06-09-2016, 09:37 AM
|
#41
|
CP Gamemaster
Join Date: Feb 2010
Location: The Gary
|
Quote:
Originally Posted by Hack&Lube
Since when are Waves Coffee or Cafe Blanca dodgy? (Both have Bitcoin ATMs). Also, Canada's biggest online Bitcoin exchange was started in Calgary 5 years ago (bought out now by a bigger company called Kraken but still in operation). In case anybody needs Bitcoins, those are places you can go.
|
They went the Hollywood route and met someone wearing a trenchcoat in a random café at 11 PM?
|
|
|
06-09-2016, 11:44 AM
|
#42
|
Atomic Nerd
Join Date: Jul 2004
Location: Calgary
|
Quote:
Originally Posted by Mazrim
They went the Hollywood route and met someone wearing a trenchcoat in a random café at 11 PM?
|
"Pssst, you wanna buy some Bitcoins?"
My guess is IT guy was exaggerating or didn't know what he was doing.
|
|
|
06-09-2016, 12:00 PM
|
#43
|
Dances with Wolves
Join Date: Jun 2006
Location: Section 304
|
If you have a website at all, you might as well use this as an excuse to take a moment to review your backup strategy. If this happened to you right now, what would you do? That even goes beyond your corporate website... might as well factor in your phone and home computers.
We used to offer backup services to our clients when we built them sites, but we found out that of the ones who decided to do it themselves, not a single one did any backups or updates. We pretty much had to make it a mandatory part of our projects just to save them from themselves.
|
|
|
06-09-2016, 10:57 PM
|
#44
|
Franchise Player
Join Date: Dec 2003
Location: Sunshine Coast
|
There are anti-ransom wares out there. I can't say how effective they are but I installed Bitdefender Anti-ransomware.
https://labs.bitdefender.com/2016/03...cine-released/
|
|
|
The Following User Says Thank You to Vulcan For This Useful Post:
|
|
06-10-2016, 11:22 AM
|
#45
|
GOAT!
|
Quote:
Originally Posted by jammies
I remember doing a project for the U of C around 2005 and the guy I was working with told me he had recently discovered a server in a closet that was connected to their network but nobody could tell him what it did or who put it there,. It was covered in dust and had obviously been there for years undisturbed. He wasn't allowed to take it down or disconnect because they were afraid it did something important.
|
It was probably an old Linux box that was running the key card server or something like that. You can just bury those things in a corner somewhere and never touch it again for a decade. Everyone uses the web interface to manage the cards and door access, etc, and they all just assume it's running off the DC or whatever, but nope. It's that old, brown piece of plastic sitting in the bottom of a closet covered in dust balls and spiderwebs that no one wants to touch.
|
|
|
The Following User Says Thank You to FanIn80 For This Useful Post:
|
|
06-10-2016, 12:00 PM
|
#46
|
Franchise Player
Join Date: Nov 2006
Location: Supporting Urban Sprawl
|
Quote:
Originally Posted by ZedMan
There is no 'IT' faculty. There's Computer Science and those guys are probably closer to mathematicians than IT admins.
|
The CPSC faculty manages it's own IT resources (mostly) independantly of the UCIT system. The guys who admin it are likely the most competent on the campus at doing this kind of thing. That doesn't mean they are perfect, mind you.
The reason they paid out was that it was faster to do that than recover backups for everything. IIRC their backup jobs run pretty much constantly and it would take forever to do a recovery of that size.
That said, it was almost certainly not Cryptolocker or TeslaCrypt, but was most than likely Locky.
The people who are running Locky are targeting businesses who they figure *must* pay or their business will lose more money due to the downtime. Can you imagine the chaos and money loss at the university if even just a handful of profs or a single department lost a day or 2 worth of data? You could be talking about results of projects that spanned many months and hundreds of man-hours. There was a big hospital in California a few months ago that paid an equivalent sum.
This isn't about the IT department being incompetent, and anyone who has ever dealt with this can tell you that even if you take every precaution, some idiot user will click on that email attachment or enable the macro in Word and you are pooched.
__________________
"Wake up, Luigi! The only time plumbers sleep on the job is when we're working by the hour."
|
|
|
The Following 2 Users Say Thank You to Rathji For This Useful Post:
|
|
06-10-2016, 12:05 PM
|
#47
|
Franchise Player
Join Date: Nov 2006
Location: Supporting Urban Sprawl
|
Quote:
Originally Posted by Russic
If you have a website at all, you might as well use this as an excuse to take a moment to review your backup strategy. If this happened to you right now, what would you do? That even goes beyond your corporate website... might as well factor in your phone and home computers.
|
I don't have time to look it up now, but I am certain there are Locky variant for Android in the wild.
Quote:
Originally Posted by Vulcan
|
I use this on my personal machine, but it is a PITA to deploy to a company without going to every machine. I am actually involved in determining the best way to use this or a similar method for vaccinating our clients to Locky. Would welcome input if you know a way.
