Calgarypuck Forums - The Unofficial Calgary Flames Fan Community

Go Back   Calgarypuck Forums - The Unofficial Calgary Flames Fan Community > Main Forums > The Off Topic Forum > Tech Talk

Reply
 
Thread Tools Search this Thread
Old 06-09-2016, 09:37 AM   #41
Mazrim
CP Gamemaster
 
Mazrim's Avatar
 
Join Date: Feb 2010
Location: The Gary
Exp:
Default

Quote:
Originally Posted by Hack&Lube View Post
Since when are Waves Coffee or Cafe Blanca dodgy? (Both have Bitcoin ATMs). Also, Canada's biggest online Bitcoin exchange was started in Calgary 5 years ago (bought out now by a bigger company called Kraken but still in operation). In case anybody needs Bitcoins, those are places you can go.
They went the Hollywood route and met someone wearing a trenchcoat in a random café at 11 PM?
Mazrim is offline   Reply With Quote
Old 06-09-2016, 11:44 AM   #42
Hack&Lube
Atomic Nerd
 
Join Date: Jul 2004
Location: Calgary
Exp:
Default

Quote:
Originally Posted by Mazrim View Post
They went the Hollywood route and met someone wearing a trenchcoat in a random café at 11 PM?
"Pssst, you wanna buy some Bitcoins?"



My guess is IT guy was exaggerating or didn't know what he was doing.
Hack&Lube is offline   Reply With Quote
Old 06-09-2016, 12:00 PM   #43
Russic
Dances with Wolves
 
Russic's Avatar
 
Join Date: Jun 2006
Location: Section 304
Exp:
Default

If you have a website at all, you might as well use this as an excuse to take a moment to review your backup strategy. If this happened to you right now, what would you do? That even goes beyond your corporate website... might as well factor in your phone and home computers.

We used to offer backup services to our clients when we built them sites, but we found out that of the ones who decided to do it themselves, not a single one did any backups or updates. We pretty much had to make it a mandatory part of our projects just to save them from themselves.
Russic is offline   Reply With Quote
Old 06-09-2016, 10:57 PM   #44
Vulcan
Franchise Player
 
Vulcan's Avatar
 
Join Date: Dec 2003
Location: Sunshine Coast
Exp:
Default

There are anti-ransom wares out there. I can't say how effective they are but I installed Bitdefender Anti-ransomware.

https://labs.bitdefender.com/2016/03...cine-released/
Vulcan is offline   Reply With Quote
The Following User Says Thank You to Vulcan For This Useful Post:
Old 06-10-2016, 11:22 AM   #45
FanIn80
GOAT!
 
FanIn80's Avatar
 
Join Date: Jun 2006
Exp:
Default

Quote:
Originally Posted by jammies View Post
I remember doing a project for the U of C around 2005 and the guy I was working with told me he had recently discovered a server in a closet that was connected to their network but nobody could tell him what it did or who put it there,. It was covered in dust and had obviously been there for years undisturbed. He wasn't allowed to take it down or disconnect because they were afraid it did something important.
It was probably an old Linux box that was running the key card server or something like that. You can just bury those things in a corner somewhere and never touch it again for a decade. Everyone uses the web interface to manage the cards and door access, etc, and they all just assume it's running off the DC or whatever, but nope. It's that old, brown piece of plastic sitting in the bottom of a closet covered in dust balls and spiderwebs that no one wants to touch.
FanIn80 is offline   Reply With Quote
The Following User Says Thank You to FanIn80 For This Useful Post:
Old 06-10-2016, 12:00 PM   #46
Rathji
Franchise Player
 
Rathji's Avatar
 
Join Date: Nov 2006
Location: Supporting Urban Sprawl
Exp:
Default

Quote:
Originally Posted by ZedMan View Post
There is no 'IT' faculty. There's Computer Science and those guys are probably closer to mathematicians than IT admins.
The CPSC faculty manages it's own IT resources (mostly) independantly of the UCIT system. The guys who admin it are likely the most competent on the campus at doing this kind of thing. That doesn't mean they are perfect, mind you.

The reason they paid out was that it was faster to do that than recover backups for everything. IIRC their backup jobs run pretty much constantly and it would take forever to do a recovery of that size.

That said, it was almost certainly not Cryptolocker or TeslaCrypt, but was most than likely Locky.

