19
reactor
5y

Just spent the entire day of which should have been the start of vacation fighting off a second wave of ransomware on one of our production servers. Gandcrab 5.2 anyone?

Turns out an exploit in our MySQL daemon allowed some fucking Chinese hackermonkey to upload a trojan and remote execute it. Thousands of angry customers, me the only one available and able to fix shit and patch up firewalls and system.

And now I get the pleasure of working on what I should have been doing today, another fire that MUST be put out today.

Fuck you deadlines. Fuck you Chinese hackers. In fact, FML.

Comments
  • 3
    I experienced Gandcrab 5.1 back in February. Luckily for me, it only effected 1 PC, which had no network shares, so it did not spread past there. Best of luck to you. I hope tomorrow is a better day, and you can enjoy the rest of your vacation.
  • 2
    @Keylan Thanks, I hope the same. Unfortunately there are no decrypt tools available for 5.2, so the only real option is to roll back to a backup and loose everything between the attack and the last backup.
  • 2
    Have no useful advice to offer, but have a ++ for having to sacrifice personal time for work.
Add Comment