4 ms·
Everything you need to know about the WannaCry / Wcry / WannaCrypt ransomware
- gbajson 9y agoThe title of this post is just annoying. "Everything you need to know...". Really? Everything? Will anything wrong happen if I will be a bit more curious than The Author?
- nv-vn 9y agoWhat I still haven't had answered is how does the infection actually spread? The bottom of this article says not to open email attachments, but also mentions closing certain ports. Is this being activated accidentally by the users or is it spreading by some exploit?
- medmunds 9y ago"The malware spread via SMB... used by Windows machines to communicate with file systems over a network. An infected machine would then propagate the infection to other at-risk boxes [that have] not received the critical MS-17-010 security patch from Microsoft which was issued on the 14th of March ... In other words, you had to be almost 2 months behind in your patch cycle in order to get hit with this. Windows 10 machines were not subject to the vulnerability..." More details starting about a quarter of the way into the article.
- iamcreasy 9y agoI am running Windows 10 1607 with build 14393.1198. My system update history says the latest update was "2017-05 Cumulative Update for Windows 10 Version 1607 for x64-based Systems (KB4019472)". How to I verify if I have MS17-010 update installed? Do I need to upgrade my windows 10 1703(Creator's update) to get this patch automatically?
- detaro 9y agothe patch is from march, way older than the creators update. If you want to make sure, go to https://technet.microsoft.com/en-us/library/security/ms17-010.aspx https://technet.microsoft.com/en-us/library/security/ms17-01..., look up the patch numbers (KB4013...) and check if you have one of them in your update history.
- iamcreasy 9y agoIf anyone is wondering these are instructions[1] to check if you have MS17-010 update, and how to stop the attack vector[2]. [1] : https://superuser.com/questions/1208741/how-to-check-if-a-specific-windows-security-update-is-installed/1208772#1208772 https://superuser.com/questions/1208741/how-to-check-if-a-sp... [2] : http://stackoverflow.com/questions/43952057/how-to-protect-from-wcrypt-wanna-cry http://stackoverflow.com/questions/43952057/how-to-protect-f...
- rattray 9y agoIt's still unclear to me why this spread so much wider & faster than other exploits.
- Omnius 9y agoAs soon as one machine is infected it will use windows shares to infect any other machine on the network that is vulnerable, without those users needing to do anything wrong. If you're un-patched anyone on the network gets infected you are infected. HTH
- rattray 9y agoYes, that helped – thanks! I had assumed that such a behavior would be common among worms; I guess Windows security must be generally better than I'd thought.
- dreish 9y agoThe article points out that the phone-home domains this ransomware uses were generated by keyboard-mashing. Can we tell what keyboard layout was used?
- oferzelig 9y agoNot really
- maerF0x0 9y agoIs it possible to just refuse the bitcoins that have this wallet in the ledger? That way they cannot spend the BTC they ransomed?