Ransomware threat: Get patched, find a firewall or upgrade fast

May 15, 2017

New Delhi, May 15: It was coming. On March 14 this year, Microsoft released a security update which addressed the vulnerability in the 16-year-old Windows XP operating system that the hackers behind the massive ransomware attack exploited and created havoc in 150 countries.

wannacry

The vulnerability in the Microsoft Windows software — exploited by “WannaCrypt” — crippled computers from hospitals in Britain to police stations in India, with hackers demanding hundreds of dollars from the users for them to regain control over their data.

Once Microsoft released the patch for the vulnerability — exploited by hacker group “Shadow Brokers” after stealing a software from the US National Security Agency (NSA) — some Window XP users installed the update called “Microsoft Security Bulletin MS17-010” on their desktops and laptops.

But several didn"t.

There are nearly 150 million computers running Windows XP operation system globally. Those who didn"t pay heed to the Windows XP patch are the ones who have fallen prey to the world"s biggest ransomware attack.

Microsoft which had discontiued security updates to its out-of-date software, has also provided a security update for all customers using Windows 8 and Windows Server 2003, anticipating further attacks on these earlier platforms being used by millions.

According to the company, “customers who are running supported versions of the operating system (Windows Vista, Windows Server 2008, Windows 7, Windows Server 2008 R2, Windows 8.1, Windows Server 2012, Windows 10, Windows Server 2012 R2, Windows Server 2016) will have received the security update MS17-010 in March.

“If customers have automatic updates enabled or have installed the update, they are protected. For other customers, we encourage them to install the update as soon as possible,” said Phillip Misner, Principal Security Group Manager, Microsoft Security Response Centre, in a statement.

Meanwhile, “WannaCrypt” locked up machines, encrypted files and demanded approximately $600 in Bitcoin for a recovery key.

According to global cyber security firms, paying heed to updates can only save your data from being put to ransom.

“Install the official patch from Microsoft that closes the vulnerability used in the attack. Ensure that security solutions are switched on all nodes of the network. If Kaspersky Lab"s solution is used, ensure that it includes the "System Watcher", a behavioural proactive detection component and that it is switched on,” Altaf Halde, Managing Director of Kaspersky Lab (South Asia), told.

“Run the "Critical Area Scan" task in Kaspersky Lab"s solution to detect possible infection as soon as possible (otherwise it will be detected automatically, if not switched off, within 24 hours),” he added.

According to Subhendu Sahu, Acting Country Manager for India, FireEye, the ransomware poses high risks to organisations using potentially vulnerable Windows machines.

“We can certainly expect follow-on attacks. Organisations seeking to take risk management steps related to this campaign should install the latest Windows patches. They should also use the indicators of compromise which are associated with this activity. FireEye has also taken steps to help secure its customers,” Sahu told.

As investigators were working to track down those responsible for the ransomware attack, Microsoft President and Chief Legal Officer Brad Smith said the governments should treat this attack as a “wake-up call”.

The news led software security providers to ramp up anti-malware software.

“Upon learning of these incidents, McAfee quickly began working to analyse samples of the ransomware and develop mitigation guidance and detection updates for its customers. McAfee has subsequently provided DAT (that contain data in text or binary format) updates to all its customers and provided them and the public further analysis on the attacks,” Ian Yip, Chief Technology Officer, Asia Pacific, McAfee, told.

If you are a home Windows XP user, patch immediately follow up with an upgrade. If you are running a vulnerable system and cannot install the patch for some reason, try doing the following:

“Disable SMBv1 (a server component) with the steps documented at "Microsoft Knowledge Base Article 2696547" and as recommended previously. Consider adding a rule on your router or firewall to block incoming Server Message Block (SMB) traffic on port 445,” said a report in the technology website Engadget.

“This is big and set to get bigger. We haven"t seen anything like this since Conficker in 2008,” Amit Nath, Head of Asia Pacific-Corporate Business at cyber security firm F-Secure Corporation, told IANS.

The Conficker worm infected millions of computers including government, business and home computers in over 190 countries.
Always make sure your files are backed up.

