<div dir="ltr">In addition since many of the softwares being used are available in totally open source versions should governments not be making use of these to developed customised solutions that will reduce their vulnerability to these kind of blanket attacks.<div>best</div></div><div class="gmail_extra"><br><div class="gmail_quote">On Sat, May 13, 2017 at 9:22 AM, Niel Harper <span dir="ltr"><<a href="mailto:niel.harper@ieee.org" target="_blank">niel.harper@ieee.org</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex"><div dir="ltr"><div class="gmail_default"><div class="m_5061995990313916859gmail-" style="font-family:"san francisco",-apple-system,system-ui,".sfnstext-regular",sans-serif;color:rgb(29,33,41);font-size:14px;letter-spacing:-0.27027px;white-space:pre-wrap"><div class="m_5061995990313916859gmail-_1mf m_5061995990313916859gmail-_1mj" style="direction:ltr;font-family:inherit"><span style="font-family:inherit">Hello Wisdom,</span></div></div><div class="m_5061995990313916859gmail-" style="font-family:"san francisco",-apple-system,system-ui,".sfnstext-regular",sans-serif;color:rgb(29,33,41);font-size:14px;letter-spacing:-0.27027px;white-space:pre-wrap"><div class="m_5061995990313916859gmail-_1mf m_5061995990313916859gmail-_1mj" style="direction:ltr;font-family:inherit"><span style="font-family:inherit"><br></span></div></div><div class="m_5061995990313916859gmail-" style="font-family:"san francisco",-apple-system,system-ui,".sfnstext-regular",sans-serif;color:rgb(29,33,41);font-size:14px;letter-spacing:-0.27027px;white-space:pre-wrap"><div class="m_5061995990313916859gmail-_1mf m_5061995990313916859gmail-_1mj" style="direction:ltr;font-family:inherit"><span style="font-family:inherit">I want to play the devil's advocate here for a minute.</span></div></div><div class="m_5061995990313916859gmail-" style="font-family:"san francisco",-apple-system,system-ui,".sfnstext-regular",sans-serif;color:rgb(29,33,41);font-size:14px;letter-spacing:-0.27027px;white-space:pre-wrap"><div class="m_5061995990313916859gmail-_1mf m_5061995990313916859gmail-_1mj" style="direction:ltr;font-family:inherit"><span style="font-family:inherit"><br></span></div></div><div class="m_5061995990313916859gmail-" style="font-family:"san francisco",-apple-system,system-ui,".sfnstext-regular",sans-serif;color:rgb(29,33,41);font-size:14px;letter-spacing:-0.27027px;white-space:pre-wrap"><div class="m_5061995990313916859gmail-_1mf m_5061995990313916859gmail-_1mj" style="direction:ltr;font-family:inherit"><span style="font-family:inherit">Ransomware has been a major problem since the mid-2000s. There was an over 150% increase in new ransomware variants in the first half of 2016 alone. Moreover, cybercriminals are now operating Ransomware-as-a-Service (RaaS) with lower buy-in costs that allow less tech-savvy perpetrators to distribute ransomware. News reports would seem to suggest that yesterday's attack was outside the norm, when it really wasn't.</span></div></div><div class="m_5061995990313916859gmail-" style="font-family:"san francisco",-apple-system,system-ui,".sfnstext-regular",sans-serif;color:rgb(29,33,41);font-size:14px;letter-spacing:-0.27027px;white-space:pre-wrap"><div class="m_5061995990313916859gmail-_1mf m_5061995990313916859gmail-_1mj" style="direction:ltr;font-family:inherit"><span style="font-family:inherit"><br></span></div></div><div class="m_5061995990313916859gmail-" style="font-family:"san francisco",-apple-system,system-ui,".sfnstext-regular",sans-serif;color:rgb(29,33,41);font-size:14px;letter-spacing:-0.27027px;white-space:pre-wrap"><div class="m_5061995990313916859gmail-_1mf m_5061995990313916859gmail-_1mj" style="direction:ltr;font-family:inherit"><span style="font-family:inherit">While providing information on this particular attack is all well and good, shouldn't we be talking about why governments should not be building up their cyber attack capabilities, and why things like stockpiling zero day vulnerabilities is a really bad idea and compromises the security of the Internet (also eroding online trust)?