Welcome guest. Before posting on our computer help forum, you must register. Click here it's easy and free.

Author Topic: Major Cyberware Attack World Wide  (Read 10848 times)

0 Members and 1 Guest are viewing this topic.

Geek-9pm

    Topic Starter

    Mastermind
  • Geek After Dark
  • Thanked: 1026
    • Gekk9pm bnlog
  • Certifications: List
  • Computer: Specs
  • Experience: Expert
  • OS: Windows 10
Major Cyberware Attack World Wide
« on: May 12, 2017, 10:22:56 PM »
Today, Friday may 12.
The BBC, the New York Times, Fox news and other major media report a very big Cyber attack taht has hit some big companies and institutions.
The link below says hospitals were also hit:
http://www.cumbriacrack.com/2017/05/12/nhs-hospitals-hit-major-cyber-attack/
Quote
Trusts and hospitals in London, Blackburn, Nottingham, Cumbria, Merseyside and Hertfordshire have been affected, other parts of the country are also reporting problems with their computer systems.
They have asked patients not to come to the hospitals unless it is an emergency.
NHS Merseyside, Tweeted: “following a suspected national cyberattack, we are taking all precautionary measures possible to protect our local NHS systems and services.”
As of 3:30pm sixteen NHS organisations have reported that they have been affected.
It is said to be ransomware.
For more search:
Major Cyberware Attack

USA Today:
https://www.usatoday.com/videos/tech/2017/05/12/major-ransomware-attack-hits-thousands-systems-worldwide/101611568/

camerongray



    Expert
  • Thanked: 306
    • Yes
    • Cameron Gray - The Random Rambings of a Computer Geek
  • Certifications: List
  • Computer: Specs
  • Experience: Expert
  • OS: Mac OS
Re: Major Cyberware Attack World Wide
« Reply #1 on: May 13, 2017, 07:57:23 AM »
The current thinking is that it used a SMB vulnerability (MS17-010) to spread across a local network.  The vulnerability was patched by Microsoft in March.  This reinforces why I lose faith in people advising to just "turn off Windows update" or that it's safe to run an unsupported version of Windows because "if you have Antivirus it'll be fine".

Don't think the situation was helped by the NHS apparently cancelling their support contract with Microsoft while still continuing to use XP: https://www.theguardian.com/technology/2015/may/26/uk-government-pcs-open-to-hackers-as-paid-windows-xp-support-ends  Does make you wonder where they are getting their IT staff from if they would be remotely happy doing such a thing.

For people that still insist on running XP, Microsoft have released a patch after this whole problem which can be found here: https://blogs.technet.microsoft.com/msrc/2017/05/12/customer-guidance-for-wannacrypt-attacks/.  At the very least apply this patch although maybe treat this as a reason why it isn't a good idea to still run a 15 year old operating system...

Geek-9pm

    Topic Starter

    Mastermind
  • Geek After Dark
  • Thanked: 1026
    • Gekk9pm bnlog
  • Certifications: List
  • Computer: Specs
  • Experience: Expert
  • OS: Windows 10
Re: Major Cyberware Attack World Wide
« Reply #2 on: May 13, 2017, 09:39:00 AM »
camerongray, I have to agree with you.
Yes, I still use XP.
But it is insane for a large company to continue running XP.



patio

  • Moderator


  • Genius
  • Maud' Dib
  • Thanked: 1769
    • Yes
  • Experience: Beginner
  • OS: Windows 7
Re: Major Cyberware Attack World Wide
« Reply #3 on: May 13, 2017, 01:40:06 PM »
No...it's not.
And the vulnerability is NOT specific to XP PC's...

