save backup solution how?

save backup solution how?

Postby Otto » Thu Feb 09, 2017 2:07 pm

Dear friends,

we are daily confronted with crypto lock ransom attacks.
Mapped drives are effected as well.
Windows SERVERBACKUP up to now was save. But who knows for how long.

We do not find any WORM hardware.

So we thought to install a FTP server or a winsocket solution.

NAS or maybe a cheap WINDOWS PC can be the server.

Does someone have experiences or suggestions.

Best regards,
Otto
********************************************************************
mod harbour - Vamos a la conquista de la Web
modharbour.org
https://www.facebook.com/groups/modharbour.club
********************************************************************
User avatar
Otto
 
Posts: 6332
Joined: Fri Oct 07, 2005 7:07 pm

Re: save backup solution how?

Postby Baxajaun » Thu Feb 09, 2017 2:13 pm

Dear Otto,

you also need a solution like Panda Adaptative Defense

http://www.pandasecurity.com/usa/intelligence-platform/solutions.htm

Please, look at https://github.com/c0p3rnic0/PROTEIN

Best regards
User avatar
Baxajaun
 
Posts: 968
Joined: Wed Oct 19, 2005 2:17 pm
Location: Gatika. Bizkaia

Re: save backup solution how?

Postby Rick Lipkin » Thu Feb 09, 2017 2:40 pm

Otto

Mapped drives as you mention AND external backup devices connected to an infected machine via USB will be destroyed by the latest Cryptp virus ..

Rick Lipkin
User avatar
Rick Lipkin
 
Posts: 2665
Joined: Fri Oct 07, 2005 1:50 pm
Location: Columbia, South Carolina USA

Re: save backup solution how?

Postby Enrico Maria Giordano » Thu Feb 09, 2017 5:29 pm

Through which ways the virus get into the system? Running infected EXEs? Opening infected email attachments? Or just visiting infected websites?

EMG
User avatar
Enrico Maria Giordano
 
Posts: 8713
Joined: Thu Oct 06, 2005 8:17 pm
Location: Roma - Italia

Re: save backup solution how?

Postby Maurizio » Thu Feb 09, 2017 6:02 pm

Ciao Otto
We use NAS. At the scheduled time NAS turns on automaticly, makes a copy and then turns itself off.

Maurizio
www.nipeservice.com
User avatar
Maurizio
 
Posts: 824
Joined: Mon Oct 10, 2005 1:29 pm

Re: save backup solution how?

Postby TimStone » Thu Feb 09, 2017 6:50 pm

Otto,

On our installed systems, I have a program that runs 24/7 on the server with the data files. Sometime after midnight, it makes a zip file with all of the database files. The name is drawn from the date, so each day is saved independently. They can have this saved to an external drive on the computer ( mapped ). Some of my clients have swappable drives, rotating them each day for the backups.

Then, in the early morning hours, my clients upload the new zip file to a cloud storage of their choice. This could be OneDrive, Dropbox, or some other resource.

The routine that does the backup is hardcoded. It only interacts with our hosted server ( offsite ) where we place update files. It uses an FTP connection, but only downloads two files ... one with updates to the key ( encrypted ) and one with updated exe files ( archived ). Access to the hosted server account is by a complex user name / password combination.

I'm sure a hacker could penetrate this system but it's an awful lot of work just to be a nuisance. Nothing financial is available in any of this process, and there is no gain. If they were fully successful, they would only cause a small business owner the time to reformat and reload everything. Frankly, that would take less time than it would take to hack the process.

So far we have experienced no problem. Hopefully, that will continue. It is far more likely that one of my clients systems will be destroyed by lightning ( actually happened ). With this system, I can have them back up and running with a new computer in about 20 minutes.

Tim
Tim Stone
http://www.MasterLinkSoftware.com
http://www.autoshopwriter.com
timstone@masterlinksoftware.com
Using: FWH 23.10 with Harbour 3.2.0 / Microsoft Visual Studio Community 2022-24 32/64 bit
User avatar
TimStone
 
Posts: 2944
Joined: Fri Oct 07, 2005 1:45 pm
Location: Trabuco Canyon, CA USA

Re: save backup solution how?

Postby Otto » Thu Feb 09, 2017 8:07 pm

Hello
at the moment we have a rate of 6% under our clients which have been effected by ransomware.
All kind and brands of antivirus software was installed.

This is how the dbf files look like. But all types of files are infected.

We need a backup of the whole disk which brings back the system 1:1.
With windows serverbackup you are back within an hour.
But who knows if SERVERBACKUP will be effects some days too.
Therefore we search for alternatives.