“That way, if they become compromised in a ransomware attack, you can wipe your disk drive clean and restore the data from the backup. Using Cloud storage with anti-virus scanning abilities to share files will help users to mitigate any possible threats,” suggested Anand Ramamoorthy, Managing Director, South Asia, McAfee.

Remember this: “WannaCrypt” probably won"t work across the internet for PCs behind a firewall or router.

“But if a server is connected directly to the internet or a PC is on the same network as an infected computer, it can spread quickly — which is exactly what has happened,” the Engadget report added.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
News Network
April 17,2020

Paris, Apr 17: Even as virologists zero in on the virus that causes COVID-19, a very basic question remains unanswered: do those who recover from the disease have immunity?

There is no clear answer to this question, experts say, even if many have assumed that contracting the potentially deadly disease confers immunity, at least for a while.

"Being immunised means that you have developed an immune response against a virus such that you can repulse it," explained Eric Vivier, a professor of immunology in the public hospital system in Marseilles.

"Our immune systems remember, which normally prevents you from being infected by the same virus later on."

For some viral diseases such a measles, overcoming the sickness confers immunity for life.

But for RNA-based viruses such as Sars-Cov-2 -- the scientific name for the bug that causes the COVID-19 disease -- it takes about three weeks to build up a sufficient quantity of antibodies, and even then they may provide protection for only a few months, Vivier told AFP.

At least that is the theory. In reality, the new coronavirus has thrown up one surprise after another, to the point where virologists and epidemiologists are sure of very little.

"We do not have the answers to that -- it's an unknown," Michael Ryan, executive director of the World Health Organization's Emergencies Programme said in a press conference this week when asked how long a recovered COVID-19 patient would have immunity.

"We would expect that to be a reasonable period of protection, but it is very difficult to say with a new virus -- we can only extrapolate from other coronaviruses, and even that data is quite limited."

For SARS, which killed about 800 people across the world in 2002 and 2003, recovered patients remained protected "for about three years, on average," Francois Balloux director of the Genetics Institute at University College London, said.

"One can certainly get reinfected, but after how much time? We'll only know retroactively."

A recent study from China that has not gone through peer review reported on rhesus monkeys that recovered from Sars-Cov-2 and did not get reinfected when exposed once again to the virus.

"But that doesn't really reveal anything," said Pasteur Institute researcher Frederic Tangy, noting that the experiment unfolded over only a month.

Indeed,several cases from South Korea -- one of the first countries hit by the new coronavirus -- found that patients who recovered from COVID-19 later tested positive for the virus.

But there are several ways to explain that outcome, scientists cautioned.

While it is not impossible that these individuals became infected a second time, there is little evidence this is what happened.

More likely, said Balloux, is that the virus never completely disappeared in the first place and remains -- dormant and asymptomatic -- as a "chronic infection", like herpes.

As tests for live virus and antibodies have not yet been perfected, it is also possible that these patients at some point tested "false negative" when in fact they had not rid themselves of the pathogen.

"That suggests that people remain infected for a long time -- several weeks," Balloux added. "That is not ideal."

Another pre-publication study that looked at 175 recovered patients in Shanghai showed different concentrations of protective antibodies 10 to 15 days after the onset of symptoms.

"But whether that antibody response actually means immunity is a separate question," commented Maria Van Kerhove, Technical Lead of the WHO Emergencies Programme.

"That's something we really need to better understand -- what does that antibody response look like in terms of immunity."

Indeed, a host of questions remain.

"We are at the stage of asking whether someone who has overcome COVID-19 is really that protected," said Jean-Francois Delfraissy, president of France's official science advisory board.

For Tangy, an even grimmer reality cannot be excluded.

"It is possible that the antibodies that someone develops against the virus could actually increase the risk of the disease becoming worse," he said, noting that the most serious symptoms come later, after the patient had formed antibodies.

For the moment, it is also unclear whose antibodies are more potent in beating back the disease: someone who nearly died, or someone with only light symptoms or even no symptoms at all. And does age make a difference?