Read more...
" Anyone who goes to a psychiatrist should have his head examined. "

Geek-9pm

    Topic Starter

    Mastermind
  • Geek After Dark
  • Thanked: 1026
    • Gekk9pm bnlog
  • Certifications: List
  • Computer: Specs
  • Experience: Expert
  • OS: Windows 10
Re: Major Cyberware Attack World Wide
« Reply #4 on: May 13, 2017, 01:47:03 PM »
Quote
The Government ended its annual £5.5 million deal with Microsoft to provide ongoing security support for Windows XP in May 2015, unless individual trusts - already struggling with budgets - were prepared to pay extra for an extended support deal.
Experts say that with no support deal in place Trusts were unable to have access to Microsoft’s anti-virus ‘patches’ designed to foil precisely the sort of attack experienced on Friday.
http://www.telegraph.co.uk/news/2017/05/13/nhs-cyber-attack-repeated-warnings-system-vulnerability-not/
This would suggest that the attack was NOT specific to XP.
Look at this:
https://www.nytimes.com/2017/05/12/world/europe/nhs-cyberattack-warnings.html?_r=0
Quote
Many of the N.H.S. computers still run Windows XP, an out-of-date software that no longer gets security updates from its maker, Microsoft. A government contract with Microsoft to update the software for the N.H.S. expired two years ago.
Many? How many is many? They should not an ANY.
Quote
“Historically, we’ve known that N.H.S. uses computers running old versions of Windows that Microsoft itself no longer supports and says is a security risk,” said Graham Cluley, a cybersecurity expert in Oxford, England. “And even on the newest computers, they would have needed to apply the patch released in March. Clearly that did not happen, or the malware wouldn’t have spread this fast.”
Is it OK to take Aspirin that has expired a year ago?
Ask your doctor.  :P
« Last Edit: May 13, 2017, 01:57:28 PM by Geek-9pm »

patio

  • Moderator


  • Genius
  • Maud' Dib
  • Thanked: 1769
    • Yes
  • Experience: Beginner
  • OS: Windows 7
Re: Major Cyberware Attack World Wide
« Reply #5 on: May 13, 2017, 01:49:57 PM »
Kinda what i stated above...
" Anyone who goes to a psychiatrist should have his head examined. "

camerongray



    Expert
  • Thanked: 306
    • Yes
    • Cameron Gray - The Random Rambings of a Computer Geek
  • Certifications: List
  • Computer: Specs
  • Experience: Expert
  • OS: Mac OS
Re: Major Cyberware Attack World Wide
« Reply #6 on: May 13, 2017, 01:51:32 PM »
I never said it was specific to XP.  However, XP machines without an extended support contract would not have received the patch that was made available for newer versions of Windows.

patio

  • Moderator


  • Genius
  • Maud' Dib
  • Thanked: 1769
    • Yes
  • Experience: Beginner
  • OS: Windows 7
Re: Major Cyberware Attack World Wide
« Reply #7 on: May 13, 2017, 02:05:57 PM »
Au contraire'...

XP still recieves important security updates...contrary to popular belief...

" Anyone who goes to a psychiatrist should have his head examined. "

Geek-9pm

    Topic Starter

    Mastermind
  • Geek After Dark
  • Thanked: 1026
    • Gekk9pm bnlog
  • Certifications: List
  • Computer: Specs
  • Experience: Expert
  • OS: Windows 10
Re: Major Cyberware Attack World Wide
« Reply #8 on: May 13, 2017, 02:07:33 PM »
I just got some yesterday. Don't know what they do.  :-\

patio

  • Moderator


  • Genius
  • Maud' Dib
  • Thanked: 1769
    • Yes
  • Experience: Beginner
  • OS: Windows 7
Re: Major Cyberware Attack World Wide
« Reply #9 on: May 13, 2017, 02:11:13 PM »
They are security updates...they went out to all Win machines...as i said...read more.