Thank you for sharing your experiences.
Best regards,
Otto


Image
********************************************************************
mod harbour - Vamos a la conquista de la Web
modharbour.org
https://www.facebook.com/groups/modharbour.club
********************************************************************
User avatar
Otto
 
Posts: 6332
Joined: Fri Oct 07, 2005 7:07 pm

Re: save backup solution how?

Postby Rick Lipkin » Thu Feb 09, 2017 8:18 pm

Enrico

The infected machines I have seen come from a clever e-mail disguised as if it were from FedEx .. something to the effect like :

FedEx .."We have tried to deliver a package to you .. please click on the button below to print the tracking receipt."

Click on the Button and it's 'lights out' ..

Rick Lipkin
User avatar
Rick Lipkin
 
Posts: 2665
Joined: Fri Oct 07, 2005 1:50 pm
Location: Columbia, South Carolina USA

Re: save backup solution how?

Postby TimStone » Thu Feb 09, 2017 8:29 pm

People must learn to NOT look at any email they are not 100% certain is OK. They must also NEVER go to websites they are not 100% certain about.
Tim Stone
http://www.MasterLinkSoftware.com
http://www.autoshopwriter.com
timstone@masterlinksoftware.com
Using: FWH 23.10 with Harbour 3.2.0 / Microsoft Visual Studio Community 2022-24 32/64 bit
User avatar
TimStone
 
Posts: 2944
Joined: Fri Oct 07, 2005 1:45 pm
Location: Trabuco Canyon, CA USA

Re: save backup solution how?

Postby Enrico Maria Giordano » Thu Feb 09, 2017 8:35 pm

Rick Lipkin wrote:Enrico

The infected machines I have seen come from a clever e-mail disguised as if it were from FedEx .. something to the effect like :

FedEx .."We have tried to deliver a package to you .. please click on the button below to print the tracking receipt."

Click on the Button and it's 'lights out' ..

Rick Lipkin


As I suspected... :-(

EMG
User avatar
Enrico Maria Giordano
 
Posts: 8713
Joined: Thu Oct 06, 2005 8:17 pm
Location: Roma - Italia

Re: save backup solution how?

Postby Enrico Maria Giordano » Thu Feb 09, 2017 8:36 pm

TimStone wrote:People must learn to NOT look at any email they are not 100% certain is OK. They must also NEVER go to websites they are not 100% certain about.


I agree.

EMG
User avatar
Enrico Maria Giordano
 
Posts: 8713
Joined: Thu Oct 06, 2005 8:17 pm
Location: Roma - Italia

Re: save backup solution how?

Postby Marcelo Via Giglio » Thu Feb 09, 2017 9:25 pm

Hi,

we have ADS server on Linux and make compressed (7z) backup every day and sent it by email automaticly to a google account

Regards

Marcelo Vía
Marcelo Via Giglio
 
Posts: 1064
Joined: Fri Oct 07, 2005 3:33 pm
Location: Cochabamba - Bolivia

Re: save backup solution how?

Postby TimStone » Wed Feb 15, 2017 1:28 am

When receiving an email that "looks authentic" but you sense it is not, right click on ALL links it contains. You will usually see the primary one is not from the original sender. Immediately trash the email.

If still in doubt, contact the supposed sender ( if you know them ) to inquire if they actually sent you an email.
Tim Stone
http://www.MasterLinkSoftware.com
http://www.autoshopwriter.com
timstone@masterlinksoftware.com
Using: FWH 23.10 with Harbour 3.2.0 / Microsoft Visual Studio Community 2022-24 32/64 bit
User avatar
TimStone
 
Posts: 2944
Joined: Fri Oct 07, 2005 1:45 pm
Location: Trabuco Canyon, CA USA

Re: save backup solution how?

Postby Otto » Wed Feb 15, 2017 10:05 am

For Office 365 users:

Advanced Threat Protection
Protect your email in real time against unknown and sophisticated attacks.
Customers with subscriptions to select Exchange or Office 365 plans can add Advanced Threat Protection

https://products.office.com/en-us/exchange/online-email-threat-protection#howToBuy

Best regards,
Otto
********************************************************************
mod harbour - Vamos a la conquista de la Web
modharbour.org
https://www.facebook.com/groups/modharbour.club
********************************************************************
User avatar
Otto
 
Posts: 6332
Joined: Fri Oct 07, 2005 7:07 pm


Return to FiveWin for Harbour/xHarbour

Who is online

Users browsing this forum: Carles and 111 guests