</span></div></div><div class="m_5061995990313916859gmail-" style="font-family:"san francisco",-apple-system,system-ui,".sfnstext-regular",sans-serif;color:rgb(29,33,41);font-size:14px;letter-spacing:-0.27027px;white-space:pre-wrap"><div class="m_5061995990313916859gmail-_1mf m_5061995990313916859gmail-_1mj" style="direction:ltr;font-family:inherit"><span style="font-family:inherit"><br></span></div></div><div class="m_5061995990313916859gmail-" style="font-family:"san francisco",-apple-system,system-ui,".sfnstext-regular",sans-serif;color:rgb(29,33,41);font-size:14px;letter-spacing:-0.27027px;white-space:pre-wrap"><div class="m_5061995990313916859gmail-_1mf m_5061995990313916859gmail-_1mj" style="direction:ltr;font-family:inherit"><span style="font-family:inherit">Additionally, shouldn't the discourse include guidelines about protecting individuals and organizations from malware attack (again not criticizing the efficacy and importance of incident response)? </span></div></div><div class="m_5061995990313916859gmail-" style="font-family:"san francisco",-apple-system,system-ui,".sfnstext-regular",sans-serif;color:rgb(29,33,41);font-size:14px;letter-spacing:-0.27027px;white-space:pre-wrap"><div class="m_5061995990313916859gmail-_1mf m_5061995990313916859gmail-_1mj" style="direction:ltr;font-family:inherit"><span style="font-family:inherit"><br></span></div></div><div class="m_5061995990313916859gmail-" style="font-family:"san francisco",-apple-system,system-ui,".sfnstext-regular",sans-serif;color:rgb(29,33,41);font-size:14px;letter-spacing:-0.27027px;white-space:pre-wrap"><div class="m_5061995990313916859gmail-_1mf m_5061995990313916859gmail-_1mj" style="direction:ltr;font-family:inherit"><span style="font-family:inherit">Sadly enough, hospitals are usually low hanging fruit for ransomware attacks. Their data sets are critical to patient care and management, and they usually don’t have the IT resources to support critical process areas like vulnerability management, patch management, business continuity management, etc. They also generally don’t have robust backup solutions and/or real-time replication to disaster recovery sites which increases the overall availability of mission critical data for recovery. And from a risk management perspective, they don’t possess the depth of human resources to employ a ‘three lines of defense’ approach to managing organizational risk. 

A robust data backup and recovery solution usually goes a long way in protect oneself from ransomware attacks. My preferred approach for organizations is usually a disk-to-disk-to-tape backup solution combined with offsite replication if possible. The backup tapes are encrypted and stored off site. For individuals, backing up critical data is also very important. But end users need to also regularly update their endpoint security, be wary of phishing and other suspicious emails, and also be mindful the rootkits can be downloaded from legitimate websites that have been compromised.</span></div><div class="m_5061995990313916859gmail-_1mf m_5061995990313916859gmail-_1mj" style="direction:ltr;font-family:inherit"><span style="font-family:inherit"><br></span></div><div class="m_5061995990313916859gmail-_1mf m_5061995990313916859gmail-_1mj" style="font-family:inherit"><span style="font-family:inherit">Regards,</span></div><div class="m_5061995990313916859gmail-_1mf m_5061995990313916859gmail-_1mj" style="font-family:inherit"><span style="font-family:inherit"><br></span></div><div class="m_5061995990313916859gmail-_1mf m_5061995990313916859gmail-_1mj" style="font-family:inherit"><span style="font-family:inherit">Niel</span></div></div></div></div><div class="gmail_extra"><div><div class="h5"><br><div class="gmail_quote">On Sat, May 13, 2017 at 6:10 AM, Wisdom Donkor <span dir="ltr"><<a href="mailto:wisdom.dk@gmail.com" target="_blank">wisdom.dk@gmail.com</a>></span> wrote:<br><blockquote class="gmail_quote" style="margin:0 0 0 .8ex;border-left:1px #ccc solid;padding-left:1ex">Dear Colleagues,<br style="font-family:sans-serif;font-size:medium"><br>Thought of sharing this information.<div><span style="font-size:15px"><br></span><span style="font-family:sans-serif;font-size:medium">Yesterday, May 12, at about 5:00 pm GMT, a massive ransomware hit </span><br style="font-family:sans-serif;font-size:medium"><span style="font-family:sans-serif;font-size:medium">computer systems of hundreds of private companies and public </span><span style="font-family:sans-serif;font-size:medium">organizations across the world which is believed to have the highest </span><span style="font-family:sans-serif;font-size:medium">infection rate of all time.