My XP rig which is on 24/7 gets them regularly...
" Anyone who goes to a psychiatrist should have his head examined. "

BC_Programmer


    Mastermind
  • Typing is no substitute for thinking.
  • Thanked: 1140
    • Yes
    • Yes
    • BC-Programming.com
  • Certifications: List
  • Computer: Specs
  • Experience: Beginner
  • OS: Windows 11
Re: Major Cyberware Attack World Wide
« Reply #10 on: May 13, 2017, 02:47:19 PM »
Windows XP is out of support and no longer receives Security Updates, and hasn't received regular security updates since April 2014.  Microsoft has provided a few out-of-band security updates for serious issues like this one to the public and continues to provide security updates and bulletins to corporations paying for extended support contracts.

The last Security update for Windows XP was KB2965111 on May 1st, 2014, (which was also an out-of-band update). I can find no reference or information about XP updates (KB articles) issued after that date.

Some users have decided that fiddling with their registry to make Windows Update identify their system as a POS Terminal system is a sufficient replacement, as those continue to receive EFT security updates. The fact that EFT security patches aren't particularly useful on consumer systems doesn't seem to affect their glee at "beating the system".



I was trying to dereference Null Pointers before it was cool.

patio

  • Moderator


  • Genius
  • Maud' Dib
  • Thanked: 1769
    • Yes
  • Experience: Beginner
  • OS: Windows 7
Re: Major Cyberware Attack World Wide
« Reply #11 on: May 13, 2017, 03:10:35 PM »
Mine gets updates about every 3 weeks...and i havent spoofed it to a POS system either...
" Anyone who goes to a psychiatrist should have his head examined. "

Geek-9pm

    Topic Starter

    Mastermind
  • Geek After Dark
  • Thanked: 1026
    • Gekk9pm bnlog
  • Certifications: List
  • Computer: Specs
  • Experience: Expert
  • OS: Windows 10
Re: Major Cyberware Attack World Wide
« Reply #12 on: May 13, 2017, 04:41:08 PM »
Back to the broad scope of topic.
Newsweek has this item of interest:

An interactive map that visualizes the global cyber war in real time has been making the rounds on social media in recent days. It shows a steady flow, or sometimes deluge, of cyber-attacks—depicted as colorful, laser-esque beams—traversing the screen...and it is captivating audiences.

http://www.newsweek.com/real-time-cyber-attack-map-shows-scope-global-cyber-war-352886

It has been reported that about 100 countries have been under attack recently.
I can not get the MSN link to work.

Geek-9pm

    Topic Starter

    Mastermind
  • Geek After Dark
  • Thanked: 1026
    • Gekk9pm bnlog
  • Certifications: List
  • Computer: Specs
  • Experience: Expert
  • OS: Windows 10
Re: Major Cyberware Attack World Wide
« Reply #13 on: May 14, 2017, 12:05:37 PM »
Today is  5/14/2017

Cyber Attack Kill switch Found.


https://www.theguardian.com/technology/2017/may/13/accidental-hero-finds-kill-switch-to-stop-spread-of-ransomware-cyber-attack

The above claims the threat is now over. Discovered by a malware  researcher.

Computer CPR



    Beginner

    Thanked: 2
    • Computer CPR
  • Experience: Beginner
  • OS: Windows 7
Re: Major Cyberware Attack World Wide
« Reply #14 on: May 16, 2017, 12:12:06 PM »
They were saying that in the source code of the malware it checks to see if this crazy long domain name is registered and if so, it doesn't do any harm.  So they registered the domain and seemed to put it at bay...for now.

Geek-9pm

    Topic Starter

    Mastermind
  • Geek After Dark
  • Thanked: 1026
    • Gekk9pm bnlog
  • Certifications: List
  • Computer: Specs
  • Experience: Expert
  • OS: Windows 10
Re: Major Cyberware Attack World Wide
« Reply #15 on: May 16, 2017, 12:47:18 PM »
That is what I also read from a link from a friend on Facebook.
However, some media reports say the threat is still running. Which seems to contradict the information about the "kill switch" thing.
And it might shift to another issue. Lawsuits.
See here:
https://www.computerhope.com/forum/index.php/topic,160820.0.html
Recent Cyber Attacvk may start lawsuits.
So we live in a crazy world?
Be a victim and get sued!  :o