RANSOMEWARE HIT COMPUTER SYSTEMS
James Gannon
james at CYBERINVASION.NET
Sat May 13 08:38:45 EEST 2017
This is great in theory but is impossible once you move out of small and medium sized enterprises.
And also FOSS software can be just as if not more vulnerable in many ways (Security remediations timelines, patch support etc)
-J
From: NCSG-Discuss <NCSG-DISCUSS at LISTSERV.SYR.EDU<mailto:NCSG-DISCUSS at LISTSERV.SYR.EDU>> on behalf of dorothy g <dgdorothydg at GMAIL.COM<mailto:dgdorothydg at GMAIL.COM>>
Reply-To: dorothy g <dgdorothydg at GMAIL.COM<mailto:dgdorothydg at GMAIL.COM>>
Date: Saturday 13 May 2017 at 15:21
To: "NCSG-DISCUSS at LISTSERV.SYR.EDU<mailto:NCSG-DISCUSS at LISTSERV.SYR.EDU>" <NCSG-DISCUSS at LISTSERV.SYR.EDU<mailto:NCSG-DISCUSS at LISTSERV.SYR.EDU>>
Subject: Re: RANSOMEWARE HIT COMPUTER SYSTEMS
In addition since many of the softwares being used are available in totally open source versions should governments not be making use of these to developed customised solutions that will reduce their vulnerability to these kind of blanket attacks.
best
On Sat, May 13, 2017 at 9:22 AM, Niel Harper <niel.harper at ieee.org<mailto:niel.harper at ieee.org>> wrote:
Hello Wisdom,
I want to play the devil's advocate here for a minute.
Ransomware has been a major problem since the mid-2000s. There was an over 150% increase in new ransomware variants in the first half of 2016 alone. Moreover, cybercriminals are now operating Ransomware-as-a-Service (RaaS) with lower buy-in costs that allow less tech-savvy perpetrators to distribute ransomware. News reports would seem to suggest that yesterday's attack was outside the norm, when it really wasn't.
While providing information on this particular attack is all well and good, shouldn't we be talking about why governments should not be building up their cyber attack capabilities, and why things like stockpiling zero day vulnerabilities is a really bad idea and compromises the security of the Internet (also eroding online trust)?
Additionally, shouldn't the discourse include guidelines about protecting individuals and organizations from malware attack (again not criticizing the efficacy and importance of incident response)?
Sadly enough, hospitals are usually low hanging fruit for ransomware attacks. Their data sets are critical to patient care and management, and they usually don’t have the IT resources to support critical process areas like vulnerability management, patch management, business continuity management, etc. They also generally don’t have robust backup solutions and/or real-time replication to disaster recovery sites which increases the overall availability of mission critical data for recovery. And from a risk management perspective, they don’t possess the depth of human resources to employ a ‘three lines of defense’ approach to managing organizational risk. A robust data backup and recovery solution usually goes a long way in protect oneself from ransomware attacks. My preferred approach for organizations is usually a disk-to-disk-to-tape backup solution combined with offsite replication if possible. The backup tapes are encrypted and stored off site. For individuals, backing up critical data is also very important. But end users need to also regularly update their endpoint security, be wary of phishing and other suspicious emails, and also be mindful the rootkits can be downloaded from legitimate websites that have been compromised.
Regards,
Niel
On Sat, May 13, 2017 at 6:10 AM, Wisdom Donkor <wisdom.dk at gmail.com<mailto:wisdom.dk at gmail.com>> wrote:
Dear Colleagues,
Thought of sharing this information.
Yesterday, May 12, at about 5:00 pm GMT, a massive ransomware hit
computer systems of hundreds of private companies and public organizations across the world which is believed to have the highest infection rate of all time.
The Ransomware in question has been identified as a variant of
ransomware known as WannaCry (also known as 'Wana Decrypt0r,' 'WannaCryptor' or 'WCRY').
Like other dangerous ransomware variants, WannaCry also blocks access to
a computer or its files and demands money to unlock it.
Once infected with the WannaCry ransomware, victims are asked to pay up
to $300 in order to remove the infection from their PCs; otherwise,
their PCs render unusable, and their files remain locked.
WannaCry attackers use a Windows exploit detected and tested by the NSA
called EternalBlue, which was stolen and released by the Shadow Brokers
hacking group over a month ago.
Microsoft released a patch for the vulnerability in March (MS17-010),
but many users and organizations who did not patch their systems are open to attacks.
The exploit has the capability to penetrate into machines running unpatched version of Windows by exploiting flaws in Microsoft Windows SMB Server. This is why the WannaCry ransomware is spreading at an astonishing pace.
Once a single computer in your organization is hit by the WannaCry
ransomware, the worm looks for other vulnerable computers and infects
them as well.
In just a few hours, the ransomware targeted over 45,000 computers in 74
countries, including United States, Russia, Germany, Turkey, Italy, Philippines and Vietnam, and that the number was still growing.
A screenshot of detailing nations attacked are attached in this email.
The ransomeware's actual mode by which it initiates and spreads itself on networks has not been discovered but like other ransomware variant, malicious links and emails are most likely the culprit.
CERT-GH recommends users and system admins:
1. Take all windows OS systems off the internet and off the network.
2. Create a backup of all files needed.
3. Store backup in an airgapped location.
4. Download windows update(KB4019472) in a sandbox environment.
5. Install the update without connecting to a network/internet.
6. After the update, the system can be connected to the internet.
Kind Regards
CERT-GHANA
--
WISDOM DONKOR (S/N Eng.)
E-government and Open Government Data Platforms Specialist
ICANN Fellow / Member, UN IGF MAG Member, ISOC Member,
Freedom Online Coalition (FOC) Member, Diplo Foundation Member,
OGP Open Data WG Member, GODAN Memember, ITAG Member
Email: wisdom.dk at gmail.com<mailto:wisdom.dk at gmail.com>
Skype: wisdom_dk
facebook: facebook at wisdom_dk
Website: www.data.gov.gh<http://www.data.gov.gh/>
www.isoc.gh<http://www.isoc.gh/> / www.itag.org.gh<http://www.itag.org.gh/>
--
Niel Harper
Barbados: +(246) 424 3809<tel:(246)%20424-3809>
London: +44 207 193 9826<tel:+44%2020%207193%209826>
Mobile: +(246) 243 3818<tel:(246)%20243-3818>
Email: niel.harper at ieee.org<mailto:niel.harper at ieee.org>
Website: http://nielharper.com<http://nielharper.com/>
-------------- next part --------------
An HTML attachment was scrubbed...
URL: <http://lists.ncsg.is/pipermail/ncsg-discuss/attachments/20170513/e56fe9b4/attachment.htm>
More information about the Ncsg-discuss
mailing list