New ransomware that targets backups. Are we susceptible?

Availability for the Always-On Enterprise

Re: New ransomware that targets backups. Are we susceptible

Veeam Logoby dburris » Mon Feb 13, 2017 9:09 pm

What someone gains admin access to the Veeam B&R server, deletes the backups, and then encrypts files. I understand we could use external USB drives or tapes to keep the data safe. But what if we are relying on Veeam Cloud Connect for off-site backups. I see there is an option there too to "Delete from disk". Is there a way to keep the Veeam Cloud archives safe from in this scenario?

Thanks,
Dave
dburris
Novice
 
Posts: 6
Liked: never
Joined: Wed Jun 03, 2009 4:24 pm
Full Name: Dave Burris

Re: New ransomware that targets backups. Are we susceptible

Veeam Logoby Gostev » Tue Feb 14, 2017 12:35 am

Your service provider certainly can arrange that. One way that immediately comes to my mind is to setup periodic storage-based snapshots on backup repository.
Gostev
Veeam Software
 
Posts: 21262
Liked: 2318 times
Joined: Sun Jan 01, 2006 1:01 am
Full Name: Anton Gostev

Re: New ransomware that targets backups. Are we susceptible

Veeam Logoby thjones » Tue Feb 14, 2017 8:48 am

Is it enough to use windows defender as antimalware scanner on each computer? In addition, I can conduct strong password policy, update all antimalware and net protecting software, plus keep primary security rules https://www.bestvpnrating.com/blog/9-ti ... rd-snowden I mean if I maintains security system in decent order, will this new malware penetrate in the system or pass round?
thjones
Lurker
 
Posts: 1
Liked: never
Joined: Sat Dec 24, 2016 3:39 pm
Full Name: Kenneth

Re: New ransomware that targets backups. Are we susceptible

Veeam Logoby Gostev » Tue Feb 14, 2017 9:49 pm

Of course it would, because Windows Defender only carries signatures to known malware. If you're "lucky" to get a newly released one, it won't protect you.
Gostev
Veeam Software
 
Posts: 21262
Liked: 2318 times
Joined: Sun Jan 01, 2006 1:01 am
Full Name: Anton Gostev

Re: New ransomware that targets backups. Are we susceptible

Veeam Logoby lukejf » Wed Feb 15, 2017 3:51 am

hey guys
I see some of you are using non domain joined veeam servers. How do you go doing restores directly back to the servers. IE AD users, Mailbox objects. We found in version 8 it failed to complete file restores correctly unless it was on the domain.
We always use tape however would like some tips on securing the backup repository
lukejf
Service Provider
 
Posts: 35
Liked: 2 times
Joined: Tue Jul 10, 2012 8:15 am
Full Name: Luke

Re: New ransomware that targets backups. Are we susceptible

Veeam Logoby Mike Resseler » Wed Feb 15, 2017 6:54 am

Hi Luke,

Can't remember well how it was in v8, but today this should not be a problem. For example, see here https://helpcenter.veeam.com/docs/backu ... tml?ver=95 to recover AD objects where you can specify a particular username / pwd to connect to your AD for restore. Do note however that your networking must allow this so look at the requirements for ports also.

On the backup repository. I tend to use a specific account to connect to the backup repository. An account that isn't used for something else. Ransomware tends to run in a user context (the user that it used to start its bad things) so if that account is not used, it won't succeed in encrypting your backup files. Please don't forget to store that account / pwd somewhere in a safe (preferred outside the company premises) so that in worse case you have access to the files :-)
Mike Resseler
Veeam Software
 
Posts: 3000
Liked: 354 times
Joined: Fri Feb 08, 2013 3:08 pm
Location: Belgium, the land of the fries, the beer, the chocolate and the diamonds...
Full Name: Mike Resseler

Re: New ransomware that targets backups. Are we susceptible

Veeam Logoby lando_uk » Fri May 12, 2017 11:24 pm 1 person likes this post

Any know cases of this latest Ransom-WannaCry infecting backups, from the AV vender info, the VBK extension isn't listed, so hopefully its ok.
lando_uk
Expert
 
Posts: 235
Liked: 17 times
Joined: Thu Oct 17, 2013 10:02 am
Full Name: Mark

Re: New ransomware that targets backups. Are we susceptible

Veeam Logoby Mike Resseler » Sat May 13, 2017 3:39 am 1 person likes this post

Hi Mark,

From what I can find, VBK are indeed not affected by this one. But never say never as these tend to change very fast :-(. Don't forget that MSFT has patched the security hole with the March update so make sure your machines are patched!
Mike Resseler
Veeam Software
 
Posts: 3000
Liked: 354 times
Joined: Fri Feb 08, 2013 3:08 pm
Location: Belgium, the land of the fries, the beer, the chocolate and the diamonds...
Full Name: Mike Resseler

Re: New ransomware that targets backups. Are we susceptible

Veeam Logoby unsichtbarre » Sun May 14, 2017 4:17 pm

We moved Veeam to a backup-only domain (no-email, no web-browsing, etc.) to gain the benefits of AD, while limiting exposure to Ransomeware.
unsichtbarre
Enthusiast
 
Posts: 56
Liked: 14 times
Joined: Mon Mar 08, 2010 4:05 pm
Full Name: John Borhek

Re: New ransomware that targets backups. Are we susceptible

Veeam Logoby frankive » Sun May 14, 2017 10:31 pm 1 person likes this post

does anyone have a nice powershells script we can run to target client and servers to see if the computer is protected from this attack?
for me it seems like the ms17-010 website refers to very many different KBs and also that some KBs replace other etc.
Would be great to have a powershelgl script we could execute on all servers and clients to verify it this gap is closed.
frankive
Service Provider
 
Posts: 688
Liked: 86 times
Joined: Tue May 14, 2013 8:35 pm
Location: Norway
Full Name: Frank Iversen

Re: New ransomware that targets backups. Are we susceptible

Veeam Logoby albertwt » Mon May 15, 2017 10:28 am

Hi Frankie,

Check this script below:

Code: Select all
https://gallery.technet.microsoft.com/scriptcenter/Script-for-check-Specific-46caba5d

Code: Select all
https://gallery.technet.microsoft.com/scriptcenter/Powershell-Query-a-patch-67cf35f8


Hope that helps you.
--
/* Veeam software enthusiast user & supporter ! */
albertwt
Expert
 
Posts: 598
Liked: 19 times
Joined: Thu Nov 05, 2009 12:24 pm
Location: Sydney, NSW

Previous

Return to Veeam Backup & Replication



Who is online

Users browsing this forum: Google Feedfetcher, Yahoo [Bot] and 18 guests