The people who are running Locky are targeting businesses who they figure *must* pay or their business will lose more money due to the downtime. Can you imagine the chaos and money loss at the university if even just a handful of profs or a single department lost a day or 2 worth of data? You could be talking about results of projects that spanned many months and hundreds of man-hours. There was a big hospital in California a few months ago that paid an equivalent sum.

This isn't about the IT department being incompetent, and anyone who has ever dealt with this can tell you that even if you take every precaution, some idiot user will click on that email attachment or enable the macro in Word and you are pooched.
__________________
"Wake up, Luigi! The only time plumbers sleep on the job is when we're working by the hour."
Rathji is offline   Reply With Quote
The Following 2 Users Say Thank You to Rathji For This Useful Post:
Old 06-10-2016, 12:05 PM   #47
Rathji
Franchise Player
 
Rathji's Avatar
 
Join Date: Nov 2006
Location: Supporting Urban Sprawl
Exp:
Default

Quote:
Originally Posted by Russic View Post
If you have a website at all, you might as well use this as an excuse to take a moment to review your backup strategy. If this happened to you right now, what would you do? That even goes beyond your corporate website... might as well factor in your phone and home computers.
I don't have time to look it up now, but I am certain there are Locky variant for Android in the wild.

Quote:
Originally Posted by Vulcan View Post
There are anti-ransom wares out there. I can't say how effective they are but I installed Bitdefender Anti-ransomware.

https://labs.bitdefender.com/2016/03...cine-released/
I use this on my personal machine, but it is a PITA to deploy to a company without going to every machine. I am actually involved in determining the best way to use this or a similar method for vaccinating our clients to Locky. Would welcome input if you know a way.
__________________
"Wake up, Luigi! The only time plumbers sleep on the job is when we're working by the hour."
Rathji is offline   Reply With Quote
Old 06-10-2016, 12:21 PM   #48
peter12
Franchise Player
 
peter12's Avatar
 
Join Date: Jul 2002
Exp:
Default

And from what I heard, they hit them right at convocation. The University needed the student data ASAP.
peter12 is offline   Reply With Quote
Old 06-10-2016, 12:55 PM   #49
Vulcan
Franchise Player
 
Vulcan's Avatar
 
Join Date: Dec 2003
Location: Sunshine Coast
Exp:
Default

Quote:
Originally Posted by Rathji View Post
I don't have time to look it up now, but I am certain there are Locky variant for Android in the wild.



I use this on my personal machine, but it is a PITA to deploy to a company without going to every machine. I am actually involved in determining the best way to use this or a similar method for vaccinating our clients to Locky. Would welcome input if you know a way.
All I know, which is very little, I got from reading this page.

http://askbobrankin.com/locked_the_l...ansomware.html
Vulcan is offline   Reply With Quote
The Following User Says Thank You to Vulcan For This Useful Post:
Old 06-14-2016, 04:11 PM   #50
Yamer
Franchise Player
 
Yamer's Avatar
 
Join Date: Jul 2009
Location: Red Deer
Exp:
Default

Congratulations to my alma mater...they made a Cracked article:

http://www.cracked.com/article_24160...ow-614_p2.html
__________________
"It's a great day for hockey."
-'Badger' Bob Johnson (1931-1991)

"I see as much misery out of them moving to justify theirselves as them that set out to do harm."
-Dr. Amos "Doc" Cochran
Yamer is offline   Reply With Quote
Old 06-14-2016, 04:21 PM   #51
Locke
Franchise Player
 
Locke's Avatar
 
Join Date: Mar 2007
Location: Income Tax Central
Exp:
Default

Quote:
Originally Posted by Yamer View Post
Congratulations to my alma mater...they made a Cracked article:

http://www.cracked.com/article_24160...ow-614_p2.html
We're #1 7! We're #1 7!
__________________
The Beatings Shall Continue Until Morale Improves!

This Post Has Been Distilled for the Eradication of Seemingly Incurable Sadness.

