Close
Page 2 of 6 FirstFirst 123456 LastLast
Results 11 to 20 of 55
  1. #11
    If I had a son he would look like....Ben SideShow Bob's Avatar
    Join Date
    Mar 2010
    Location
    SE Aurora
    Posts
    7,121

    Default

    Quote Originally Posted by Eric P View Post
    So I have been dealing with this the past few days.

    https://www.denverpost.com/2018/02/2...nsomware-cdot/

    My computer as well as the majority of pcs in the building are infected. Many state employees sitting around unable to work since we rely on electronic data so much. The push to go paperless is backfiring.

    And we all got new systems in the past 2 months.

    Sounds like someone hacked in using a vendors account vs someone opening a files sent to them.

    8 bitcoin per computer
    Yep, rumors are that we will need to go back to the pre-SAP “Green Sheets” for a little while,

    Wonder how February’s payroll is going to be handled ? And the OT that is due this month... And of course the OT that I have racked up this month..... And the fiasco of the bi-monthly pay implimtation that is coming soon.
    Last edited by SideShow Bob; 02-24-2018 at 11:35.
    My T.P. wheeling and dealing feedback is here.

    Opinions are like assholes, everybody has one, and it stinks more than mine.


    Yo Homie, That my chainsaw ?



    Pati, improbe et vince

  2. #12
    Machine Gunner
    Join Date
    Mar 2013
    Location
    Highlands Ranch
    Posts
    1,960

    Default

    Quote Originally Posted by Zundfolge View Post
    So by today's valuation that's $81,000 per computer.

    At this point just wipe all the computers and start from scratch, it would be cheaper.
    They are wiping infected computers now. But still have just started at HQ. I'm guessing at least a month before all is fixed.

  3. #13
    Possesses Antidote for "Cool" Gman's Avatar
    Join Date
    Oct 2005
    Location
    Puyallup, WA
    Posts
    17,848

    Default

    Quote Originally Posted by Eric P View Post
    They are wiping infected computers now. But still have just started at HQ. I'm guessing at least a month before all is fixed.
    Wow. A month? They could really use some automation.

    Were the users given least privileged accounts or was everyone a local Admin? Hopefully there weren't any users connected to a network file share with permissions to modify the files.
    Liberals never met a slippery slope they didn't grease.
    -Me

    I wish technology solved people issues. It seems to just reveal them.
    -Also Me


  4. #14
    a cool, fancy title hollohas's Avatar
    Join Date
    Mar 2010
    Location
    Littleton
    Posts
    6,072

    Default

    CDOT has 2000+ employee computers?

  5. #15
    Machine Gunner
    Join Date
    Mar 2013
    Location
    Highlands Ranch
    Posts
    1,960

    Default

    Quote Originally Posted by Gman View Post
    Wow. A month? They could really use some automation.

    Were the users given least privileged accounts or was everyone a local Admin? Hopefully there weren't any users connected to a network file share with permissions to modify the files.

    Not sure exactly what you are asking. But we can not install software without IT connecting to and installing it. Exception is advertised software on the servers.

    The virus was pushed to user pcs from the server. Not all systems were affected.

    I'm guessing on the time based on how many pcs need cleaning and how long it took to roll out the new pcs.

    And yes there are over 2000 computers at CDOT. I think it's approximately 3600 employees.
    Last edited by Eric P; 02-24-2018 at 14:00.

  6. #16
    BANNED....or not? Skip's Avatar
    Join Date
    Jan 2013
    Location
    Highlands Ranch, CO
    Posts
    3,871

    Default

    Quote Originally Posted by hollohas View Post
    CDOT has 2000+ employee computers?
    This does tell an interesting story about a agency whose job is to maintain roads (not something like administer benefits). Unless the roads are maintained by computer, then it makes sense. But I think we're a few years off from that.

    What AV was CDOT using?
    Always eat the vegans first

  7. #17
    Machine Gunner
    Join Date
    Jun 2010
    Location
    Conifer
    Posts
    1,473

    Default

    I'm part of the security team responding to this incident; not really good for those involved to talk about it while the incident is still in process. I haven't seen anything sensitive posted so far, but thought I would just post a friendly warning.
    I predict future happiness for Americans if they can prevent the government from wasting the labors of the people under the pretense of taking care of them.
    Thomas Jefferson

    Feedback

  8. #18
    BANNED....or not? Skip's Avatar
    Join Date
    Jan 2013
    Location
    Highlands Ranch, CO
    Posts
    3,871

    Default

    Understood.

    When this is over, if someone can tell me what AV to avoid, I'd appreciate it.
    Always eat the vegans first

  9. #19
    Possesses Antidote for "Cool" Gman's Avatar
    Join Date
    Oct 2005
    Location
    Puyallup, WA
    Posts
    17,848

    Default

    Quote Originally Posted by Skip View Post
    This does tell an interesting story about a agency whose job is to maintain roads (not something like administer benefits). Unless the roads are maintained by computer, then it makes sense. But I think we're a few years off from that.

    What AV was CDOT using?
    It's in the link above. They are running McAfee. CDOT provided a sample to McAfee and the crypto malware was found to be a new variant which McAfee provided a new DAT to catch.

    You can get hit no matter the AV solution. I've managed McAfee in an environment of over 16k systems and it's a good product, but it's only as good as the person managing all of the variables to best suit the environment.

    If you're allowing autorun on drives, which includes mapped network drives, it only takes one system to drop an autorun file on the network share to infect all systems using that network share. Ran into that when McAfee kept cleaning an autorun file accessed over the network when Trend AV wasn't catching the infected file on the file server.

    Sent from my SM-T700 using Tapatalk
    Last edited by Gman; 02-24-2018 at 14:59.
    Liberals never met a slippery slope they didn't grease.
    -Me

    I wish technology solved people issues. It seems to just reveal them.
    -Also Me


  10. #20
    Zombie Slayer kidicarus13's Avatar
    Join Date
    Nov 2007
    Location
    Littleton
    Posts
    6,309

    Default

    Quote Originally Posted by MED View Post
    I'm part of the security team responding to this incident; not really good for those involved to talk about it while the incident is still in process. I haven't seen anything sensitive posted so far, but thought I would just post a friendly warning.
    FASTER!

    jk
    Lessons cost money. Good ones cost lots. -Tony Beets

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •