Tips dari KOMINFO untuk menghadapi Ransomware WannaCrypt

30 views
Skip to first unread message

Willy Sutrisno

unread,
May 14, 2017, 12:34:52 AM5/14/17
to IDNOG
Bantu forward, semoga bermanfaat. Silahkan check di internet untuk informasi lebih jauh.

--
Sent from my Google INBOX

Alfons Tanujaya

unread,
May 14, 2017, 3:32:00 AM5/14/17
to id...@googlegroups.com

Langkah 2 dan 3 sederhana ?

Itu mah ngga kerja namanya :p. Bisa seharian nge backup doang.

Langkah 9 .... sederhana dan jadul.

 

Mohon maaf. Minta izin comel.

 

Salam,

Alfons

--
Web: http://www.idnog.or.id
Facebook: https://www.facebook.com/idnog
Linkedin: http://www.linkedin.com/groups/IDNOG-6657303
---
You received this message because you are subscribed to the Google Groups "IDNOG" group.
To unsubscribe from this group and stop receiving emails from it, send an email to idnog+un...@googlegroups.com.
To post to this group, send email to id...@googlegroups.com.
Visit this group at https://groups.google.com/group/idnog.
For more options, visit https://groups.google.com/d/optout.

image001.jpg

Isa Lpse

unread,
May 14, 2017, 5:06:26 AM5/14/17
to id...@googlegroups.com
kasus ini sebennya udah lama. cuman infonya lambat ajah. 


--
Web: http://www.idnog.or.id
Facebook: https://www.facebook.com/idnog
Linkedin: http://www.linkedin.com/groups/IDNOG-6657303
---
You received this message because you are subscribed to the Google Groups "IDNOG" group.
To unsubscribe from this group and stop receiving emails from it, send an email to idnog+unsubscribe@googlegroups.com.
Langkah Mitigasi Serangan Ransomware.pdf.pdf

Firdaus Rachmawan

unread,
May 14, 2017, 6:33:20 AM5/14/17
to IDNOG
waaaahh makasi banyak atas share nya
berguna bangett 

Daus

Tatag Danang SN

unread,
May 14, 2017, 7:21:52 AM5/14/17
to id...@googlegroups.com, Firdaus Rachmawan

Sekedar berbagi,

untuk patch XP dan Windows 2008 Server bisa download patch di

https://blogs.technet.microsoft.com/msrc/2017/05/12/customer-guidance-for-wannacrypt-attacks/

seharusnya saat ini sudah tidak menyebar karena domain relaynya sudah kena sinkhole, info lengkap bisa dicek di :

https://gist.github.com/rain-1/989428fa5504f378b993ee6efbc0b168


salam

--

Tatag Danang SN - Helpdesk

To unsubscribe from this group and stop receiving emails from it, send an email to idnog+un...@googlegroups.com.

Willy Sutrisno

unread,
May 14, 2017, 10:26:25 PM5/14/17
to IDNOG
Bagaimana network teman teman hari ini, sejauh ini aman aman saja?


Willy

Good judgement come from experience; experience come from bad judgement - Mulla Nasrudin

On 14 May 2017, at 12:34, Willy Sutrisno <wi...@sutrisno.me> wrote:

Bantu forward, semoga bermanfaat. Silahkan check di internet untuk informasi lebih jauh.

<4B230A43-36EA-4CEA-8C9B-D1D7247008F0-2475-0000038909FDE343.jpeg>

Rizky M. Dinata

unread,
May 14, 2017, 10:39:41 PM5/14/17
to id...@googlegroups.com
Alhamdulillah sejauh ini aman om Willy.

Best Regards,

Rizky M. Dinata


This e-mail message contains information intended solely for the intended recipient and is confidential or private in nature. If you are not the intended recipient, you must not read, disseminate, distribute, copy or otherwise use this message or any file attached to this message. Any such unauthorized use is prohibited and may be unlawful. If you have received this message in error, please notify the sender immediately and then delete the original message from your machine.

Isa Lpse

unread,
May 14, 2017, 11:34:27 PM5/14/17
to id...@googlegroups.com

Pada tanggal 15 Mei 2017 09.39, "Rizky M. Dinata" <rizk...@gmail.com> menulis:
Alhamdulillah sejauh ini aman om Willy.

Best Regards,

Rizky M. Dinata


This e-mail message contains information intended solely for the intended recipient and is confidential or private in nature. If you are not the intended recipient, you must not read, disseminate, distribute, copy or otherwise use this message or any file attached to this message. Any such unauthorized use is prohibited and may be unlawful. If you have received this message in error, please notify the sender immediately and then delete the original message from your machine.


On May 15, 2017, at 09:26, Willy Sutrisno <wi...@sutrisno.me> wrote:

Bagaimana network teman teman hari ini, sejauh ini aman aman saja?


Willy

Good judgement come from experience; experience come from bad judgement - Mulla Nasrudin

On 14 May 2017, at 12:34, Willy Sutrisno <wi...@sutrisno.me> wrote:

Bantu forward, semoga bermanfaat. Silahkan check di internet untuk informasi lebih jauh.

<4B230A43-36EA-4CEA-8C9B-D1D7247008F0-2475-0000038909FDE343.jpeg>
--
Sent from my Google INBOX

--
Web: http://www.idnog.or.id
Facebook: https://www.facebook.com/idnog
Linkedin: http://www.linkedin.com/groups/IDNOG-6657303
---
You received this message because you are subscribed to the Google Groups "IDNOG" group.
To unsubscribe from this group and stop receiving emails from it, send an email to idnog+unsubscribe@googlegroups.com.

To post to this group, send email to id...@googlegroups.com.
Visit this group at https://groups.google.com/group/idnog.
For more options, visit https://groups.google.com/d/optout.

--
Web: http://www.idnog.or.id
Facebook: https://www.facebook.com/idnog
Linkedin: http://www.linkedin.com/groups/IDNOG-6657303
---
You received this message because you are subscribed to the Google Groups "IDNOG" group.
To unsubscribe from this group and stop receiving emails from it, send an email to idnog+unsubscribe@googlegroups.com.

Tatag Danang SN

unread,
May 15, 2017, 4:08:55 AM5/15/17
to id...@googlegroups.com

Sekedar berbagi,

untuk patch XP dan Windows 2008 Server bisa download patch di

https://blogs.technet.microsoft.com/msrc/2017/05/12/customer-guidance-for-wannacrypt-attacks/

seharusnya saat ini sudah tidak menyebar karena domain relaynya sudah kena sinkhole, info lengkap bisa dicek di :

https://gist.github.com/rain-1/989428fa5504f378b993ee6efbc0b168


salam

--

Tatag Danang SN - Helpdesk


On 2017-05-14 17:33, Firdaus Rachmawan wrote:

waaaahh makasi banyak atas share nya
berguna bangett 
 
Daus
On Sun, May 14, 2017 at 4:06 PM, Isa Lpse <isa....@gmail.com> wrote:
kasus ini sebennya udah lama. cuman infonya lambat ajah. 
 
Pada tanggal 14 Mei 2017 11.34, "Willy Sutrisno" <wi...@sutrisno.me> menulis:
Bantu forward, semoga bermanfaat. Silahkan check di internet untuk informasi lebih jauh.
 
To unsubscribe from this group and stop receiving emails from it, send an email to idnog+un...@googlegroups.com.

To post to this group, send email to id...@googlegroups.com.
Visit this group at https://groups.google.com/group/idnog.
For more options, visit https://groups.google.com/d/optout.

--
Web: http://www.idnog.or.id
Facebook: https://www.facebook.com/idnog
Linkedin: http://www.linkedin.com/groups/IDNOG-6657303
---
You received this message because you are subscribed to the Google Groups "IDNOG" group.
To unsubscribe from this group and stop receiving emails from it, send an email to idnog+un...@googlegroups.com.

Bagus Ahmad Maulida

unread,
May 15, 2017, 6:35:11 AM5/15/17
to id...@googlegroups.com
dengan info sperti itu, apakah wabah ransomware sudah bisa dikatakan tidak menyebar lagi ??
dan apakah tindakan prefentif masih perlu dilakukan ?? misal dg blok port 139, 445 dan 3389 ?
Terima Kasih

Bagus Ahmad M
------------------------------------------------------------
PT. Dinamika Metamorfosa Indonesia
Anakida Building, 5th Floor - Suite 501
Phone    : 021 8282988
Fax         : 021 8282988
Mobile   : 082 3311 5 7791
Email      ba...@dinamof.co.id
------------------------------------------------------------
"Melayani,Memberikan Solusi, Menumbuh Kembangkan"
-----------------------------------------------------------

Harijanto Pribadi

unread,
May 15, 2017, 10:27:17 PM5/15/17
to IDNOG
Tindakan kominfo apjii idcert dan idsirtii adalah untuk meminimasi dampak penyebaran wannacry , dgn memberikan peringatan agar masyarakat aware dan segera melakukan patch dan tindakan preventive lainnya tetapi tdk otomatis menghentikan penyebaran virus secara total

Jadi tetap kudu waspada

Utk blok port 139,455 dari Internet ke lan atau sebaliknya tetap kudu dilakukan karena protokol smb dan active directory tdk untuk lalu lalang melalui Internet tetapi cukup di LAN atau jika diperlukan harus melalui VPN, intranet atau MPLS 

Utk port 3389 jika diperlukan diset di firewall hanya boleh di akses dr ip mana saja

Thx
HP

Oky Lisman

unread,
May 16, 2017, 4:56:39 AM5/16/17
to id...@googlegroups.com
Slamat sore...., tolong di bantu mas, sy instal pacth ms17-010 kok gak bisa ya, keterangan muncul "The update is not applicable to your computer" sudah sy coba download smua unk versi windows 7,tapi hasilnya tetap sama. 

Mohon bantuan nya

Danang

unread,
May 16, 2017, 6:30:09 AM5/16/17
to id...@googlegroups.com
untuk windows 7 kemungkinan belum sp 1 dan atau updatenya ada yg lompat, untuk baiknya pakai vitur windows update supaya runtut updatenya

regards

Tatag Danang SN
To unsubscribe from this group and stop receiving emails from it, send an email to idnog+un...@googlegroups.com.

Oky Lisman

unread,
May 16, 2017, 6:31:53 AM5/16/17
to id...@googlegroups.com
Iya, makasih mas danang

Oky Lisman

unread,
May 16, 2017, 6:34:53 AM5/16/17
to id...@googlegroups.com
Kira-kira berbahaya gak ya mas, klu sy up date dulu windows nya, baru sy instal patch nya...., sy takut komp sy kena virus ransomeware klu sy konek in ke internet.

Mohon bantuan nya, 
Makasih sblm nya

Alfons Tanujaya

unread,
May 16, 2017, 6:38:32 AM5/16/17
to id...@googlegroups.com

Kalau Windowsnya sudah diupdate lebih dari 2 bulan yang lalu, itu aman banget. Patchnya itu patch bulan Maret.

Yang harus hati-hati Windows XP dan Windows Server 2003 yang tidak ada automatic updatenya, pastikan update manual dulu (download dari tempat lain) dan instal MS17-010 setelah itu baru boleh konek.

 

Sebenarnya resikonya sudah rendah banget karena WannaCrynya tinggal sedikit sekali. Tapi nothing wrong with a bit paranoid.

 

Salam,

Alfons

Iya, makasih mas danang

 

--

Sent from my Google INBOX

 

--
Web: http://www.idnog.or.id
Facebook: https://www.facebook.com/idnog
Linkedin: http://www.linkedin.com/groups/IDNOG-6657303
---
You received this message because you are subscribed to the Google Groups "IDNOG" group.

To unsubscribe from this group and stop receiving emails from it, send an email to idnog+un...@googlegroups.com.


To post to this group, send email to id...@googlegroups.com.
Visit this group at https://groups.google.com/group/idnog.
For more options, visit https://groups.google.com/d/optout.

--
Web: http://www.idnog.or.id
Facebook: https://www.facebook.com/idnog
Linkedin: http://www.linkedin.com/groups/IDNOG-6657303
---
You received this message because you are subscribed to the Google Groups "IDNOG" group.

To unsubscribe from this group and stop receiving emails from it, send an email to idnog+un...@googlegroups.com.


To post to this group, send email to id...@googlegroups.com.
Visit this group at https://groups.google.com/group/idnog.
For more options, visit https://groups.google.com/d/optout.

--
Web: http://www.idnog.or.id
Facebook: https://www.facebook.com/idnog
Linkedin: http://www.linkedin.com/groups/IDNOG-6657303
---
You received this message because you are subscribed to the Google Groups "IDNOG" group.

To unsubscribe from this group and stop receiving emails from it, send an email to idnog+un...@googlegroups.com.


To post to this group, send email to id...@googlegroups.com.
Visit this group at https://groups.google.com/group/idnog.
For more options, visit https://groups.google.com/d/optout.

--
Web: http://www.idnog.or.id
Facebook: https://www.facebook.com/idnog
Linkedin: http://www.linkedin.com/groups/IDNOG-6657303
---
You received this message because you are subscribed to the Google Groups "IDNOG" group.

To unsubscribe from this group and stop receiving emails from it, send an email to idnog+un...@googlegroups.com.


To post to this group, send email to id...@googlegroups.com.
Visit this group at https://groups.google.com/group/idnog.
For more options, visit https://groups.google.com/d/optout.

--
Web: http://www.idnog.or.id
Facebook: https://www.facebook.com/idnog
Linkedin: http://www.linkedin.com/groups/IDNOG-6657303
---
You received this message because you are subscribed to the Google Groups "IDNOG" group.

To unsubscribe from this group and stop receiving emails from it, send an email to idnog+un...@googlegroups.com.


To post to this group, send email to id...@googlegroups.com.
Visit this group at https://groups.google.com/group/idnog.
For more options, visit https://groups.google.com/d/optout.

