Ransomware threat: Get patched, find a firewall or upgrade fast

May 15, 2017

New Delhi, May 15: It was coming. On March 14 this year, Microsoft released a security update which addressed the vulnerability in the 16-year-old Windows XP operating system that the hackers behind the massive ransomware attack exploited and created havoc in 150 countries.

wannacry

The vulnerability in the Microsoft Windows software — exploited by “WannaCrypt” — crippled computers from hospitals in Britain to police stations in India, with hackers demanding hundreds of dollars from the users for them to regain control over their data.

Once Microsoft released the patch for the vulnerability — exploited by hacker group “Shadow Brokers” after stealing a software from the US National Security Agency (NSA) — some Window XP users installed the update called “Microsoft Security Bulletin MS17-010” on their desktops and laptops.

But several didn"t.

There are nearly 150 million computers running Windows XP operation system globally. Those who didn"t pay heed to the Windows XP patch are the ones who have fallen prey to the world"s biggest ransomware attack.

Microsoft which had discontiued security updates to its out-of-date software, has also provided a security update for all customers using Windows 8 and Windows Server 2003, anticipating further attacks on these earlier platforms being used by millions.

According to the company, “customers who are running supported versions of the operating system (Windows Vista, Windows Server 2008, Windows 7, Windows Server 2008 R2, Windows 8.1, Windows Server 2012, Windows 10, Windows Server 2012 R2, Windows Server 2016) will have received the security update MS17-010 in March.

“If customers have automatic updates enabled or have installed the update, they are protected. For other customers, we encourage them to install the update as soon as possible,” said Phillip Misner, Principal Security Group Manager, Microsoft Security Response Centre, in a statement.

Meanwhile, “WannaCrypt” locked up machines, encrypted files and demanded approximately $600 in Bitcoin for a recovery key.

According to global cyber security firms, paying heed to updates can only save your data from being put to ransom.

“Install the official patch from Microsoft that closes the vulnerability used in the attack. Ensure that security solutions are switched on all nodes of the network. If Kaspersky Lab"s solution is used, ensure that it includes the "System Watcher", a behavioural proactive detection component and that it is switched on,” Altaf Halde, Managing Director of Kaspersky Lab (South Asia), told.

“Run the "Critical Area Scan" task in Kaspersky Lab"s solution to detect possible infection as soon as possible (otherwise it will be detected automatically, if not switched off, within 24 hours),” he added.

According to Subhendu Sahu, Acting Country Manager for India, FireEye, the ransomware poses high risks to organisations using potentially vulnerable Windows machines.

“We can certainly expect follow-on attacks. Organisations seeking to take risk management steps related to this campaign should install the latest Windows patches. They should also use the indicators of compromise which are associated with this activity. FireEye has also taken steps to help secure its customers,” Sahu told.

As investigators were working to track down those responsible for the ransomware attack, Microsoft President and Chief Legal Officer Brad Smith said the governments should treat this attack as a “wake-up call”.

The news led software security providers to ramp up anti-malware software.

“Upon learning of these incidents, McAfee quickly began working to analyse samples of the ransomware and develop mitigation guidance and detection updates for its customers. McAfee has subsequently provided DAT (that contain data in text or binary format) updates to all its customers and provided them and the public further analysis on the attacks,” Ian Yip, Chief Technology Officer, Asia Pacific, McAfee, told.

If you are a home Windows XP user, patch immediately follow up with an upgrade. If you are running a vulnerable system and cannot install the patch for some reason, try doing the following:

“Disable SMBv1 (a server component) with the steps documented at "Microsoft Knowledge Base Article 2696547" and as recommended previously. Consider adding a rule on your router or firewall to block incoming Server Message Block (SMB) traffic on port 445,” said a report in the technology website Engadget.

“This is big and set to get bigger. We haven"t seen anything like this since Conficker in 2008,” Amit Nath, Head of Asia Pacific-Corporate Business at cyber security firm F-Secure Corporation, told IANS.

The Conficker worm infected millions of computers including government, business and home computers in over 190 countries.
Always make sure your files are backed up.

“That way, if they become compromised in a ransomware attack, you can wipe your disk drive clean and restore the data from the backup. Using Cloud storage with anti-virus scanning abilities to share files will help users to mitigate any possible threats,” suggested Anand Ramamoorthy, Managing Director, South Asia, McAfee.