__________________
"Wake up, Luigi! The only time plumbers sleep on the job is when we're working by the hour."
|
|
|
06-10-2016, 12:21 PM
|
#48
|
Franchise Player
|
And from what I heard, they hit them right at convocation. The University needed the student data ASAP.
|
|
|
06-10-2016, 12:55 PM
|
#49
|
Franchise Player
Join Date: Dec 2003
Location: Sunshine Coast
|
Quote:
Originally Posted by Rathji
I don't have time to look it up now, but I am certain there are Locky variant for Android in the wild.
I use this on my personal machine, but it is a PITA to deploy to a company without going to every machine. I am actually involved in determining the best way to use this or a similar method for vaccinating our clients to Locky. Would welcome input if you know a way.
|
All I know, which is very little, I got from reading this page.
http://askbobrankin.com/locked_the_l...ansomware.html
|
|
|
The Following User Says Thank You to Vulcan For This Useful Post:
|
|
06-14-2016, 04:11 PM
|
#50
|
Franchise Player
Join Date: Jul 2009
Location: Red Deer
|
Congratulations to my alma mater...they made a Cracked article:
http://www.cracked.com/article_24160...ow-614_p2.html
__________________
"It's a great day for hockey."
-'Badger' Bob Johnson (1931-1991)
"I see as much misery out of them moving to justify theirselves as them that set out to do harm."
-Dr. Amos "Doc" Cochran
|
|
|
06-14-2016, 04:21 PM
|
#51
|
Franchise Player
Join Date: Mar 2007
Location: Income Tax Central
|
Quote:
Originally Posted by Yamer
|
We're # 1 7! We're # 1 7!
__________________
The Beatings Shall Continue Until Morale Improves!
This Post Has Been Distilled for the Eradication of Seemingly Incurable Sadness.
The World Ends when you're dead. Until then, you've got more punishment in store. - Flames Fans
If you thought this season would have a happy ending, you haven't been paying attention.
|
|
|
06-15-2016, 12:50 PM
|
#52
|
Franchise Player
|
Cracked is basically buzzfeed now
__________________
Quote:
Originally Posted by MisterJoji
Johnny eats garbage and isn’t 100% committed.
|
|
|
|
06-16-2016, 04:06 PM
|
#53
|
Franchise Player
Join Date: Jul 2009
Location: Red Deer
|
Quote:
Originally Posted by nik-
Cracked is basically buzzfeed now
|
Apart from their weekly "The Most Insane Things...", how so?
__________________
"It's a great day for hockey."
-'Badger' Bob Johnson (1931-1991)
"I see as much misery out of them moving to justify theirselves as them that set out to do harm."
-Dr. Amos "Doc" Cochran
|
|
|
06-17-2016, 03:26 PM
|
#54
|
Franchise Player
Join Date: Jul 2009
Location: Red Deer
|
And it has just hit Red Deer College. We received a notification about 15 minutes ago and we are completely locked. It's the weekend for me, but the Students here are heading into spring term exams on Monday with no access to the system.
__________________
"It's a great day for hockey."
-'Badger' Bob Johnson (1931-1991)
"I see as much misery out of them moving to justify theirselves as them that set out to do harm."
-Dr. Amos "Doc" Cochran
|
|
|
06-17-2016, 08:45 PM
|
#55
|
Had an idea!
|
Is there no endpoint security on these networks? Cisco AMP or similar service?
|
|
|
06-20-2016, 04:43 PM
|
#56
|
Franchise Player
Join Date: Nov 2006
Location: Supporting Urban Sprawl
|
Quote:
Originally Posted by Azure
Is there no endpoint security on these networks? Cisco AMP or similar service?
|
UofC almost all profs have local admin rights on their PC. At that point, almost no malware protection in the world will stop a dedicated attacker using a 0-day, or similar exploit . Keep in mind these are targeted attacks, not just people clicking on random links or spam email attachments.
__________________
"Wake up, Luigi! The only time plumbers sleep on the job is when we're working by the hour."
|
|
|
06-20-2016, 05:31 PM
|
#57
|
Had an idea!
|
How does that lead to the entire network being shut down? Local admin rights shouldn't give them access to everything else should it?
|
|
|
06-20-2016, 09:14 PM
|
#58
|
Franchise Player
Join Date: Feb 2007
Location: A small painted room
|
Quote:
Originally Posted by Yamer
And it has just hit Red Deer College. We received a notification about 15 minutes ago and we are completely locked. It's the weekend for me, but the Students here are heading into spring term exams on Monday with no access to the system.
|
Yikes
|
|
|
06-21-2016, 08:50 AM
|
#59
|
Dances with Wolves
Join Date: Jun 2006
Location: Section 304
|
Quote:
Originally Posted by Yamer
And it has just hit Red Deer College. We received a notification about 15 minutes ago and we are completely locked. It's the weekend for me, but the Students here are heading into spring term exams on Monday with no access to the system.
|
Whatever happened with this?
|
|
|
06-21-2016, 09:53 AM
|
#60
|
Crash and Bang Winger
|
I wonder what professor clicked on the fishing email to get this started. My guess is someone in Liberal Arts or Geology.
Off site backup via HP/Iron Mountain, Veeam etc will protect you. There will be some downtime as restores take time but no reason to pay these russian/chinese peeps.
|
|
|
Posting Rules
|
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
HTML code is Off
|
|
|
All times are GMT -6. The time now is 02:15 PM.
|
|