3 ms·
> if they had backups? I would put a delay in ransomware so it sneaks in weekly and monthly backups, and only then trigger it. If stuff gets restored, sneaked
by auslander 7y ago
> if they had backups?
I would put a delay in ransomware so it sneaks in weekly and monthly backups, and only then trigger it. If stuff gets restored, sneaked warez will activate again. I bet backups are overwritten after several months.
- beagle3 7y agoSuch a thing is likely to happen but it is much more target specific (e.g. my office backs up data, not code, so you would have to find something scripted that’s in use for that to work on my office) so it will likely happen only if the Low hanging fruits (generic attacks that need much less customization) aren’t lucrative anymore.
- auslander 7y ago> my office backs up data, not code No user's apps? No Registry? Ok, sneak it in Word document then. This delay thing can be applied wholesale, not targeted.
- beagle3 7y agoeverything is backed up for reference, but only data is ever restored. Macro execution is supposed to be disabled on Word/Excel, though I trust that less (and there’s always the issue of some unpatched/zeroday); however, to go through here is more expensive for attackera because much more individual targeting and customization is required.
- auslander 7y agoGood practice. I'm just playing around, devil's advocate.
- AnIdiotOnTheNet 7y agoIt is difficult to imagine people who are heavy Excel users being ok with macros being disabled wholesale.
- beagle3 7y agoIndeed, they are not heavy excel users. Which is sort of the point: the need for targeted attacks greatly reduces and segments the addressable “market” for the bad guys.
- auslander 7y agoNah. Point stands, attack can survive the restore inside Office docs because macros are generally allowed.