Remember this: “WannaCrypt” probably won"t work across the internet for PCs behind a firewall or router.

“But if a server is connected directly to the internet or a PC is on the same network as an infected computer, it can spread quickly — which is exactly what has happened,” the Engadget report added.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
Agencies
April 17,2020

New Delhi, Apr 17: The Indian Railways turned 167 years old on Thursday and for the first time ever, its trains did not carry any passengers on its birthday and instead stood idle in the yards waiting for the nationwide lockdown to end.

On this day 167 years ago, the wheels of the first passenger train in the country from Mumbai to Thane started rolling.

In 1974, Indians experienced life without trains for the first time. In May 1974 during the strike of the railways that lasted for around three weeks, drivers, station masters, guards, track staff and many others went on 'chakka jam' demanding fixed working hours for train drivers and an across-the-board pay hike.

"I can recall those times vividly. I remember that our leader George Fernandes had almost secured a deal with the then railway minister, but it fell through when it was taken to the then Prime Minister Indira Gandhi," All India Railwaymens Federation General Secretary Shiv Gopal Mishra, who was an apprentice in the railways at that time, told PTI.

"Fernandes was arrested in Lucknow. The workers went through a lot at that time. But those were days that angry workers had refused to give in and took great risks to get their demands met," he said.

However, just like this time, four decades ago too freight trains carrying essential supplies were run and the unions agreed to let some passenger trains run on the trunk routes like the Kalka Mail from Howrah to Delhi.

"Never ever in its history, there has been such a long interruption of services. Not during the World Wars, not during the 1974 railway strike, or any other national calamity or natural disaster," a railway spokesperson said.

The first Indian Railways passenger train was flagged off on April 16, 1853, from Mumbai to nearby Thane.

On Thursday, the Railway Ministry wished the railways a happy birthday on Twitter - "Today, 167 years ago with the zeal of 'never to stop' the wheels of the first passenger train from Mumbai to Thane started rolling. For the first time, passenger services are stopped for your safety. Stay indoors & make the nation victorious," it said.

Railway has suspended all passenger services since March 25 till May 3 due to the coronavirus outbreak. Around 15,523 trains run by the railways have been affected including 9,000 passenger trains and 3,000 mail express services which are run daily. It caters to over 20 million passengers every day.

According to the Union health ministry, the death toll due to coronavirus rose to 414 and the number of cases to 12,380 in the country on Thursday.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
Agencies
June 24,2020

New Delhi, Jun 24: The Centre has made it mandatory for sellers to enter the 'Country of Origin' while registering all new products on government e-marketplace (GeM).

The e-marketplace is a special purpose vehicle (SPV) under the Ministry of Commerce and Industry which facilitates the entry of small local sellers in public procurement, while implementing 'Make in India' and MSE Purchase Preference Policies of the Centre.

Accordingly, the ministry said the move has been made to promote 'Make in India' and 'Atma Nirbhar Bharat'.

The provision has been enabled via the introduction of new features on GeM.

Besides the registration process, the new feature also reminds sellers who have already uploaded their products, to disclose their products' 'Country of Origin' details.

The ministry further said that failing to disclose the detail will lead to removal of the products from the e-marketplace.

"GeM has taken this significant step to promote 'Make in India' and 'Aatmanirbhar Bharat'," the ministry said in a statement.

"GeM has also enabled a provision for indication of the percentage of local content in products. With this new feature, now, the 'Country of Origin' as well as the local content percentage are visible in the marketplace for all items. More importantly, the 'Make in India' filter has now been enabled on the portal. Buyers can choose to buy only those products that meet the minimum 50 per cent local content criteria."

In case of bids, the ministry said that buyers can now reserve any bid for a "Class I Local suppliers. For those bids below Rs 200 crore, only Class I and Class II Local Suppliers are eligible to bid, with Class I supplier getting purchase preference".

In addition to this, the Department for Promotion of Industry and Internal Trade (DPIIT) has reportedly called for a meeting with all e-commerce companies such as Amazon and Flipkart to display the country of origin on the products sold on their platform, as well as the extent of value added in India.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.
News Network
June 18,2020

Beijing, Jun 18:  Besides washing hands and wearing masks, it is also important to close the toilet lid before flushing to contain the spread of COVID-19, as per a new study.