--

Terima Kasih

 

Bagus Ahmad M

------------------------------------------------------------

PT. Dinamika Metamorfosa Indonesia
Anakida Building, 5th Floor - Suite 501
Phone    : 021 8282988
Fax         : 021 8282988
Mobile   : 082 3311 5 7791
Email      : ba...@dinamof.co.id

------------------------------------------------------------

"Melayani,Memberikan Solusi, Menumbuh Kembangkan"

-----------------------------------------------------------

--
Web: http://www.idnog.or.id
Facebook: https://www.facebook.com/idnog
Linkedin: http://www.linkedin.com/groups/IDNOG-6657303
---
You received this message because you are subscribed to the Google Groups "IDNOG" group.

To unsubscribe from this group and stop receiving emails from it, send an email to idnog+un...@googlegroups.com.


To post to this group, send email to id...@googlegroups.com.
Visit this group at https://groups.google.com/group/idnog.
For more options, visit https://groups.google.com/d/optout.

--
Web: http://www.idnog.or.id
Facebook: https://www.facebook.com/idnog
Linkedin: http://www.linkedin.com/groups/IDNOG-6657303
---
You received this message because you are subscribed to the Google Groups "IDNOG" group.

To unsubscribe from this group and stop receiving emails from it, send an email to idnog+un...@googlegroups.com.


To post to this group, send email to id...@googlegroups.com.
Visit this group at https://groups.google.com/group/idnog.
For more options, visit https://groups.google.com/d/optout.

--
Web: http://www.idnog.or.id
Facebook: https://www.facebook.com/idnog
Linkedin: http://www.linkedin.com/groups/IDNOG-6657303
---
You received this message because you are subscribed to the Google Groups "IDNOG" group.

To unsubscribe from this group and stop receiving emails from it, send an email to idnog+un...@googlegroups.com.


To post to this group, send email to id...@googlegroups.com.
Visit this group at https://groups.google.com/group/idnog.
For more options, visit https://groups.google.com/d/optout.

--
Web: http://www.idnog.or.id
Facebook: https://www.facebook.com/idnog
Linkedin: http://www.linkedin.com/groups/IDNOG-6657303
---
You received this message because you are subscribed to the Google Groups "IDNOG" group.

To unsubscribe from this group and stop receiving emails from it, send an email to idnog+un...@googlegroups.com.


To post to this group, send email to id...@googlegroups.com.
Visit this group at https://groups.google.com/group/idnog.
For more options, visit https://groups.google.com/d/optout.

--
Web: http://www.idnog.or.id
Facebook: https://www.facebook.com/idnog
Linkedin: http://www.linkedin.com/groups/IDNOG-6657303
---
You received this message because you are subscribed to the Google Groups "IDNOG" group.

To unsubscribe from this group and stop receiving emails from it, send an email to idnog+un...@googlegroups.com.

Oky Lisman

unread,
May 16, 2017, 6:46:48 AM5/16/17
to id...@googlegroups.com
Oke siap, makasih ya mas, skrg sy sudah paham.  Makasih banyak ya mas

Iya, makasih mas danang

 

To unsubscribe from this group and stop receiving emails from it, send an email to idnog+unsubscribe@googlegroups.com.


To post to this group, send email to id...@googlegroups.com.
Visit this group at https://groups.google.com/group/idnog.
For more options, visit https://groups.google.com/d/optout.

--
Web: http://www.idnog.or.id
Facebook: https://www.facebook.com/idnog
Linkedin: http://www.linkedin.com/groups/IDNOG-6657303
---
You received this message because you are subscribed to the Google Groups "IDNOG" group.

To unsubscribe from this group and stop receiving emails from it, send an email to idnog+unsubscribe@googlegroups.com.


To post to this group, send email to id...@googlegroups.com.
Visit this group at https://groups.google.com/group/idnog.
For more options, visit https://groups.google.com/d/optout.

--
Web: http://www.idnog.or.id
Facebook: https://www.facebook.com/idnog
Linkedin: http://www.linkedin.com/groups/IDNOG-6657303
---
You received this message because you are subscribed to the Google Groups "IDNOG" group.

To unsubscribe from this group and stop receiving emails from it, send an email to idnog+unsubscribe@googlegroups.com.


To post to this group, send email to id...@googlegroups.com.
Visit this group at https://groups.google.com/group/idnog.
For more options, visit https://groups.google.com/d/optout.

--
Web: http://www.idnog.or.id
Facebook: https://www.facebook.com/idnog
Linkedin: http://www.linkedin.com/groups/IDNOG-6657303
---
You received this message because you are subscribed to the Google Groups "IDNOG" group.

To unsubscribe from this group and stop receiving emails from it, send an email to idnog+unsubscribe@googlegroups.com.


To post to this group, send email to id...@googlegroups.com.
Visit this group at https://groups.google.com/group/idnog.
For more options, visit https://groups.google.com/d/optout.

--
Web: http://www.idnog.or.id
Facebook: https://www.facebook.com/idnog
Linkedin: http://www.linkedin.com/groups/IDNOG-6657303
---
You received this message because you are subscribed to the Google Groups "IDNOG" group.

To unsubscribe from this group and stop receiving emails from it, send an email to idnog+unsubscribe@googlegroups.com.


To post to this group, send email to id...@googlegroups.com.
Visit this group at https://groups.google.com/group/idnog.
For more options, visit https://groups.google.com/d/optout.

--

Terima Kasih

 

Bagus Ahmad M

------------------------------------------------------------

PT. Dinamika Metamorfosa Indonesia
Anakida Building, 5th Floor - Suite 501
Phone    : 021 8282988
Fax         : 021 8282988
Mobile   : 082 3311 5 7791
Email      : ba...@dinamof.co.id

------------------------------------------------------------

"Melayani,Memberikan Solusi, Menumbuh Kembangkan"

-----------------------------------------------------------

--
Web: http://www.idnog.or.id
Facebook: https://www.facebook.com/idnog
Linkedin: http://www.linkedin.com/groups/IDNOG-6657303
---
You received this message because you are subscribed to the Google Groups "IDNOG" group.

To unsubscribe from this group and stop receiving emails from it, send an email to idnog+unsubscribe@googlegroups.com.


To post to this group, send email to id...@googlegroups.com.
Visit this group at https://groups.google.com/group/idnog.
For more options, visit https://groups.google.com/d/optout.

--
Web: http://www.idnog.or.id
Facebook: https://www.facebook.com/idnog
Linkedin: http://www.linkedin.com/groups/IDNOG-6657303
---
You received this message because you are subscribed to the Google Groups "IDNOG" group.

To unsubscribe from this group and stop receiving emails from it, send an email to idnog+unsubscribe@googlegroups.com.


To post to this group, send email to id...@googlegroups.com.
Visit this group at https://groups.google.com/group/idnog.
For more options, visit https://groups.google.com/d/optout.

