Groups | Search | Server Info | Keyboard shortcuts | Login | Register [http] [https] [nntp] [nntps]


Groups > comp.os.linux.advocacy > #343804

Re: Windows?

From Desk Rabbit <me@example.com>
Newsgroups comp.os.linux.advocacy
Subject Re: Windows?
Date 2016-02-17 12:44 +0000
Organization A noiseless patient Spider
Message-ID <na1ppa$hu$2@deskrabbit.motzarella.org> (permalink)
References <20160216191422.48cb0e82@maxa-pc> <n9vqdf$n7d$1@dont-email.me> <20160216195425.1b1906d8@maxa-pc>

Show all headers | View raw


On 16/02/2016 18:54, Melzzzzz wrote:
> On Tue, 16 Feb 2016 13:42:52 -0500
> "Ezekiel" <zeke@nosuchemail.com> wrote:
>
>> "Melzzzzz" <mel@zzzzz.com> wrote in message
>> news:20160216191422.48cb0e82@maxa-pc...
>>> http://www.techtimes.com/articles/133874/20160216/hackers-hold-hollywood-hospital-s-computer-system-hostage-demand-3-6-million-as-patients-transferred.htm
>>> "
>>> Hackers have taken the computer system of the Hollywood Presbyterian
>>> Medical Center hostage, demanding 9,000 Bitcoin or $3.6 million.
>>> "
>>
>>      "The administration has forbidden the use of other computers
>>      for fear that the harmful software could spread to more
>> workstations."
>>
>> Most likely Windows if it's workstations.
>>
>> I could see local data being encrypted/taken-hostage but all the
>> important stuff at a hospital should be on some backend DB running on
>> a server. IT should constantly be backing up this data. If the
>> servers weren't compromised (and they shouldn't have) then what does
>> the $3.6M get them?
>
> Problem is always one machine that keeps important password(s).
> That goes like that. User plugs in usb key with game or
> access some malware site, etc. When hacker gets passwords for access to
> server, all is lost. No matter OS on the server.
>
>
>>
>> Did they get in by leaving USB drives in the parking lot?
>
> Probably.

Wouldn't work on any site we manage. USB is locked out except for a few 
and each stick/drive is scanned before being used.

It's a little more difficult at a print shop we support where customers 
bring in sticks with work on them to be printed but the AV we use scans 
the stick before allowing access, never had a problem.

This ransomware is usually from links in emails. A good AV on the email 
system and managed DNS like Umbrella stops that in its tracks.

And yes in the early days of ransomware we had a couple of customers hit 
but by using shadow copies (A Windows server technology enabled by 
default unlike Linux Server) all the files were replaced within an hour 
and no damage was done, no business lost and no ransom paid.

Back to comp.os.linux.advocacy | Previous | NextPrevious in thread | Next in thread | Find similar | Unroll thread


Thread

Windows? Melzzzzz <mel@zzzzz.com> - 2016-02-16 19:14 +0100
  Re: Windows? "Ezekiel" <zeke@nosuchemail.com> - 2016-02-16 13:42 -0500
    Re: Windows? Melzzzzz <mel@zzzzz.com> - 2016-02-16 19:54 +0100
      Re: Windows? "Ezekiel" <zeke@nosuchemail.com> - 2016-02-16 14:19 -0500
        Re: Windows? Melzzzzz <mel@zzzzz.com> - 2016-02-16 20:52 +0100
          Re: Windows? "Ezekiel" <zeke@nosuchemail.com> - 2016-02-16 15:23 -0500
      Re: Windows? Desk Rabbit <me@example.com> - 2016-02-17 12:44 +0000
  Re: Windows? owl <owl@rooftop.invalid> - 2016-02-16 20:05 +0000
    Re: Windows? "Ezekiel" <zeke@nosuchemail.com> - 2016-02-16 15:34 -0500
      Re: Windows? owl <owl@rooftop.invalid> - 2016-02-16 21:05 +0000
        Re: Windows? "Ezekiel" <zeke@nosuchemail.com> - 2016-02-16 16:42 -0500
          Re: Windows? owl <owl@rooftop.invalid> - 2016-02-16 22:13 +0000
            Re: Windows? DFS <nospam@dfs.com> - 2016-02-16 19:41 -0500
              Re: Windows? owl <owl@rooftop.invalid> - 2016-02-17 00:49 +0000
                Re: Windows? DFS <nospam@dfs.com> - 2016-02-16 20:05 -0500
        Re: Windows? Desk Rabbit <me@example.com> - 2016-02-17 14:16 +0000
          Re: Windows? owl <owl@rooftop.invalid> - 2016-02-17 18:59 +0000
  Re: Windows? John Gohde <john.h.gohde@gmail.com> - 2016-02-17 05:11 -0800

csiph-web