</span><br style="font-family:sans-serif;font-size:medium"><span style="font-family:sans-serif;font-size:medium">The Ransomware in question has been identified as a variant of </span><br style="font-family:sans-serif;font-size:medium"><span style="font-family:sans-serif;font-size:medium">ransomware known as WannaCry (also known as 'Wana Decrypt0r,' </span><span style="font-family:sans-serif;font-size:medium">'WannaCryptor' or 'WCRY').</span><div><br style="font-family:sans-serif;font-size:medium"><span style="font-family:sans-serif;font-size:medium">Like other dangerous ransomware variants, WannaCry also blocks access to </span><br style="font-family:sans-serif;font-size:medium"><span style="font-family:sans-serif;font-size:medium">a computer or its files and demands money to unlock it.</span><br style="font-family:sans-serif;font-size:medium"><br style="font-family:sans-serif;font-size:medium"><span style="font-family:sans-serif;font-size:medium">Once infected with the WannaCry ransomware, victims are asked to pay up </span><br style="font-family:sans-serif;font-size:medium"><span style="font-family:sans-serif;font-size:medium">to $300 in order to remove the infection from their PCs; otherwise, </span><br style="font-family:sans-serif;font-size:medium"><span style="font-family:sans-serif;font-size:medium">their PCs render unusable, and their files remain locked.</span><br style="font-family:sans-serif;font-size:medium"><br style="font-family:sans-serif;font-size:medium"><span style="font-family:sans-serif;font-size:medium">WannaCry attackers use a Windows exploit detected and tested by the NSA </span><br style="font-family:sans-serif;font-size:medium"><span style="font-family:sans-serif;font-size:medium">called EternalBlue, which was stolen and released by the Shadow Brokers </span><br style="font-family:sans-serif;font-size:medium"><span style="font-family:sans-serif;font-size:medium">hacking group over a month ago.</span><br style="font-family:sans-serif;font-size:medium"><br style="font-family:sans-serif;font-size:medium"><span style="font-family:sans-serif;font-size:medium">Microsoft released a patch for the vulnerability in March (MS17-010), </span><br style="font-family:sans-serif;font-size:medium"><span style="font-family:sans-serif;font-size:medium">but many users and organizations who did not patch their systems are </span><span style="font-family:sans-serif;font-size:medium">open to attacks.</span><br style="font-family:sans-serif;font-size:medium"><br style="font-family:sans-serif;font-size:medium"><span style="font-family:sans-serif;font-size:medium">The exploit has the capability to penetrate into machines running </span><span style="font-family:sans-serif;font-size:medium">unpatched version of Windows by exploiting flaws in Microsoft Windows </span><span style="font-family:sans-serif;font-size:medium">SMB Server. This is why the WannaCry ransomware is spreading at an </span><span style="font-family:sans-serif;font-size:medium">astonishing pace.</span><br style="font-family:sans-serif;font-size:medium"><span style="font-family:sans-serif;font-size:medium">Once a single computer in your organization is hit by the WannaCry </span><br style="font-family:sans-serif;font-size:medium"><span style="font-family:sans-serif;font-size:medium">ransomware, the worm looks for other vulnerable computers and infects </span><br style="font-family:sans-serif;font-size:medium"><span style="font-family:sans-serif;font-size:medium">them as well.</span><br style="font-family:sans-serif;font-size:medium"><br style="font-family:sans-serif;font-size:medium"><span style="font-family:sans-serif;font-size:medium">In just a few hours, the ransomware targeted over 45,000 computers in 74 </span><br style="font-family:sans-serif;font-size:medium"><span style="font-family:sans-serif;font-size:medium">countries, including United States, Russia, Germany, Turkey, Italy, </span><span style="font-family:sans-serif;font-size:medium">Philippines and Vietnam, and that the number was still growing.</span><br style="font-family:sans-serif;font-size:medium"><br style="font-family:sans-serif;font-size:medium"><span style="font-family:sans-serif;font-size:medium">A screenshot of detailing nations attacked are attached in this email.