--
Web: http://www.idnog.or.id
Facebook: https://www.facebook.com/idnog
Linkedin: http://www.linkedin.com/groups/IDNOG-6657303
---
You received this message because you are subscribed to the Google Groups "IDNOG" group.

To unsubscribe from this group and stop receiving emails from it, send an email to idnog+unsubscribe@googlegroups.com.


To post to this group, send email to id...@googlegroups.com.
Visit this group at https://groups.google.com/group/idnog.
For more options, visit https://groups.google.com/d/optout.

--
Web: http://www.idnog.or.id
Facebook: https://www.facebook.com/idnog
Linkedin: http://www.linkedin.com/groups/IDNOG-6657303
---
You received this message because you are subscribed to the Google Groups "IDNOG" group.

To unsubscribe from this group and stop receiving emails from it, send an email to idnog+unsubscribe@googlegroups.com.


To post to this group, send email to id...@googlegroups.com.
Visit this group at https://groups.google.com/group/idnog.
For more options, visit https://groups.google.com/d/optout.

--
Web: http://www.idnog.or.id
Facebook: https://www.facebook.com/idnog
Linkedin: http://www.linkedin.com/groups/IDNOG-6657303
---
You received this message because you are subscribed to the Google Groups "IDNOG" group.

To unsubscribe from this group and stop receiving emails from it, send an email to idnog+unsubscribe@googlegroups.com.


To post to this group, send email to id...@googlegroups.com.
Visit this group at https://groups.google.com/group/idnog.
For more options, visit https://groups.google.com/d/optout.

--
Web: http://www.idnog.or.id
Facebook: https://www.facebook.com/idnog
Linkedin: http://www.linkedin.com/groups/IDNOG-6657303
---
You received this message because you are subscribed to the Google Groups "IDNOG" group.
To unsubscribe from this group and stop receiving emails from it, send an email to idnog+unsubscribe@googlegroups.com.

Willy Sutrisno

unread,
May 17, 2017, 7:18:11 AM5/17/17
to IDNOG
Ransomware ini bisa jadi lebih parah tapi tidak terjadi, karena ini (long technical read) 

Harijanto Pribadi

unread,
May 17, 2017, 8:00:03 AM5/17/17
to id...@googlegroups.com
dear all

tentunya modus ransomware ini kedepan akan semakin marak karena si pembuat bisa secara instan mendapatkan keuntungan economis (langsung dapat duitnya) via bitcoin 

kalau sekarang memanfaatkan kelemahan protocol smb/cifs active directory maka mungkin saja berikutnya melalui protocol/services/daemon lainnya yang vulnerable jadi step by step yang sudah di sosialisasikan oleh kemenkominfo dkk apakah ada cara yang lebih smart ? cuman penasaran kali ada ide yang lebih cemerlang

thx
HP

<4B230A43-36EA-4CEA-8C9B-D1D7247008F0-2475-0000038909FDE343.jpeg>
-- 
Sent from my Google INBOX
-- 
Sent from my Google INBOX

-- 
Web: http://www.idnog.or.id
Facebook: https://www.facebook.com/idnog
Linkedin: http://www.linkedin.com/groups/IDNOG-6657303
--- 
You received this message because you are subscribed to the Google Groups "IDNOG" group.
To unsubscribe from this group and stop receiving emails from it, send an email to idnog+un...@googlegroups.com.

Danang

unread,
May 17, 2017, 8:45:22 AM5/17/17
to id...@googlegroups.com
dh,

selalu update windows atau autoupdate on dan auto install update seperti rekomendasi windows adalah pilihan paling bijak.
OS yang unsupported lagi mending dipensiunkan. 

hormat saya


Tatag Danang SN

Danang

unread,
May 17, 2017, 9:17:55 AM5/17/17
to id...@googlegroups.com
untuk windows 7 kemungkinan belum sp 1 dan atau updatenya ada yg lompat, untuk baiknya pakai vitur windows update supaya runtut updatenya

regards

Tatag Danang SN

Bantu forward, semoga bermanfaat. Silahkan check di internet untuk informasi lebih jauh.
 
--
Sent from my Google INBOX


--
Web: http://www.idnog.or.id
Facebook: https://www.facebook.com/idnog
Linkedin: http://www.linkedin.com/groups/IDNOG-6657303
---
You received this message because you are subscribed to the Google Groups "IDNOG" group.
To unsubscribe from this group and stop receiving emails from it, send an email to idnog+unsubscribe@googlegroups.com.

To post to this group, send email to id...@googlegroups.com.
Visit this group at https://groups.google.com/group/idnog.
For more options, visit https://groups.google.com/d/optout.


--
Web: http://www.idnog.or.id
Facebook: https://www.facebook.com/idnog
Linkedin: http://www.linkedin.com/groups/IDNOG-6657303
---
You received this message because you are subscribed to the Google Groups "IDNOG" group.
To unsubscribe from this group and stop receiving emails from it, send an email to idnog+unsubscribe@googlegroups.com.

To post to this group, send email to id...@googlegroups.com.
Visit this group at https://groups.google.com/group/idnog.
For more options, visit https://groups.google.com/d/optout.


--
Web: http://www.idnog.or.id
Facebook: https://www.facebook.com/idnog
Linkedin: http://www.linkedin.com/groups/IDNOG-6657303
---
You received this message because you are subscribed to the Google Groups "IDNOG" group.
To unsubscribe from this group and stop receiving emails from it, send an email to idnog+unsubscribe@googlegroups.com.

To post to this group, send email to id...@googlegroups.com.
Visit this group at https://groups.google.com/group/idnog.
For more options, visit https://groups.google.com/d/optout.

--
Web: http://www.idnog.or.id
Facebook: https://www.facebook.com/idnog
Linkedin: http://www.linkedin.com/groups/IDNOG-6657303
---
You received this message because you are subscribed to the Google Groups "IDNOG" group.
To unsubscribe from this group and stop receiving emails from it, send an email to idnog+unsubscribe@googlegroups.com.

To post to this group, send email to id...@googlegroups.com.
Visit this group at https://groups.google.com/group/idnog.
For more options, visit https://groups.google.com/d/optout.

--
Web: http://www.idnog.or.id
Facebook: https://www.facebook.com/idnog
Linkedin: http://www.linkedin.com/groups/IDNOG-6657303
---
You received this message because you are subscribed to the Google Groups "IDNOG" group.
To unsubscribe from this group and stop receiving emails from it, send an email to idnog+unsubscribe@googlegroups.com.

To post to this group, send email to id...@googlegroups.com.
Visit this group at https://groups.google.com/group/idnog.
For more options, visit https://groups.google.com/d/optout.



--
Terima Kasih

Bagus Ahmad M
------------------------------------------------------------
PT. Dinamika Metamorfosa Indonesia
Anakida Building, 5th Floor - Suite 501
Phone    : 021 8282988
Fax         : 021 8282988
Mobile   : 082 3311 5 7791
Email      ba...@dinamof.co.id
------------------------------------------------------------
"Melayani,Memberikan Solusi, Menumbuh Kembangkan"
-----------------------------------------------------------

--
Web: http://www.idnog.or.id
Facebook: https://www.facebook.com/idnog
Linkedin: http://www.linkedin.com/groups/IDNOG-6657303
---
You received this message because you are subscribed to the Google Groups "IDNOG" group.
To unsubscribe from this group and stop receiving emails from it, send an email to idnog+unsubscribe@googlegroups.com.

