NHS England hit by cyber attack, phone and IT systems down

Fed up talking videogames? Why?
User avatar
Kezzer
Member
Joined in 2012

PostRe: NHS England hit by cyber attack, phone and IT systems down
by Kezzer » Fri May 12, 2017 5:57 pm

yeah Iberdrola were hit too.

This post is exempt from the No Context Thread.

Tomous wrote:Tell him to take his fake reality out of your virtual reality and strawberry float off


Image
Image
Image
User avatar
Dual
Member
Joined in 2008

PostRe: NHS England hit by cyber attack, phone and IT systems down
by Dual » Fri May 12, 2017 5:58 pm

This is why we should privatise the nhs

User avatar
Lex-Man
Member
Joined in 2008
Contact:

PostRe: NHS England hit by cyber attack, phone and IT systems down
by Lex-Man » Fri May 12, 2017 6:00 pm

Dual wrote:This is why we should privatise the nhs


And allow the government to circumvent all our encryption so they can work out who did it.

Amusement under late capitalism is the prolongation of work.
User avatar
satriales
Member
Joined in 2008

PostRe: NHS England hit by cyber attack, phone and IT systems down
by satriales » Fri May 12, 2017 6:01 pm

Denster wrote:For the last 20 yrs.

Awesome. It's just surprising as you're so pro-Tory, but this isn't the politics topic so I'll say no more.

User avatar
Denster
Member
Member
Joined in 2008

PostRe: NHS England hit by cyber attack, phone and IT systems down
by Denster » Fri May 12, 2017 6:05 pm

satriales wrote:
Denster wrote:For the last 20 yrs.

Awesome. It's just surprising as you're so pro-Tory, but this isn't the politics topic so I'll say no more.


:lol:

Yeah I get that a lot.

User avatar
False
COOL DUDE
Joined in 2008

PostRe: NHS England hit by cyber attack, phone and IT systems down
by False » Fri May 12, 2017 6:06 pm

lex-man wrote:They just hit ip addresses until they find a vulnerable target.


Actually they usually come as a concealed email attachment. You can mask almost any executable as a Word macro.

Image
User avatar
Errkal
Member
Joined in 2011
Location: Hastings
Contact:

PostRe: NHS England hit by cyber attack, phone and IT systems down
by Errkal » Fri May 12, 2017 6:28 pm

lex-man wrote:
Errkal wrote:
lex-man wrote:
Errkal wrote:
lex-man wrote:They just hit ip addresses until they find a vulnerable target.


The NHS sites inside its own network isolated from the Internet, they connect via a number of very restricted gateways, some trusts have internet gateways but most dont, so this is more targetted than that.


Do you work in it for the NHS because that wasn't my experience?


Yup, IT for like 11 years or so.


Where I worked two and a half years ago all of our front facing machines had internet access. It was all replaced by visualised desktops running off servers but still very much hooked up to the internet.

The guardian article mentions that it the mail sever was the first place to get hit.


In a message to a Guardian reporter, one NHS IT worker said: “At approximately 12.30pm we experienced a problem with our email servers crashing. Following this a lot of our clinical systems and patient systems were reported to have gone down.


They also mention it wasn't an attack targeting the NHS specifically.

“This attack was not specifically targeted at the NHS and is affecting organisations from across a range of sectors.


https://www.theguardian.com/society/201 ... ber-attack

So I still stand by my comment.


They have internet access, because n3 goes to the web via some gateways, what I mean is a trusts networks is a secured network within n3 that is a secured network from the internet, you can get to the web getting getting in is very hard. So this would need to be more targeted to get someone to start something that lets you in.

You can direct host vpn, web servers via n3, trusts have their own internet lines for them but they aren't use for internet usually, N3 is.

User avatar
Kezzer
Member
Joined in 2012

PostRe: NHS England hit by cyber attack, phone and IT systems down
by Kezzer » Fri May 12, 2017 7:25 pm

nested networks!

it's networks all the way down!

This post is exempt from the No Context Thread.

Tomous wrote:Tell him to take his fake reality out of your virtual reality and strawberry float off


Image
Image
Image
User avatar
Irene Demova
Member
Joined in 2009
AKA: Karl

PostRe: NHS England hit by cyber attack, phone and IT systems down
by Irene Demova » Fri May 12, 2017 7:33 pm

Man now the worst episode of The Good Wife is actually relevent

User avatar
Lagamorph
Member ♥
Joined in 2010

PostRe: NHS England hit by cyber attack, phone and IT systems down
by Lagamorph » Fri May 12, 2017 8:12 pm

FedEx in America has now been hit.

There are also rumours that the cause of the attack is an NSA tool.

Lagamorph's Underwater Photography Thread
Zellery wrote:Good post Lagamorph.
Turboman wrote:Lagomorph..... Is ..... Right
User avatar
satriales
Member
Joined in 2008

PostRe: NHS England hit by cyber attack, phone and IT systems down
by satriales » Fri May 12, 2017 9:15 pm

Lagamorph wrote:FedEx in America has now been hit.

There are also rumours that the cause of the attack is an NSA tool.


A month or so back a load of NSA hacking tools were released on the internet. One of our customers at work had a server get infected with ransomware from one of those tools, luckily they had a backup so nothing was lost but It wouldn't surprise me to see a lot more of these attacks.

User avatar
Lex-Man
Member
Joined in 2008
Contact:

PostRe: NHS England hit by cyber attack, phone and IT systems down
by Lex-Man » Fri May 12, 2017 9:15 pm

Errkal wrote:
lex-man wrote:
Errkal wrote:
lex-man wrote:
Errkal wrote:
lex-man wrote:They just hit ip addresses until they find a vulnerable target.