Faced with all these uncertainties, some experts have doubts about the wisdom of persuing a "herd immunity" strategy such that the virus -- unable to find new victims -- peters out by itself when a majority of the population is immune.

"The only real solution for now is a vaccine," Archie Clements, a professor at Curtin University in Perth Australia, told AFP.

At the same time, laboratories are developing a slew of antibody tests to see what proportion of the population in different countries and regions have been contaminated.

Such an approach has been favoured in Britain and Finland, while in Germany some experts have floated the idea of an "immunity passport" that would allow people to go back to work.

"It's too premature at this point," said Saad Omer, a professor of infectious diseases at the Yale School of Medicine.

"We should be able to get clearer data very quickly -- in a couple of months -- when there will be reliable antibody tests with sensitivity and specificity."

One concern is "false positives" caused by the tests detecting antibodies unrelated to COVID-19.

The idea of immunity passports or certificates also raises ethical questions, researchers say.

"People who absolutely need to work -- to feed their families, for example -- could try to get infected," Balloux.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
Agencies
June 22,2020

New delhi, Jun 22: As consumer sentiment runs high amid growing chorus for boycotting Chinese goods in the country, the fluid market situation offers new opportunities for various smartphone makers, especially the non-Chinese ones like Samsung, Apple, Nokia, Asus and others, to realign their strategies and regain the lost market share in the face of fierce Chinese competition.

The challenge here would be not to look "opportunistic" and leverage the current explosive situation on just riding on the anti-Chinese sentiment but to offer real challenges in the form of top-end devices with solid internals at affordable price points, feel industry experts.

"The current market conditions in India are fluid and open up new opportunities for smartphone original equipment manufacturers (OEMs) to focus and leverage," Prabhu Ram, Head-Industry Intelligence Group, CyberMedia Research (CMR), told IANS.

In the first quarter (January-March) this year, Samsung's shipments were driven by its upgraded A and M series (A51, A20s, A30s, and M30s).

According to Counterpoint Research, Samsung managed to hold third position in Q1 2020 due to launches across several price tiers, especially in the affordable premium segment (S10 Lite, Note 10 Lite).

The South Korean smartphone maker last week announced a Rs 4,000 price drop on its popular Galaxy Note10 Lite smartphone that will now cost Rs 37,999 (6GB variant).

Earlier this month, Samsung launched two new smartphones, Galaxy M11 and Galaxy M01, with powerful batteries under Rs 15,000 in India.

Galaxy M11 comes in two variants. The 3GB+32GB will be priced at Rs 10,999 while the higher 4GB+64GB variant will be available for Rs 12,999.

Samsung has also launched an affordable Galaxy A21s smartphone with quad-camera system and 5,000mAh battery at a starting price of Rs 16,499.

Also read: Boycott China? OnePlus 8 Pro sold out within minutes of going on sale

On the other hand, Apple grew a strong 78 per cent YoY driven by strong shipments of iPhone 11 and multiple discounts on platforms like Flipkart and Amazon in Q1, according to Counterpoint.

Apple has also brought its cheapest yet powerful new iPhone SE that costs Rs 38,900 (64GB) in India with a special offer from HDFC Bank. The new iPhone SE is powered by the Apple-designed A13 Bionic, the fastest chip in a smartphone and features the best single-camera system ever in an iPhone.

According to Tarun Pathak, Associate Director, Counterpoint Research, consumer sentiments are running high and a section of users will look for alternatives, benefitting global and Indian brands.

"However, we do not think non-Chinese brands will run aggressive campaigns based on the situation as it might look like being opportunistic," Pathak told media.

It may actually let brands of Chinese origin try to run aggressive campaigns on their presence and scale.

"Some of these Chinese brands have been active in scaling up local value addition, creating jobs and investing in research and development," Pathak noted.

On Saturday, market leader Xiaomi said that it is "more Indian" than any other smartphone brand.

The company's India head Manu Kumar Jain said that the company's mobile phone R&D centre and product team is in India, it employs 50,000 people in the country, the entire leadership team is Indian and that the company pays its taxes in India.

Earlier, Realme India CEO Madhav Sheth who is also very active on social media said that Realme is an Indian startup.