To post to this group, send email to id...@googlegroups.com.
Visit this group at https://groups.google.com/group/idnog.
For more options, visit https://groups.google.com/d/optout.

--
Web: http://www.idnog.or.id
Facebook: https://www.facebook.com/idnog
Linkedin: http://www.linkedin.com/groups/IDNOG-6657303
---
You received this message because you are subscribed to the Google Groups "IDNOG" group.
To unsubscribe from this group and stop receiving emails from it, send an email to idnog+unsubscribe@googlegroups.com.

To post to this group, send email to id...@googlegroups.com.
Visit this group at https://groups.google.com/group/idnog.
For more options, visit https://groups.google.com/d/optout.

--
Web: http://www.idnog.or.id
Facebook: https://www.facebook.com/idnog
Linkedin: http://www.linkedin.com/groups/IDNOG-6657303
---
You received this message because you are subscribed to the Google Groups "IDNOG" group.
To unsubscribe from this group and stop receiving emails from it, send an email to idnog+un...@googlegroups.com.
To post to this group, send email to id...@googlegroups.com.
Visit this group at https://groups.google.com/group/idnog.
For more options, visit https://groups.google.com/d/optout.

Jefri A

unread,
May 17, 2017, 9:17:56 AM5/17/17
to id...@googlegroups.com
Tambahan :
1. enable shadow copy
2. Selalu login pakai user yg gak punya privilege. ibarat linux musti sudo dulu.. :)
3. Selalu backup automatic ke storage non windows..seperti NAS, SAN, kalau berupa server, ya pakai linux utk backup servernya.
4. enable firewall, hanya allow port/program yg diinginkan.
5. backup daily, weekly.


To unsubscribe from this group and stop receiving emails from it, send an email to idnog+unsubscribe@googlegroups.com.

To post to this group, send email to id...@googlegroups.com.
Visit this group at https://groups.google.com/group/idnog.
For more options, visit https://groups.google.com/d/optout.

--
Web: http://www.idnog.or.id
Facebook: https://www.facebook.com/idnog
Linkedin: http://www.linkedin.com/groups/IDNOG-6657303
---
You received this message because you are subscribed to the Google Groups "IDNOG" group.
To unsubscribe from this group and stop receiving emails from it, send an email to idnog+unsubscribe@googlegroups.com.

To post to this group, send email to id...@googlegroups.com.
Visit this group at https://groups.google.com/group/idnog.
For more options, visit https://groups.google.com/d/optout.

--
Web: http://www.idnog.or.id
Facebook: https://www.facebook.com/idnog
Linkedin: http://www.linkedin.com/groups/IDNOG-6657303
---
You received this message because you are subscribed to the Google Groups "IDNOG" group.
To unsubscribe from this group and stop receiving emails from it, send an email to idnog+unsubscribe@googlegroups.com.

Oky Lisman

unread,
May 17, 2017, 9:51:28 AM5/17/17
to id...@googlegroups.com
Makasih mas jefri atas tambahan infonya

Harijanto Pribadi

unread,
May 17, 2017, 11:18:41 AM5/17/17
to IDNOG
Kalau versi crack wkwk
Eh mac os x kan gratis ya bisa jalan di x86

To unsubscribe from this group and stop receiving emails from it, send an email to idnog+unsubscribe@googlegroups.com.

To post to this group, send email to id...@googlegroups.com.
Visit this group at https://groups.google.com/group/idnog.
For more options, visit https://groups.google.com/d/optout.

--
Web: http://www.idnog.or.id
Facebook: https://www.facebook.com/idnog
Linkedin: http://www.linkedin.com/groups/IDNOG-6657303
---
You received this message because you are subscribed to the Google Groups "IDNOG" group.
To unsubscribe from this group and stop receiving emails from it, send an email to idnog+unsubscribe@googlegroups.com.

To post to this group, send email to id...@googlegroups.com.
Visit this group at https://groups.google.com/group/idnog.
For more options, visit https://groups.google.com/d/optout.

--
Web: http://www.idnog.or.id
Facebook: https://www.facebook.com/idnog
Linkedin: http://www.linkedin.com/groups/IDNOG-6657303
---
You received this message because you are subscribed to the Google Groups "IDNOG" group.
To unsubscribe from this group and stop receiving emails from it, send an email to idnog+unsubscribe@googlegroups.com.

ganesha pranayoga

unread,
Jun 22, 2017, 12:14:07 AM6/22/17
to id...@googlegroups.com

TAP~{•}

unread,
Jun 22, 2017, 12:17:17 AM6/22/17
to ganesha pranayoga
:-)
‎Thursday, June 22, 2017 11:17:00 
To unsubscribe from this group and stop receiving emails from it, send an email to idnog+un...@googlegroups.com.

Isa Lpse

unread,
Jun 22, 2017, 1:39:20 AM6/22/17
to id...@googlegroups.com
Waduh.. makin bahaya ajah nih. bisa nyerang linux. waduh bagaimana nih. apakah ada solusi? 

Alfons Tanujaya

unread,
Jun 22, 2017, 1:58:02 AM6/22/17
to id...@googlegroups.com

Dear Friends,

 

Brainstorming saja.

 

  1. Backup data dan jadikan offline. Atau buat pengamanan kredensial bagi yang ingin mengakses data backup sehingga ransomware ngga bisa akses. Jangan buka full akses ke data backup. Kalau kena ransomware data backup ikut di enkrip yah sama saja bohong, bukan data backup lagi namanya. Tapi data moyung.
  2. Gunakan antivirus di Linux (ini kalau anda percaya Linux sudah bisa kena virus, kalau ngga percaya dan tetap klaim Linux kebal virus yah silahkan saja dengan keyakinan anda).

 

Salam,

Alfons

 

From: id...@googlegroups.com [mailto:id...@googlegroups.com] On Behalf Of Isa Lpse
Sent: Thursday, June 22, 2017 12:39 PM
To: id...@googlegroups.com
Subject: Re: [IDNOG] Re: Tips dari KOMINFO untuk menghadapi Ransomware WannaCrypt

 

Waduh.. makin bahaya ajah nih. bisa nyerang linux. waduh bagaimana nih. apakah ada solusi? 

 

To unsubscribe from this group and stop receiving emails from it, send an email to idnog+un...@googlegroups.com.


To post to this group, send email to 

--
Web: http://www.idnog.or.id
Facebook: https://www.facebook.com/idnog
Linkedin: http://www.linkedin.com/groups/IDNOG-6657303
---
You received this message because you are subscribed to the Google Groups "IDNOG" group.

To unsubscribe from this group and stop receiving emails from it, send an email to idnog+un...@googlegroups.com.


