_(novel_series)

Re: Another Ransomware Outbreak Is Going Global

#408

Maersk is down. Their main site says: Maersk IT systems are down We can confirm that Maersk IT systems are down across multiple sites and business units due to a cyber attack. We continue to assess the situation. The safety of our employees, our operations and customer's business is our top priority. We will update when we have more information.[1] Maersk is the largest shipping company in the world. 600 ships, with…

The parallels with the "Daemon" in Daniel Suarez' novel are scary. small spoiler ahead This Daemon is an AI that keeps data of big companies hostage - it will destroy all that company's data if the company does not pay protection money, or if the company involves law enforcement. Because a lot of companies in the novel don't stick to the AI's rules, these companies go down with the exact same symptoms as Maersk is no…

This is also a fabulously entertaining novel.

Re: Another Ransomware Outbreak Is Going Global

#409

Earlier quoted context omitted.

I sent my first packet-of-death to an unprotected Windows machine in 1996, so...

1997 here :-) hat was that XP xploit app from back then... I cant recall what it was called...

WinNT 4.0.

https://en.m.wikipedia.org/wiki/Windows_NT_4.0

Re: Another Ransomware Outbreak Is Going Global

#410
post #199

Earlier quoted context omitted.

If it gets big enough then people just hear from each other if paying unlocks the data or not. The best way to end ransomware is to get serious about security. In many cases, being attacked by a ransomware, is paying a low price compared to if it was a targeted attack. edit: Also, I imagine it gets easier after you wrote one i.e. many ransomewares come from the same author. So he could gain a reputation by signing me…

>If it gets big enough then people just hear from each other if paying unlocks the data or not. The idea would be to create "fake" ransomware that looks exactly like the real one >The best way to end ransomware is to get serious about security No matter how serious you get there always gonna be bugs, there isn't a single piece of mass distributed software in human history without bugs. That said, we should try to imp…

If forging digital signature is not that hard, then you can release some great scientific paper moving crypto decades ahead, or alternatively you can make billions.
Post reply on HN