The NHS sites inside its own network isolated from the Internet, they connect via a number of very restricted gateways, some trusts have internet gateways but most dont, so this is more targetted than that.


Do you work in it for the NHS because that wasn't my experience?


Yup, IT for like 11 years or so.


Where I worked two and a half years ago all of our front facing machines had internet access. It was all replaced by visualised desktops running off servers but still very much hooked up to the internet.

The guardian article mentions that it the mail sever was the first place to get hit.


In a message to a Guardian reporter, one NHS IT worker said: “At approximately 12.30pm we experienced a problem with our email servers crashing. Following this a lot of our clinical systems and patient systems were reported to have gone down.


They also mention it wasn't an attack targeting the NHS specifically.

“This attack was not specifically targeted at the NHS and is affecting organisations from across a range of sectors.


https://www.theguardian.com/society/201 ... ber-attack

So I still stand by my comment.


They have internet access, because n3 goes to the web via some gateways, what I mean is a trusts networks is a secured network within n3 that is a secured network from the internet, you can get to the web getting getting in is very hard. So this would need to be more targeted to get someone to start something that lets you in.

You can direct host vpn, web servers via n3, trusts have their own internet lines for them but they aren't use for internet usually, N3 is.


Yeah, it probably got in via an email so it may have been sent directly to an NHS mail address. Although it could have just been sent to some bodies web mail account. It's already hit a load of other companies.

Amusement under late capitalism is the prolongation of work.
User avatar
Errkal
Member
Joined in 2011
Location: Hastings
Contact:

PostRe: NHS England hit by cyber attack, phone and IT systems down
by Errkal » Fri May 12, 2017 9:19 pm

Probably a bit of both, from the organisations I've heard from today they have no impact as such other than panicked and shutting gooseberry fool down.

I think most of the impact is just people's over reaction than an actual intrusion.

One of our customers for example got us to shut down all servers, another pulled their n3 connections. All from seeing it on the news.

User avatar
satriales
Member
Joined in 2008

PostRe: NHS England hit by cyber attack, phone and IT systems down
by satriales » Fri May 12, 2017 9:20 pm

If you've done all Windows Updates then you should be safe as it was patched a few weeks ago.

User avatar
Errkal
Member
Joined in 2011
Location: Hastings
Contact:

PostRe: NHS England hit by cyber attack, phone and IT systems down
by Errkal » Fri May 12, 2017 9:22 pm

Amusing most of our customers are a combination of NetWare and OES so have even less to worry about.

User avatar
Lex-Man
Member
Joined in 2008
Contact:

PostRe: NHS England hit by cyber attack, phone and IT systems down
by Lex-Man » Fri May 12, 2017 9:29 pm

satriales wrote:If you've done all Windows Updates then you should be safe as it was patched a few weeks ago.


Here's an article about the ransomwhere you need this patch, it's pretty likely you already have it though

https://arstechnica.co.uk/security/2017 ... ernalblue/

https://technet.microsoft.com/en-us/lib ... aa970312fc)(256380)(2459594)(TnL5HPStwNw-mC26Ai1RgPs8y1VWNfdDKw)()

Amusement under late capitalism is the prolongation of work.
User avatar
False
COOL DUDE
Joined in 2008

PostRe: NHS England hit by cyber attack, phone and IT systems down
by False » Fri May 12, 2017 9:33 pm

If anyone is in the IT biz, it looks to be the shadowbroker vulnerability which is fixed by MS17-010 back in March. If you are behind on your patching then I think you want to disable smbv1 at least.

Image
User avatar
Alvin Flummux
Member
Joined in 2008
Contact:

PostRe: NHS England hit by cyber attack, phone and IT systems down
by Alvin Flummux » Fri May 12, 2017 9:53 pm

satriales wrote:
Lagamorph wrote:FedEx in America has now been hit.

There are also rumours that the cause of the attack is an NSA tool.


A month or so back a load of NSA hacking tools were released on the internet. One of our customers at work had a server get infected with ransomware from one of those tools, luckily they had a backup so nothing was lost but It wouldn't surprise me to see a lot more of these attacks.


Wasn't it Wikileaks who put those tools out there?

Real strawberry floating nice of them. :|

User avatar
satriales
Member
Joined in 2008

PostRe: NHS England hit by cyber attack, phone and IT systems down
by satriales » Fri May 12, 2017 10:18 pm

Gently-Parted Ringpiece wrote:If anyone is in the IT biz, it looks to be the shadowbroker vulnerability which is fixed by MS17-010 back in March. If you are behind on your patching then I think you want to disable smbv1 at least.

The Eternalblue exploit that I saw (and I think is what got the NHS) also targets SMBv2, but some of the other exploits from the same group do target SMBv3.

User avatar
Lagamorph
Member ♥
Joined in 2010

PostRe: NHS England hit by cyber attack, phone and IT systems down
by Lagamorph » Fri May 12, 2017 10:29 pm

It amazes me that even in Server 2016 SMB v1 is still enabled by default.

Lagamorph's Underwater Photography Thread
Zellery wrote:Good post Lagamorph.
Turboman wrote:Lagomorph..... Is ..... Right

Return to “Stuff”

Who is online

Users browsing this forum: D_C, Godzilla, Little Old Man, Met, Monkey Man, shy guy 64, TonyDA, wensleydale and 616 guests