To post to this group, send email to id...@googlegroups.com.
Visit this group at https://groups.google.com/group/idnog.
For more options, visit https://groups.google.com/d/optout.

--
Web: http://www.idnog.or.id
Facebook: https://www.facebook.com/idnog
Linkedin: http://www.linkedin.com/groups/IDNOG-6657303
---
You received this message because you are subscribed to the Google Groups "IDNOG" group.

To unsubscribe from this group and stop receiving emails from it, send an email to idnog+un...@googlegroups.com.


To post to this group, send email to id...@googlegroups.com.
Visit this group at https://groups.google.com/group/idnog.
For more options, visit https://groups.google.com/d/optout.

--
Web: http://www.idnog.or.id
Facebook: https://www.facebook.com/idnog
Linkedin: http://www.linkedin.com/groups/IDNOG-6657303
---
You received this message because you are subscribed to the Google Groups "IDNOG" group.

To unsubscribe from this group and stop receiving emails from it, send an email to idnog+un...@googlegroups.com.


To post to this group, send email to id...@googlegroups.com.
Visit this group at https://groups.google.com/group/idnog.
For more options, visit https://groups.google.com/d/optout.

--
Web: http://www.idnog.or.id
Facebook: https://www.facebook.com/idnog
Linkedin: http://www.linkedin.com/groups/IDNOG-6657303
---
You received this message because you are subscribed to the Google Groups "IDNOG" group.

To unsubscribe from this group and stop receiving emails from it, send an email to idnog+un...@googlegroups.com.


To post to this group, send email to id...@googlegroups.com.
Visit this group at https://groups.google.com/group/idnog.
For more options, visit https://groups.google.com/d/optout.

--
Web: http://www.idnog.or.id
Facebook: https://www.facebook.com/idnog
Linkedin: http://www.linkedin.com/groups/IDNOG-6657303
---
You received this message because you are subscribed to the Google Groups "IDNOG" group.

To unsubscribe from this group and stop receiving emails from it, send an email to idnog+un...@googlegroups.com.

Jimmy IndoAsli

unread,
Jun 22, 2017, 2:16:12 AM6/22/17
to idnog
Hosting Nayana di korsel bisa kena salah satu penyebabnya karena linux server mrk pakai versi kernel dan apache versi lama dr tahun  2008 gak diupdate




To unsubscribe from this group and stop receiving emails from it, send an email to idnog+unsubscribe@googlegroups.com.


To post to this group, send email to 

--
Web: http://www.idnog.or.id
Facebook: https://www.facebook.com/idnog
Linkedin: http://www.linkedin.com/groups/IDNOG-6657303
---
You received this message because you are subscribed to the Google Groups "IDNOG" group.

To unsubscribe from this group and stop receiving emails from it, send an email to idnog+unsubscribe@googlegroups.com.


To post to this group, send email to id...@googlegroups.com.
Visit this group at https://groups.google.com/group/idnog.
For more options, visit https://groups.google.com/d/optout.

--
Web: http://www.idnog.or.id
Facebook: https://www.facebook.com/idnog
Linkedin: http://www.linkedin.com/groups/IDNOG-6657303
---
You received this message because you are subscribed to the Google Groups "IDNOG" group.

To unsubscribe from this group and stop receiving emails from it, send an email to idnog+unsubscribe@googlegroups.com.


To post to this group, send email to id...@googlegroups.com.
Visit this group at https://groups.google.com/group/idnog.
For more options, visit https://groups.google.com/d/optout.

--
Web: http://www.idnog.or.id
Facebook: https://www.facebook.com/idnog
Linkedin: http://www.linkedin.com/groups/IDNOG-6657303
---
You received this message because you are subscribed to the Google Groups "IDNOG" group.

To unsubscribe from this group and stop receiving emails from it, send an email to idnog+unsubscribe@googlegroups.com.


To post to this group, send email to id...@googlegroups.com.
Visit this group at https://groups.google.com/group/idnog.
For more options, visit https://groups.google.com/d/optout.

--
Web: http://www.idnog.or.id
Facebook: https://www.facebook.com/idnog
Linkedin: http://www.linkedin.com/groups/IDNOG-6657303
---
You received this message because you are subscribed to the Google Groups "IDNOG" group.

To unsubscribe from this group and stop receiving emails from it, send an email to idnog+unsubscribe@googlegroups.com.


To post to this group, send email to id...@googlegroups.com.
Visit this group at https://groups.google.com/group/idnog.
For more options, visit https://groups.google.com/d/optout.

--
Web: http://www.idnog.or.id
Facebook: https://www.facebook.com/idnog
Linkedin: http://www.linkedin.com/groups/IDNOG-6657303
---
You received this message because you are subscribed to the Google Groups "IDNOG" group.

To unsubscribe from this group and stop receiving emails from it, send an email to idnog+unsubscribe@googlegroups.com.


To post to this group, send email to id...@googlegroups.com.
Visit this group at https://groups.google.com/group/idnog.
For more options, visit https://groups.google.com/d/optout.

--
Web: http://www.idnog.or.id
Facebook: https://www.facebook.com/idnog
Linkedin: http://www.linkedin.com/groups/IDNOG-6657303
---
You received this message because you are subscribed to the Google Groups "IDNOG" group.
To unsubscribe from this group and stop receiving emails from it, send an email to idnog+unsubscribe@googlegroups.com.

Alfons Tanujaya

unread,
Jun 22, 2017, 2:31:36 AM6/22/17
to id...@googlegroups.com

Kalau begitu pencegahannya ditambah lagi jadi ada 3 poin :

  1. Selalu update OS dan semua aplikasi dengan patch terkini guna mencegah eksploitasi. (walaupun dalam prakteknya mungkin bisa saja patch membuat server bermasalah .... nambah kerjaan admin nih).
  2. Jika memungkinkan tambahkan TFA dalam proses login administator.
  1. Backup data dan jadikan offline. Atau buat pengamanan kredensial bagi yang ingin mengakses data backup sehingga ransomware ngga bisa akses. Jangan buka full akses ke data backup. Kalau kena ransomware data backup ikut di enkrip yah sama saja bohong, bukan data backup lagi namanya. Tapi data moyung.
  2. Gunakan antivirus di Linux (ini kalau anda percaya Linux sudah bisa kena virus, kalau ngga percaya dan tetap klaim Linux kebal virus yah silahkan saja dengan keyakinan anda).

    SIlahkan ditambahkan embah2 admin.

    Selamat menunaikan ibadah puasa baig yang menjalankan.

     

    Salam,

    Alfons

    To unsubscribe from this group and stop receiving emails from it, send an email to idnog+un...@googlegroups.com.


    To post to this group, send email to 

    --
    Web: http://www.idnog.or.id
    Facebook: https://www.facebook.com/idnog
    Linkedin: http://www.linkedin.com/groups/IDNOG-6657303
    ---
    You received this message because you are subscribed to the Google Groups "IDNOG" group.

    To unsubscribe from this group and stop receiving emails from it, send an email to idnog+un...@googlegroups.com.