</span><br style="font-family:sans-serif;font-size:medium"><br style="font-family:sans-serif;font-size:medium"><span style="font-family:sans-serif;font-size:medium">The ransomeware's actual mode by which it initiates and spreads itself </span><span style="font-family:sans-serif;font-size:medium">on networks has not been discovered but like other ransomware variant, </span><span style="font-family:sans-serif;font-size:medium">malicious links and emails are most likely the culprit.</span><br style="font-family:sans-serif;font-size:medium"><br style="font-family:sans-serif;font-size:medium"><span style="font-family:sans-serif;font-size:medium">CERT-GH recommends users and system admins:</span><br style="font-family:sans-serif;font-size:medium"><br style="font-family:sans-serif;font-size:medium"><span style="font-family:sans-serif;font-size:medium">1. Take all windows OS systems off the internet and off the network.</span><br style="font-family:sans-serif;font-size:medium"><span style="font-family:sans-serif;font-size:medium">2. Create a backup of all files needed.</span><br style="font-family:sans-serif;font-size:medium"><span style="font-family:sans-serif;font-size:medium">3. Store backup in an airgapped location.</span><br style="font-family:sans-serif;font-size:medium"><span style="font-family:sans-serif;font-size:medium">4. Download windows update(KB4019472) in a sandbox environment.</span><br style="font-family:sans-serif;font-size:medium"><span style="font-family:sans-serif;font-size:medium">5. Install the update without connecting to a network/internet.</span><br style="font-family:sans-serif;font-size:medium"><span style="font-family:sans-serif;font-size:medium">6. After the update, the system can be connected to the internet.</span><br style="font-family:sans-serif;font-size:medium"><br style="font-family:sans-serif;font-size:medium"><span style="font-family:sans-serif;font-size:medium">Kind Regards</span><br style="font-family:sans-serif;font-size:medium"><br style="font-family:sans-serif;font-size:medium"><br style="font-family:sans-serif;font-size:medium"><span style="font-family:sans-serif;font-size:medium">CERT-GHANA</span></div></div><span class="m_5061995990313916859HOEnZb"><font color="#888888"><br><br>-- <br><div dir="ltr"><div><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div dir="ltr"><div><div style="font-size:small"><b>WISDOM DONKOR (S/N Eng.)</b><br></div><div style="font-size:small">E-government and Open Government Data Platforms Specialist<b><br></b></div><div style="font-size:small">ICANN Fellow / Member, UN IGF MAG Member, ISOC Member,<br></div><div style="font-size:small">Freedom Online Coalition (FOC) Member, Diplo Foundation Member,</div><div style="font-size:small">OGP Open Data WG Member, GODAN Memember, ITAG Member<br></div></div><div><div style="font-size:small"><div>Email: <a href="mailto:wisdom.dk@gmail.com" style="color:rgb(17,85,204)" target="_blank">wisdom.dk@gmail.com</a></div><div>Skype: wisdom_dk</div><div>facebook: facebook@wisdom_dk<br></div><div>Website: <a href="http://www.data.gov.gh/" style="color:rgb(17,85,204)" target="_blank">www.data.gov.gh</a><br></div><div><a href="http://www.isoc.gh/" style="color:rgb(17,85,204)" target="_blank">www.isoc.gh</a> / <a href="http://www.itag.org.gh/" style="color:rgb(17,85,204)" target="_blank">www.itag.org.gh</a></div></div></div></div></div></div></div></div></div></div></div><br>
</font></span></blockquote></div><br><br clear="all"><div><br></div></div></div><span class="HOEnZb"><font color="#888888">-- <br><div class="m_5061995990313916859gmail_signature" data-smartmail="gmail_signature"><div dir="ltr"><b>Niel Harper</b><br><div>Barbados: +<a href="tel:(246)%20424-3809" value="+12464243809" target="_blank">(246) 424 3809</a><br></div><div>London: <a href="tel:+44%2020%207193%209826" value="+442071939826" target="_blank">+44 207 193 9826</a><br></div><div>Mobile: +<a href="tel:(246)%20243-3818" value="+12462433818" target="_blank">(246) 243 3818</a><br>Email: <a href="mailto:niel.harper@ieee.org" style="color:rgb(17,85,204)" target="_blank">niel.harper@ieee.org</a></div><div>Website: <a href="http://nielharper.com/" target="_blank">http://nielharper.com</a></div></div></div>
</font></span></div>
</blockquote></div><br></div>