The World Ends when you're dead. Until then, you've got more punishment in store. - Flames Fans

If you thought this season would have a happy ending, you haven't been paying attention.
Locke is offline   Reply With Quote
Old 06-15-2016, 12:50 PM   #52
nik-
Franchise Player
 
nik-'s Avatar
 
Join Date: Jun 2004
Exp:
Default

Cracked is basically buzzfeed now
__________________
Quote:
Originally Posted by MisterJoji View Post
Johnny eats garbage and isn’t 100% committed.
nik- is offline   Reply With Quote
Old 06-16-2016, 04:06 PM   #53
Yamer
Franchise Player
 
Yamer's Avatar
 
Join Date: Jul 2009
Location: Red Deer
Exp:
Default

Quote:
Originally Posted by nik- View Post
Cracked is basically buzzfeed now
Apart from their weekly "The Most Insane Things...", how so?
__________________
"It's a great day for hockey."
-'Badger' Bob Johnson (1931-1991)

"I see as much misery out of them moving to justify theirselves as them that set out to do harm."
-Dr. Amos "Doc" Cochran
Yamer is offline   Reply With Quote
Old 06-17-2016, 03:26 PM   #54
Yamer
Franchise Player
 
Yamer's Avatar
 
Join Date: Jul 2009
Location: Red Deer
Exp:
Default

And it has just hit Red Deer College. We received a notification about 15 minutes ago and we are completely locked. It's the weekend for me, but the Students here are heading into spring term exams on Monday with no access to the system.
__________________
"It's a great day for hockey."
-'Badger' Bob Johnson (1931-1991)

"I see as much misery out of them moving to justify theirselves as them that set out to do harm."
-Dr. Amos "Doc" Cochran
Yamer is offline   Reply With Quote
Old 06-17-2016, 08:45 PM   #55
Azure
Had an idea!
 
Azure's Avatar
 
Join Date: Oct 2005
Exp:
Default

Is there no endpoint security on these networks? Cisco AMP or similar service?
Azure is offline   Reply With Quote
Old 06-20-2016, 04:43 PM   #56
Rathji
Franchise Player
 
Rathji's Avatar
 
Join Date: Nov 2006
Location: Supporting Urban Sprawl
Exp:
Default

Quote:
Originally Posted by Azure View Post
Is there no endpoint security on these networks? Cisco AMP or similar service?
UofC almost all profs have local admin rights on their PC. At that point, almost no malware protection in the world will stop a dedicated attacker using a 0-day, or similar exploit . Keep in mind these are targeted attacks, not just people clicking on random links or spam email attachments.
__________________
"Wake up, Luigi! The only time plumbers sleep on the job is when we're working by the hour."
Rathji is offline   Reply With Quote
Old 06-20-2016, 05:31 PM   #57
Azure
Had an idea!
 
Azure's Avatar
 
Join Date: Oct 2005
Exp:
Default

How does that lead to the entire network being shut down? Local admin rights shouldn't give them access to everything else should it?
Azure is offline   Reply With Quote
Old 06-20-2016, 09:14 PM   #58
calumniate
Franchise Player
 
calumniate's Avatar
 
Join Date: Feb 2007
Location: A small painted room
Exp:
Default

Quote:
Originally Posted by Yamer View Post
And it has just hit Red Deer College. We received a notification about 15 minutes ago and we are completely locked. It's the weekend for me, but the Students here are heading into spring term exams on Monday with no access to the system.
Yikes
calumniate is offline   Reply With Quote
Old 06-21-2016, 08:50 AM   #59
Russic
Dances with Wolves
 
Russic's Avatar
 
Join Date: Jun 2006
Location: Section 304
Exp:
Default

Quote:
Originally Posted by Yamer View Post
And it has just hit Red Deer College. We received a notification about 15 minutes ago and we are completely locked. It's the weekend for me, but the Students here are heading into spring term exams on Monday with no access to the system.
Whatever happened with this?
Russic is offline   Reply With Quote
Old 06-21-2016, 09:53 AM   #60
temple5
Crash and Bang Winger
 
Join Date: Jan 2008
Exp:
Default

I wonder what professor clicked on the fishing email to get this started. My guess is someone in Liberal Arts or Geology.

Off site backup via HP/Iron Mountain, Veeam etc will protect you. There will be some downtime as restores take time but no reason to pay these russian/chinese peeps.
temple5 is offline   Reply With Quote
Reply

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT -6. The time now is 05:22 PM.

Calgary Flames
2024-25




Powered by vBulletin® Version 3.8.4
Copyright ©2000 - 2025, Jelsoft Enterprises Ltd.
Copyright Calgarypuck 2021 | See Our Privacy Policy