    To post to this group, send email to id...@googlegroups.com.
    Visit this group at https://groups.google.com/group/idnog.
    For more options, visit https://groups.google.com/d/optout.

    --
    Web: http://www.idnog.or.id
    Facebook: https://www.facebook.com/idnog
    Linkedin: http://www.linkedin.com/groups/IDNOG-6657303
    ---
    You received this message because you are subscribed to the Google Groups "IDNOG" group.

    To unsubscribe from this group and stop receiving emails from it, send an email to idnog+un...@googlegroups.com.


    To post to this group, send email to id...@googlegroups.com.
    Visit this group at https://groups.google.com/group/idnog.
    For more options, visit https://groups.google.com/d/optout.

    --
    Web: http://www.idnog.or.id
    Facebook: https://www.facebook.com/idnog
    Linkedin: http://www.linkedin.com/groups/IDNOG-6657303
    ---
    You received this message because you are subscribed to the Google Groups "IDNOG" group.

    To unsubscribe from this group and stop receiving emails from it, send an email to idnog+un...@googlegroups.com.


    To post to this group, send email to id...@googlegroups.com.
    Visit this group at https://groups.google.com/group/idnog.
    For more options, visit https://groups.google.com/d/optout.

    --
    Web: http://www.idnog.or.id
    Facebook: https://www.facebook.com/idnog
    Linkedin: http://www.linkedin.com/groups/IDNOG-6657303
    ---
    You received this message because you are subscribed to the Google Groups "IDNOG" group.

    To unsubscribe from this group and stop receiving emails from it, send an email to idnog+un...@googlegroups.com.


    To post to this group, send email to id...@googlegroups.com.
    Visit this group at https://groups.google.com/group/idnog.
    For more options, visit https://groups.google.com/d/optout.

    --
    Web: http://www.idnog.or.id
    Facebook: https://www.facebook.com/idnog
    Linkedin: http://www.linkedin.com/groups/IDNOG-6657303
    ---
    You received this message because you are subscribed to the Google Groups "IDNOG" group.

    To unsubscribe from this group and stop receiving emails from it, send an email to idnog+un...@googlegroups.com.


    To post to this group, send email to id...@googlegroups.com.
    Visit this group at https://groups.google.com/group/idnog.
    For more options, visit https://groups.google.com/d/optout.

    --
    Web: http://www.idnog.or.id
    Facebook: https://www.facebook.com/idnog
    Linkedin: http://www.linkedin.com/groups/IDNOG-6657303
    ---
    You received this message because you are subscribed to the Google Groups "IDNOG" group.

    To unsubscribe from this group and stop receiving emails from it, send an email to idnog+un...@googlegroups.com.


    To post to this group, send email to id...@googlegroups.com.
    Visit this group at https://groups.google.com/group/idnog.
    For more options, visit https://groups.google.com/d/optout.

    --
    Web: http://www.idnog.or.id
    Facebook: https://www.facebook.com/idnog
    Linkedin: http://www.linkedin.com/groups/IDNOG-6657303
    ---
    You received this message because you are subscribed to the Google Groups "IDNOG" group.

    To unsubscribe from this group and stop receiving emails from it, send an email to idnog+un...@googlegroups.com.

    Tatag Danang SN

    unread,
    Jun 22, 2017, 3:12:50 PM6/22/17
    to id...@googlegroups.com

    selain dari om Alfons bisa juga baca baca info soal erebus di

    https://www.trendmicro.com/vinfo/us/security/news/cyber-attacks/erebus-linux-ransomware-impact-to-servers-and-countermeasures

    regards


    --

    Tatag Danang SN

    ganesha pranayoga

    unread,
    Jun 28, 2017, 7:53:09 AM6/28/17
    to id...@googlegroups.com
    Selain wannacry masih ada ransomware yang lainnya. Ada yang tau cara kerja ransomware petya?
    image1.JPG
    image2.JPG
    image3.JPG

    Sent from my iPhone

    dikshie

    unread,
    Jun 28, 2017, 8:54:20 AM6/28/17
    to IDNOG
    dari sisi lain:

    Cryptovirology: The Birth, Neglect, and Explosion of Ransomware
    https://cacm.acm.org/magazines/2017/7/218875-cryptovirology/fulltext

    Cryptovirology was born out of scientific curiosity of what the future
    may hold for software attacks that merge cryptographic technology with
    malware. It started at Columbia University as a natural by-product of
    an unnatural union: a former hacker placed in a room with a
    cryptographer, both given ample time with which to contemplate the
    dystopia of tomorrow. Collectively, given our backgrounds, we had
    amassed a body of highly unconventional scientific problems that
    hackers face when infiltrating computer systems as well as the
    foundational cryptography with which to solve those problems.

    Our list of problems included the following question: How devastating
    could the most insidious malicious software attack be against a
    target? To put things in perspective this was circa 1995. Many people
    had not heard of the Internet, and among those that did, many were
    obtaining an email address for the first time. The typical home
    computer was not online all the time. Users had to use dial-up modems
    when they wanted to check email. USB technology did not exist.
    3.5-inch floppy disks were the norm. Cryptography, for millennia, had
    been perceived as a purely protective technology, and in particular as
    a way to hide the content of messages, secure data at rest, and
    authenticate users.

    On the one hand we were aware of the failed AIDS Information Trojan
    that scrambled the names of the victim's files using a symmetric key
    and demanded a ransom to unscramble them. From a technological
    perspective this attack crumbled since the decryption key could be
    extracted from the code of the Trojan.

    In addition, we had in mind the grotesque vision of H.R. Giger in the
    science-fiction movie Alien.5 Of particular interest to us was the
    alien facehugger. This creature resembled a cross between an insect
    and an octopus. It would wrap its legs around the victim's face and
    insert a tube down the victim's throat. It wrapped its long tail
    around the victim's neck and squeezed. The victim would enter a form
    of coma, while the egg the face-hugger implanted into the abdomen
    would incubate into a drone (or queen) and burst through the stomach
    of the victim, thus completing a phase of the alien life cycle.

    There was no way to safely remove the facehugger once attached.
    Touching the facehugger caused it to tighten its tail and restrict the
    flow of air to the lungs. Cutting it caused its corrosive alien blood
    to bleed out and disintegrate everything it seeped through (including
    the floors of the spaceship). Try as they did the crew's scientists
    could not find a way to safely remove facehuggers from their victims.

    The AIDS Trojan and the facehugger idea defined in our minds the
    "where we are now" versus where malicious software attacks might
    evolve to, respectively. We sought a digital analogue of the
    facehugger, namely, a forced symbiotic relationship between a computer
    virus and its host where removing the virus is more damaging than
    leaving it in place.