In his latest episode of Ask Madhav' series on YouTube, Sheth said: "I can proudly say Realme is an Indian startup, which is now a global MNC (multinational corporation)".

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
Agencies
May 31,2020

Cape Canaveral, May 31: SpaceX, the private rocket company of billionaire entrepreneur Elon Musk, launched two Americans into orbit from Florida on Saturday in a landmark mission marking the first spaceflight of NASA astronauts from U.S. soil in nine years.

A SpaceX Falcon 9 rocket lifted off from the Kennedy Space Center at 3:22 p.m. EDT (19:22 GMT), launching Doug Hurley and Bob Behnken on a 19-hour ride aboard the company’s newly designed Crew Dragon capsule bound for the International Space Station.

Just before liftoff, Hurley said, “SpaceX, we’re go for launch. Let’s light this candle,” paraphrasing the famous comment uttered on the launch pad in 1961 by Alan Shepard, the first American flown into space.

Minutes after launch, the first-stage booster rocket of the Falcon 9 separated from the upper second-stage rocket and flew itself back to Earth to descend safely onto a landing platform floating in the Atlantic.

High above the Earth, the Crew Dragon jettisoned moments later from the second-stage rocket, sending the capsule on its way to the space station.

The exhilarating spectacle of the rocket soaring flawlessly into the heavens came as a welcome triumph for a nation gripped by racially-charged civil unrest as well as ongoing fear and economic upheaval from the coronavirus pandemic.

The Falcon 9 took off from the same launch pad used by NASA’s final space shuttle flight, piloted by Hurley, in 2011. Since then, NASA astronauts have had to hitch rides into orbit aboard Russia’s Soyuz spacecraft.

“It’s incredible, the power, the technology,” said U.S. President Donald Trump, who was at Kennedy Space Center at Cape Canaveral in Florida for the launch. “That was a beautiful sight to see.”

The mission’s first launch attempt on Wednesday was called off with less than 17 minutes remaining on the countdown clock. Weather again threatened Saturday’s launch, but cleared in time to proceed with the mission.

SPACEFLIGHT MILESTONES

NASA chief Jim Bridenstine has said resuming launches of American astronauts on American-made rockets from U.S. soil is the space agency’s top priority.

“I’m breathing a sigh of relief, but I will also tell you I’m not gonna celebrate until Bob and Doug are home safely.” Bridenstine said.

For Musk, the launch represents another milestone for the reusable rockets his company pioneered to make spaceflight less costly and more frequent. And it marks the first time commercially developed space vehicles - owned and operated by a private entity rather than NASA - have carried Americans into orbit.

The last time NASA launched astronauts into space aboard a brand new vehicle was 40 years ago at the start of the space shuttle program.

Musk, the South African-born high-tech entrepreneur who made his fortune in Silicon Valley, is also chief executive of electric carmaker and battery manufacturer Tesla Inc. He founded Hawthorne, California-based SpaceX, formally known as Space Exploration Technologies, in 2002.

Hurley, 53, and Behnken, 49, NASA employees under contract to fly with SpaceX, are expected to remain at the space station for several weeks, assisting a short-handed crew aboard the orbital laboratory.

Boeing Co, producing its own launch system in competition with SpaceX, is expected to fly its CST-100 Starliner vehicle with astronauts aboard for the first time next year. NASA has awarded nearly $8 billion combined to SpaceX and Boeing for development of their rival rockets.

Trump also hailed the launch as a major advance toward the goal of eventually sending humans to Mars.

He was joined at the viewing by Musk, as well as Vice President Mike Pence, Commerce Secretary Wilbur Ross, Education Secretary Betsy DeVos, Florida congressman Matt Gaetz and Senator Rick Scott.

Earlier on Saturday, the crew bid goodbye to their families. Prior to climbing into a specially designed Tesla automobile for the ride to the launch site, Behnken told his young son, “Be good for mom. Make her life easy.”

During the drive, Behnken and Hurley passed former astronaut Garrett Reisman who held a sign saying, “Take me with you.”

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.