Author Topic: NSA Exploit Strikes Again  (Read 1510 times)

Ben

  • Administrator
  • Senior Member
  • *****
  • Posts: 46,078
  • I'm an Extremist!
NSA Exploit Strikes Again
« on: June 27, 2017, 07:04:09 PM »
The Petya ransomware is infecting much of Europe, including Maersk shipping. I'm curious how far that actually affects their worldwide shipping and what backups they have for something like that.

Petya is using the same exploit as Wannacry did, which was developed by the NSA to poke into everybody's business. Thanks NSA.

http://www.foxnews.com/tech/2017/06/27/huge-ransomware-attack-hits-europe-sparks-mass-disruption.html
"I'm a foolish old man that has been drawn into a wild goose chase by a harpy in trousers and a nincompoop."

Regolith

  • friend
  • Senior Member
  • ***
  • Posts: 6,171
Re: NSA Exploit Strikes Again
« Reply #1 on: June 28, 2017, 12:00:22 AM »
Anyone who hasn't patched that vulnerability by now almost freaking deserves it.  :facepalm:
The price of freedom is eternal vigilance. - Thomas Jefferson

Necessity is the plea for every infringement of human freedom. It is the argument of tyrants; it is the creed of slaves. - William Pitt the Younger

Perfectly symmetrical violence never solved anything. - Professor Hubert J. Farnsworth

agricola

  • friend
  • Senior Member
  • ***
  • Posts: 1,248
Re: NSA Exploit Strikes Again
« Reply #2 on: June 28, 2017, 10:54:35 AM »
Anyone who hasn't patched that vulnerability by now almost freaking deserves it.  :facepalm:

you mean the virus or the NSA?
"Idiot!  A long life eating mush is best."
"Make peace, you fools"

Perd Hapley

  • Superstar of the Internet
  • friend
  • Senior Member
  • ***
  • Posts: 61,431
  • My prepositions are on/in
Re: NSA Exploit Strikes Again
« Reply #3 on: June 28, 2017, 11:22:34 AM »
you mean the virus or the NSA?

Well played.
"Doggies are angel babies!" -- my wife

Fitz

  • Face-melter
  • friend
  • Senior Member
  • ***
  • Posts: 6,254
  • Floyd Rose is my homeboy
    • My Book
Re: NSA Exploit Strikes Again
« Reply #4 on: June 28, 2017, 07:40:42 PM »
Anyone who hasn't patched that vulnerability by now almost freaking deserves it.  :facepalm:

This

so far as we can tell, the kill switch found and used during the last one made tons of IT people say "Oh ok, we're safe now"

... so they were still unpatched.


Fitz

---------------
I have reached a conclusion regarding every member of this forum.
I no longer respect any of you. I hope the following offends you as much as this thread has offended me:
You are all awful people. I mean this *expletive deleted*ing seriously.

-MicroBalrog

RevDisk

  • friend
  • Senior Member
  • ***
  • Posts: 12,633
    • RevDisk.net
Re: NSA Exploit Strikes Again
« Reply #5 on: June 30, 2017, 08:46:41 AM »
This

so far as we can tell, the kill switch found and used during the last one made tons of IT people say "Oh ok, we're safe now"

... so they were still unpatched.

 :facepalm:

It's not the 90's anymore. Any business these days at a minimum needs monthly patching, reporting, enterprise grade AV and malware/baddie checking at multiple points all over the network. Plus you know, employee training. My email gets filtered three times before a user sees it, and we still sometimes get new stuff. Then you have the desktop AV just in case.

Morons. If it can't be patched, draw up a business plan for scheduled replacement. Or put them behind dedicated firewalls with very tight whitelists.
"Rev, your picture is in my King James Bible, where Paul talks about "inventors of evil."  Yes, I know you'll take that as a compliment."  - Fistful, possibly highest compliment I've ever received.

Fitz

  • Face-melter
  • friend
  • Senior Member
  • ***
  • Posts: 6,254
  • Floyd Rose is my homeboy
    • My Book
Re: NSA Exploit Strikes Again
« Reply #6 on: June 30, 2017, 06:59:35 PM »
:facepalm:

It's not the 90's anymore. Any business these days at a minimum needs monthly patching, reporting, enterprise grade AV and malware/baddie checking at multiple points all over the network. Plus you know, employee training. My email gets filtered three times before a user sees it, and we still sometimes get new stuff. Then you have the desktop AV just in case.

Morons. If it can't be patched, draw up a business plan for scheduled replacement. Or put them behind dedicated firewalls with very tight whitelists.


We even patched old OS's that we said we were done patching, and people still got hit.


Fitz

---------------
I have reached a conclusion regarding every member of this forum.
I no longer respect any of you. I hope the following offends you as much as this thread has offended me:
You are all awful people. I mean this *expletive deleted*ing seriously.

-MicroBalrog

RevDisk

  • friend
  • Senior Member
  • ***
  • Posts: 12,633
    • RevDisk.net
Re: NSA Exploit Strikes Again
« Reply #7 on: July 01, 2017, 11:11:01 AM »
We even patched old OS's that we said we were done patching, and people still got hit.

In fairness, some blame lies on lots of vendors who screw up and do not keep up with security. I've seen quite a few legacy systems labeled "DO NOT PATCH, OR WILL BREAK COMPLETELY". I've always made it conditional that max of one year or we yank the cable. That's not as easy with say, a CNC router that's a couple million bucks. Embedded computer folks are generally the absolute stone cold worst, and charge insane pricing for support that's terrible.
"Rev, your picture is in my King James Bible, where Paul talks about "inventors of evil."  Yes, I know you'll take that as a compliment."  - Fistful, possibly highest compliment I've ever received.