ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    Database held for ransom, anyone experience this before?

    IT Discussion
    11
    20
    1.3k
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • donaldlandruD
      donaldlandru
      last edited by

      Had this forwarded to my desk this morning. This client uses AWS hosted database and found this over the weekend.

      Anyone ever see this before?

      database_ransom.jpg

      JaredBuschJ travisdh1T 2 Replies Last reply Reply Quote 0
      • JaredBuschJ
        JaredBusch @donaldlandru
        last edited by

        @donaldlandru someone is screwed.

        Reid CooperR 1 Reply Last reply Reply Quote 3
        • travisdh1T
          travisdh1 @donaldlandru
          last edited by

          @donaldlandru Should've used stronger password and 2fa. Time to break out the backups.

          JaredBuschJ scottalanmillerS 2 Replies Last reply Reply Quote 1
          • DustinB3403D
            DustinB3403
            last edited by

            Wipe and reload, and of course immediately change the password to something stronger.

            donaldlandruD JaredBuschJ 2 Replies Last reply Reply Quote 0
            • donaldlandruD
              donaldlandru @DustinB3403
              last edited by

              @DustinB3403 said in Database held for ransom, anyone experience this before?:

              Wipe and reload, and of course immediately change the password to something stronger.

              Haha thankfully not ours to fix, but that was the advice. I’d also vote against paying the bitcoin since they’ll “leak” the database either way.

              1 Reply Last reply Reply Quote 1
              • JaredBuschJ
                JaredBusch @travisdh1
                last edited by

                @travisdh1 said in Database held for ransom, anyone experience this before?:

                @donaldlandru Should've used stronger password and 2fa.

                That is not how anything works.

                1 Reply Last reply Reply Quote 1
                • JaredBuschJ
                  JaredBusch @DustinB3403
                  last edited by

                  @DustinB3403 said in Database held for ransom, anyone experience this before?:

                  Wipe and reload, and of course immediately change the password to something stronger.

                  That, or more likely IMO, cleanup the shit code that let them gain access through a SQL injection.

                  1 Reply Last reply Reply Quote 1
                  • scottalanmillerS
                    scottalanmiller @travisdh1
                    last edited by

                    @travisdh1 said in Database held for ransom, anyone experience this before?:

                    Time to break out the backups.

                    That pretty much sums it up.

                    1 Reply Last reply Reply Quote 0
                    • CloudKnightC
                      CloudKnight
                      last edited by

                      ouch....

                      1 Reply Last reply Reply Quote 0
                      • RojoLocoR
                        RojoLoco
                        last edited by

                        All your database are belong to us. Um, them.

                        1 Reply Last reply Reply Quote 4
                        • Reid CooperR
                          Reid Cooper @JaredBusch
                          last edited by

                          @JaredBusch said in Database held for ransom, anyone experience this before?:

                          @donaldlandru someone is screwed.

                          Assuming no backups and that it has sensitive data. Might just be Wordpress posts and public already.

                          donaldlandruD 1 Reply Last reply Reply Quote 0
                          • donaldlandruD
                            donaldlandru @Reid Cooper
                            last edited by

                            @Reid-Cooper said in Database held for ransom, anyone experience this before?:

                            @JaredBusch said in Database held for ransom, anyone experience this before?:

                            @donaldlandru someone is screwed.

                            Assuming no backups and that it has sensitive data. Might just be Wordpress posts and public already.

                            Nah they had backups. Not Wordpress lol

                            1 Reply Last reply Reply Quote 0
                            • 1
                              1337
                              last edited by 1337

                              Sound like this one:
                              https://www.csoonline.com/article/3174306/ransomware-attacks-targeted-hundreds-of-mysql-databases.html

                              According to the article it's a brute force attack on root account of the mysql database.

                              A little more info:
                              https://www.guardicore.com/2017/02/0-2-btc-strikes-back-now-attacking-mysql-databases/

                              Looks like the database is erased without being dumped somewhere so no sense in paying anything.

                              1 Reply Last reply Reply Quote 1
                              • dbeatoD
                                dbeato
                                last edited by

                                What Database type was this? an RDS or hosted inside a server?

                                JaredBuschJ 1 Reply Last reply Reply Quote 0
                                • JaredBuschJ
                                  JaredBusch @dbeato
                                  last edited by

                                  @dbeato said in Database held for ransom, anyone experience this before?:

                                  What Database type was this? an RDS or hosted inside a server?

                                  .....

                                  @donaldlandru said in Database held for ransom, anyone experience this before?:

                                  This client uses AWS hosted database and found this over the weekend.

                                  dbeatoD scottalanmillerS 2 Replies Last reply Reply Quote 0
                                  • dbeatoD
                                    dbeato @JaredBusch
                                    last edited by

                                    @JaredBusch said in Database held for ransom, anyone experience this before?:

                                    @dbeato said in Database held for ransom, anyone experience this before?:

                                    What Database type was this? an RDS or hosted inside a server?

                                    .....

                                    @donaldlandru said in Database held for ransom, anyone experience this before?:

                                    This client uses AWS hosted database and found this over the weekend.

                                    Still very ambiguous...

                                    1 Reply Last reply Reply Quote 0
                                    • scottalanmillerS
                                      scottalanmiller @JaredBusch
                                      last edited by

                                      @JaredBusch said in Database held for ransom, anyone experience this before?:

                                      @dbeato said in Database held for ransom, anyone experience this before?:

                                      What Database type was this? an RDS or hosted inside a server?

                                      .....

                                      @donaldlandru said in Database held for ransom, anyone experience this before?:

                                      This client uses AWS hosted database and found this over the weekend.

                                      Assuming that means the SaaS AWS packages and not something else, AWS offers seven categories and 15 unique database options

                                      https://aws.amazon.com/products/databases/

                                      1 Reply Last reply Reply Quote 0
                                      • Emad RE
                                        Emad R
                                        last edited by Emad R

                                        Yup, restore from backups. ARe you using old Drupal or Wordpress Site or shared hosting like TMD ?

                                        1 Reply Last reply Reply Quote 0
                                        • JaredBuschJ
                                          JaredBusch
                                          last edited by

                                          FFS already.

                                          All of you just need to stop. This is nothing that @donaldlandru needs to do.

                                          This is not his database.

                                          He has no credentials to AWS.

                                          He has no credentials to the database with access beyond read only.

                                          His company has zero liability or issues.

                                          They should have their legal team in on this meeting in the morning.

                                          Because this accusation is complete and utter bullshit.

                                          dbeatoD 1 Reply Last reply Reply Quote 2
                                          • dbeatoD
                                            dbeato @JaredBusch
                                            last edited by

                                            @JaredBusch Yes, you were correct and we discussed this last night on the Telegram group 🙂 .

                                            1 Reply Last reply Reply Quote 0
                                            • 1 / 1
                                            • First post
                                              Last post