According to a new study cited by The Washington Post, scientists who simulated toilet water and airflows, have found that flushing a toilet can generate a plume of virus-containing aerosol particles that is widespread and can linger in the air long enough to be inhaled by others. The novel coronavirus has been found in the faeces of COVID-19 patients, but it remains unknown whether such clouds could contain enough virus to infect a person.

"Flushing will lift the virus up from the toilet bowl," co-author Ji-Xiang Wang, who researches fluids at Yangzhou University in Yangzhou, China, said in an email. Wang stressed that bathroom users "need to close the lid first and then trigger the flushing process" and wash hands properly if the closure is not possible. As one flushes the toilet with the lids open, bits of faecal matter swish around so violently that they can be propelled into the air, become aerosolised and then settle on the surroundings.

Experts call it the "toilet plume".Age-old studies have been made to understand the potential for airborne transmission of infectious disease via sewage, and the toilet plume's role. Scientists who have seeded toilet bowls with bacteria and viruses have found contamination of seats, flush handles, bathroom floors and nearby surfaces. This is one reason we are told to wash our hands after visiting the toilet. Public bathrooms are well known to contribute to the spread of viruses that transmit via ingestion, such as the noroviruses that haunt cruise ships. However, their role in the transmission of respiratory viruses has not been established, said Charles P Gerba, a microbiologist at the University of Arizona."The risk is not zero, but how great a risk it is, we do not know. The big unknown is how much virus is infectious in the toilet when you flush it ... and how much virus does it take to cause an infection," said Gerba, who has studied the intersection of toilets and infectious disease for 45 years.

A study published in March in the journal Gastroenterology found significant amounts of coronavirus in the stool of patients and determined that viral RNA lasted in faeces even after the virus cleared from the patients` respiratory tracts. While another study in the journal Lancet found coronavirus in faeces up to a month after the illness had passed.

Scientists around the world are now studying sewage to track the spread of the virus. According to the researchers, the presence of the virus in excrement and the gastrointestinal tract raises the prospect of transmission via toilets, because many COVID-19 patients experience diarrhoea or vomiting.

A study of air samples in two hospitals in Wuhan, China found that although coronavirus aerosols in isolation wards and ventilated patient rooms were very low, "it was higher in the toilet areas used by the patients".The Centers for Disease Control and Prevention (CDC) says it remains "unclear whether the virus found in faeces may be capable of causing COVID-19," and "there has not been any confirmed report of the virus spreading from faeces to a person".For now, the CDC characterises the risk as low based on observations from previous outbreaks of other coronaviruses such as severe acute respiratory syndrome (SARS) and the Middle East respiratory syndrome (MERS). Wang decided to use computer models to simulate toilet plumes while isolating at home, as per Chinese government orders and thinking about how a fluids researcher "could contribute to the global fight against the virus".

Published in the journal Physics of Fluids, the study found that flushing of both single-inlet toilets, which push water into the bowl from one port, and annular-inlet toilets, which pour water into the bowl from the rim's surrounding edge with even greater energy, results in "massive upward transport of virus".

Particles can reach heights of more than three feet and float in the air for more than a minute, it found. The paper recommends not just lid-closing and hand-washing, it urges manufacturers to produce toilets that close and self-clean automatically. It also suggests that toilet-users should wipe down the seat. Gerba, however, said seats should not be a major concern.

Research has found that public and household toilet seats are typically the cleanest surfaces in restrooms, he said, probably because so many people already wipe them off before using them. Also, he said of SARS-CoV-2, the virus that causes COVID-19, "I don't think it's butt-borne, so I don`t think you have to worry."Gerba, who has been studying coronavirus transmission for two decades to investigate the role of a toilet flushing in a SARS outbreak stresses "flush and run" when using a public toilet without a lid. Gerba also said that people should wash hands well post-flushing and use hand sanitiser after leaving the restroom. "Choose well-ventilated bathrooms if possible and do not hang around the restroom in any case," added Gerba.

Comments

Add new comment

  • Coastaldigest.com reserves the right to delete or block any comments.
  • Coastaldigset.com is not responsible for its readers’ comments.
  • Comments that are abusive, incendiary or irrelevant are strictly prohibited.
  • Please use a genuine email ID and provide your name to avoid reject.