"62 minutes could bring your business down"
I guess they could bring all the businesses down much quicker.
edit: link https://www.crowdstrike.com/en-us/#teaser-79minutes-adversar...
"62 minutes could bring your business down"
I guess they could bring all the businesses down much quicker.
edit: link https://www.crowdstrike.com/en-us/#teaser-79minutes-adversar...
"The issue has been identified, isolated and a fix has been deployed."
Maybe I'm misunderstanding what I read elsewhere, but is the machine not BSODing upon boot, prior to a Windows Update service being able to run? The "fix" I see on reddit is roughly:
Workaround Steps:
1. Boot Windows into Safe Mode or the Windows Recovery Environment
2. Navigate to the C:\Windows\System32\drivers\CrowdStrike directory
3. Locate the file matching “C-00000291*.sys”, and delete it.
I'm horrified at the thought of tens of thousands of novice Windows users digging through System32 to delete driver files; can someone set my mind at ease and assure me this will eventually be fixed in an automated fashion?
https://www.crowdstrike.com/blog/statement-on-windows-sensor...
Their lawyers certainly won't allow mentioning such dramatic (is "dramatic" appropriate here?) consequences.
It's like two hours of work with dnsmasq and a minimal Linux ISO. The only problem is that much of the work is not shareable between organisations; network structures differ, architectures may differ, partition layout may differ, the list of assets (and their MAC addresses) will differ.
Edit: + individual organisations won't be storing their BitLocker recovery keys in the same manner as each other either. You did back up the recovery keys when you enabled BitLocker, right? Modern cryptsetup(8) supports a BITLK extension for unlocking said volumes with a recovery key. Again, this can be scripted.
Because writing such a script (that mounts the filesystem and delete a file) under stress and time constraint is a great idea? That's a recipe for a worse disaster. The best solution, for now, is to go PC by PC manually. The sole reason the situation is as is was the lack of backstage testing.
Nope. Both my orgs (+2000 each) have sent out a Google doc to personal emails on using CMD Prompt to delete that file.
Anyone with technical experience is being drafted to get on calls and help people manually delete this file.
> I guess they could bring all the businesses down much quicker.
It is because the buyer does not get the message. And, when they get it, it is too late.