    But what we discovered was not exactly that which we sought. We
    discovered the first secure data kidnapping attack. We called it
    cryptoviral extortion. In cryptoviral extortion, the attacker
    generates a key pair for a public key cryptosystem and places the
    "public encryption key" in the cryptovirus. The corresponding "private
    decryption key" is kept private. The crypto-virus spreads and infects
    many host systems. It attacks the host system by hybrid encrypting the
    victim's files: encrypting the files with a locally generated random
    symmetric key and encrypting that key with the public key. It zeroizes
    the symmetric key and plain-text and then puts up a ransom note
    containing the asymmetric ciphertext and a means to contact the
    attacker. The victim sends the payment and the asymmetric ciphertext
    to the attacker. The attacker receives the payment, decrypts the
    asymmetric ciphertext with his private key, and sends the recovered
    symmetric key to the victim. The victim deciphers his files with the
    symmetric key.

    At no point is the private key revealed to the victims. Only the
    attacker can decrypt the asymmetric ciphertext. Furthermore, the
    symmetric key that a victim receives is of no use to other victims
    since it was randomly generated.

    We presented this attack along with the facehugger analogy at the 1996
    IEEE Security and Privacy conference.8 The discovery was perceived as
    being simultaneously innovative and somewhat vulgar. Years later, the
    media relabeled the cryptoviral extortion attack as ransomware. In the
    conference paper we proposed that electronic money could be extorted
    by the attacker. This is what happens today using bitcoin. We have
    observed that what we described over 20 years ago is the exact
    "business model" used today in an estimated $1 billion-a-year criminal
    industry: the industry of ransomware.

    We discovered that public key cryptography holds the power to break
    the symmetry between the view of an antivirus analyst and the view of
    the attacker. The view of the antivirus analyst is the malware code
    and the public key it contains. The view of the attacker is the
    malware code, the public key it contains, and the corresponding
    private key. The malware can perform trapdoor one-way operations on
    the victim's machine that only the attacker can undo. A multitude of
    cryptovirology attacks, both overt and covert in nature, are based on
    the unique advantage this gives to the attacker. These methods
    weaponize cryptography as an attack tool as opposed to the previous
    uses that were defensive in nature.

    In our 2004 book Malicious Cryptography: Exposing Cryptovirology9 we
    presented the following analogy: cryptovirology is to penetrating
    computer systems as cryptanalysis is to cracking ciphers. It is a
    proactive anticipation of the opponent's next move and suggests that
    certain countermeasures should be developed and put into place. To
    counter cryptoviral extortion we recommended a diligent backup
    strategy and searching for crypto code where it does not belong. We
    warned the public about these threats and similar ones by publishing
    our findings, thereby providing a significant head start to develop
    and deploy defenses.

    It has been a long road that we have followed, fraught with skepticism
    and criticism, ultimately resulting in worldwide recognition that
    cryptoviral extortion is a severe threat. Over the years we have given
    numerous lectures on cryptovirology. We have experienced the spectrum
    of possible reactions. Some concurred that the threat is real. Others
    insisted that cryptoviral extortion was pointless, that it offered
    nothing to the attacker beyond deleting the hard drive. Still others
    professed that no victim would ever pay.

    Shortly after we published our book, it was met with harsh criticism.
    An expert who had written books on computer viruses published a
    scathing review, concluding that for those seriously involved in the
    study of malware the book is of "little practical use." This opinion
    directly translates to telling the public there is no need to worry
    about ransomware. We attributed such reactions to the inherent
    resistance many people feel toward new ideas, especially ideas that
    merge two previously distinct disciplines, in this case, malware and
    cryptography. It seemed to us that the difficulties known as the
    "innovator's dilemma"2 apply also to proactively addressing threats
    and risks.

    Cryptovirology has proven itself to be a formidable threat. Ransomware
    attacks make the news daily. Victims include individuals, hospitals,
    police precincts, universities, transportation systems, and government
    offices. We even saw the development of "ransomware as a service"
    where cryptovirology tools are sold to criminals that perpetrate
    cryptoviral extortion (for more details on ransomware, see
    https://en.wikipedia.org/wiki/Ransomware). This past year we have
    witnessed a vicious downward spiral: the more organizations that were
    attacked, the more news coverage there was on ransomware. The more
    news coverage there was on ransomware, the more criminals got in on
    the action, prompting ever more news coverage. The media amplified
    cryptovirology awareness among law-abiding citizens and criminals
    alike.

    Social and legal reactions to the damage followed. In fact, the trip
    further down the spiral changed the very definition of a "computer
    breach." Prior, a computer breach was synonymous with the exfiltration
    of sensitive data from an organization. This past year the meaning
    expanded to account for ransomware. A recent fact sheet published by
    the U.S. Department of Health and Human Services on ransomware and
    HIPAA states that when electronically protected health information is
    encrypted by ransomware a breach has occurred and the incident
    therefore constitutes a disclosure that violates HIPAA.6 The
    justification for this definition is that the adversary has taken
    control of sensitive health information. This is a significant change
    in the definition of a computer "breach" since now, due to the threat
    of cryptoviral extortion, a breach can occur even when no sensitive
    data is exfiltrated!

    A highly publicized and effective ransomware attack was carried out
    against the Hollywood Presbyterian Medical Center, and the hospital
    paid $17,000 in bitcoin for restoration. This, along with the epidemic
    levels of similar attacks, prompted the state of California to enact a
    new law that addresses ransomware.1 "SB-1137 Computer crimes:
    ransomware" amends Section 523 of the Penal Code to outlaw the
    introduction of ransomware into a computer system with the intent of
    extorting money. Reuters reported that the WannaCry crypto-worm from
    May 2017 locked up more than 200,000 computers in more than 150
    countries.7 The attack exploited a vulnerability hoarded by the NSA
    that was exposed by whistle-blowers and later patched. The attack was
    nonetheless severe since organizations and individuals were not
    diligent enough in patching.

    We finally point out that cryptovirology has influenced popular
    culture as well, inspiring the plot in Barry Eisler's techno-thriller
    Fault Line.3

    Over the years we have observed a palpable reluctance by security
    companies to describe the cryptoviral extortion attack in detail and
    discuss countermeasures. We view this as being fundamentally flawed;
    it is the classic phenomenon of "reactive security" (acting after the
    attack) as opposed to the preventative "proactive security."

    We believe ransomware is the tip of the iceberg. Most cryptovirology
    attacks are covert in nature, allowing the adversary to securely steal
    information completely unnoticed. These attacks would slip past or
    stymie the vast majority of computer incident response teams. It took
    over 20 years for cryptoviral extortion to gain worldwide recognition,
    and it appears that the bulk of these other attacks, which are fully
    described in the scientific literature, are heading in the same
    direction: destined to be overlooked until a large-scale real-world
    attack is publicized. Santayana's aphorism: "those who cannot remember
    the past are condemned to repeat it"4 seems to apply equally well to
    malicious cryptography.







    2017-06-28 20:29 GMT+09:00 ganesha pranayoga <neshen...@gmail.com>:
    > Selain wannacry masih ada ransomware yang lainnya. Ada yang tau cara kerja
    > ransomware petya?
    >
    >
    -dikshie-
    Reply all
    Reply to author
    Forward
    0 new messages