Close

Results 1 to 16 of 16

Threaded View

Previous Post Previous Post   Next Post Next Post
  1. #1
    DF Super Moderator
    evilsatan's Avatar
    Join Date
    Jul 2004
    Location
    Essex
    Posts
    20,080
    Thanks
    1,105
    Thanked:        3,242
    Karma Level
    1542

    Default Protecting yourself from WannaCry ransomware

    This may not all be accurate or the best advice but I am sharing what I have, feel free to add to it or amend as you see fit.

    The SMBv1 protocol was exploited by EternalBlue (part of the NSA leaked tools), this is enabled by default in all Windows operating systems older than Windows 10/Server 2016. Other platforms should not be affected.

    • Use decent security

    Ever since Rap recommended it so many years ago on here, Eset has been my security product of choice. Most of my clients have Eset Endpoint Security (or Smart Security in the case of home users), the response from them was this:
    ESET’s network protection module was already blocking attempts to exploit the leaked vulnerability at the network level before this particular malware was even created. ESET increased the protection level by adding detection for this specific threat as Win32/Filecoder.WannaCryptor.D; first detected in the 15404 VSDs, released May-12-2017, 13:20 CEST (UTC/GMT +02:00). Prior to that, ESET LiveGrid protected against this particular attack starting around 11:26AM CEST.
    Even if you don't want to use Eset general advice is to use a good, premium security suite. I don't know how well they coped with this particular threat but I hear Kaspersky or Bitdefender are both very good alternatives to Eset, or you can check out reports on these apparently unbiased sites:
    https://www.av-comparatives.org/
    https://www.av-test.org/en/

    • Keep Windows up to date

    The advice was to keep Windows up to date but in particular you need to patch Microsoft Security Bulletin MS17-010. You can find the relevant patches for operating systems as old as Windows XP here: https://technet.microsoft.com/en-us/.../ms17-010.aspx
    Be sure to select the correct architecture, and if it says SP1/SP2 make sure you have that service pack installed or it will not apply the patch. If you use another variant of OS, WHS2011 for example, look what the base OS is. In the case of WHS2011 you will need Server 2008 R2.

    Security only patches the flaw only, the rollup includes the patch and some quality updates so up to you which you install. It is worth noting that subsequent months security rollups e.g. April/May do not include previous months patches so you need to install the March patch from the link above. You should also be on at least Windows 7/Server 2008 R2 as older systems are not supported by Microsoft, these patches are one-offs given the severity of this vuln.

    • Disable SMBv1

    This should help you disable SMBv1, most people should not need it any more.
    https://support.microsoft.com/en-us/...ws-server-2012

    • Backup your data

    You should have an offsite backup of any data you can't afford to lose, preferably this would have versioning too in case your infected files are uploaded and in some cases you may want snapshots (depending what you are backing up).
    Last edited by evilsatan; 16th May 2017 at 07:28 PM.

    9 Thanks given to evilsatan

    Ashley (16th May 2017),  Bald Bouncer (16th May 2017),  EvilBoB (17th May 2017),  Mickey (16th May 2017),  muttleymacclad (16th May 2017),  Over Carl (16th May 2017),  piggzy (16th May 2017),  WRATH OF BOD (16th May 2017)  


Similar Threads

  1. Ransomware resource
    By Zippeyrude in forum System Security
    Replies: 7
    Last Post: 15th April 2017, 02:08 PM
  2. [NEW] I just received this on the War of Ransomware [ Security ]
    By Black Oracle in forum System Security
    Replies: 2
    Last Post: 13th June 2016, 10:07 AM
  3. Cryptolocker Ransomware Warning
    By MsDG in forum System Security
    Replies: 60
    Last Post: 25th November 2013, 07:26 PM

Social Networking Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •