• Published May 10, 2017
  • 0 0

It’s 7:30 a.m. on a Monday morning. As I walk into the office , someone calls me to tell me they can’t find their documents. I check the user’s PC and find corrupted files with a suspiciously uniform naming scheme. Looking further, I realise that there’s a shortcut conveniently placed in each folder named “how to unlock your files.html”, or at least something like that. Clicking on it, I’m greeted by a price the perpetrators want to charge: 1 Bitcoin. That’s R13000 in South African Rands. I check my backup drives and both are encrypted as well . The server’s image backups (basically a snapshot of the entire server at any given point) are on both drives. My heart sinks at the sheer terror of the situation.

Yes, this is the one situation I never wanted to be in, my work server got hit by ransomware.

The whole setup appears like a scam. Some googling results in searches saying things like “Don’t pay, they won’t release your files.”, or “I paid and never got my documents back. There was no backup.” I phone my company’s server support provider. They send someone within the hour. We do a sweep of the network and find that the ransomware didn’t perpetrate through the desktops. It got in some other way. The only other place could be through the open Remote Desktop port (3389) that allows us remote access via the internet.

The impact assessment was as grim as expected: Payroll files were locked, all accounting data encrypted and all user documents sealed . Payroll was 2 weeks away, so there was enough time to recover information and get the systems up again at least.

This is where things got hairy. The server on-site hosted a DHCP server*, SQL server**, payroll installation and access control database. Backups for all these items were encrypted and the hackers could’ve had time to access this information from the Friday the server was attacked.

The technician from the support provider took the server to his office where they proceeded to try and decrypt its contents. Two days pass and we hear of no progress. I ask some questions: How did the antivirus package not prevent this ransomware from getting in? If the desktops were not hit, why was the server only affected? How did the attack happen? What about the network vulnerabilities? Are there any worth plugging immediately?

Related Article SA Top 10 Report - 9 - 11 June '17

No answers came when I raised the issue of an open RDP port to the internet, nor of the single VPN license (Virtual Private Network) , we could use to add a layer of protection. Instead, changing the admin account password was their solution. To say I was feeling a little despondent was an understatement.

Fast forward two weeks and we got our payroll data back and one backup drive was decrypted. Backups from a separate provider helped us get two major systems back, but the user data only came back a week later. It turned out that the image restore failed and the disks were not mounting correctly. You know what was even more frightening? The decryption key was 256 characters long. Imagine how long it would’ve taken a regular PC to decrypt it considering it takes most servers a day to unlock a key half that size? A further four days worth of work had to be done to ensure the server was working again. None of this was tested prior to the incident. Even when using decryption tools provided by Avast and other anti-virus developers, we still struggled to get the data decrypted.

The type of ransomware used against us.

There were several lessons I gained from this experience:

1. Keep several backup providers for different subsystems

The additional payroll backup saved me from getting fired, and we were successfully able to pay our employees. Had this not been done there, there would’ve been many more issues to face long-term – one of which would’ve been me and others not being paid.

2. Backup to different media wherever possible

Backup to your external hard disk and to the cloud where you can. Working documents are the most critical part of any business. Any information like application licenses and keys are also important for safe keeping. For emails, archive to Mimecast or other providers. This will go a long way to protecting your information in the case of these kinds of attacks. Google and Microsoft both have great archiving capabilities . OneDrive is another service that one can use to back their data up to prevent data loss. Avoid using PST files wherever possible, and try to use IMAP accounts while pushing emails to an archiving service. If you’re a home user – stick to Gmail . The space you get with a free account is worth the tradeoff you make for letting Google see your information. You’ll thank me later.

Related Article The Mummy

3. Don’t rely on your backup and server support provider to bring you back up

Promises are great. Delivering on them in time is even better. Until you’ve had disaster recovery testing done properly, don’t expect everything to go smooth in case of failure. Insist on DR testing, and more-so insist on seeing the results every 3 months. This goes for home users too. Knowing how to reinstall your operating system and doing so every few months to ensure smooth operation can make the difference between minor inconvenience and total catastrophe. If worst comes to worst, have another computer ready to fill the important roles of your server just in case.

4. Have a backup plan in case you lose a system

Have a spare laptop with office loaded? Keep it ready in case your desktop fails. Have a DHCP server in your office? Set up a spare Linux box with a desktop so your internet is still accessible. Linux Lite and some googling will give you a decent chance at being able to work if you have software dependencies. Better yet, run a separate backup of your data on a desktop not related to your server for all essential data. Have that backed up to the cloud as a safety net? Small measures make for big recoveries. How big is your Steam library? Are your save games backed up on a gaming service like PSN? Anything remotely valuable must be kept somewhere.

Image credit: http://www.bellemaisoninc.com

5. Expect the worst

I didn’t anticipate being hit by ransomware. Nor did I expect that my service provider would take just over three weeks to get my systems back up. Ask yourself “What’s the worst that can happen?”, then work out what you can do in each situation. It goes a long way to protect oneself from these challenges by preparing for the worst.

6. Install a strong Anti-virus

Most antivirus programs will work for you. Bitdefender is a well-reputed security application but can still be exploited. Malwarebytes has recently started building their own all-in-one protection system, and Webroot is becoming a strong contender in the security space. ESET’s NOD32 is also a reliable solution. Sophos Intercept X is also another solution which proposes protection against ransomware. Avoid a free solution wherever you can. The payment on a solid security program can mean the difference between weeks of downtime versus a day.

Related Article Geeky Goods Review: DC Collectibles Alex Ross Joker & Harley Quinn Statue

7. Educate family and users

If a mail seems suspicious, it’s probably malicious. Well-built anti-spam filters like Mimecast or Google’s will filter out most of the evil stuff on the internet. Clicking links just because they might appear interesting is a particularly bad thing to do too. If you, a user or your family ever do open up one of these links – you’re asking for trouble. Ensure that the people around you are security aware. Use complex passwords and discourage lazy attempts like Pass123.

This was a hard lesson I refuse to go through again. Protection and prevention remain the best things to do for you and your business. Security is a serious business and now that everyone has internet access – the risks are even greater. I understand this article is a little more serious than your usual Geek Node digest – but it’s one worth reading through, at least in my view.

The following two tabs change content below. - Bio

  • Latest Posts

plut

Gaming / Tech / Entertainment Author at Geek Node

Zubayr could be defined as any one of these traits: Grizzled, optimistic, jaded, blunt, opinionated, irreverent and reserved. His experience was once carbon dated to the glory days of Doom and Duke Nukem 3D. It still amazes him how irrelevant those have become these days.Some say his tears generate DLC unlock codes, and that the WASD combination was discovered by his typo while on Yahoo Chat.

Latest posts by plut ( see all )

- Tech Review: Razer Deathadder Elite – The Spartan - July 5, 2017

- Video Game Review: DiRT 4: How Codemasters code their groove back - June 20, 2017

- Tech Review: HP Spectre 13: The Professional - June 14, 2017

- Tech Review: Acer Swift 7 – Acer’s new fitness model - June 7, 2017

- Tech Review: Lenovo Y700 Gaming Laptop - May 31, 2017

Article Tags: computers · cryptolocker · featured · PC · ransomware · tech

Article Categories: Tech Feature