ML
    • Recent
    • Categories
    • Tags
    • Popular
    • Users
    • Groups
    • Register
    • Login

    Database held for ransom, anyone experience this before?

    Scheduled Pinned Locked Moved IT Discussion
    20 Posts 11 Posters 1.5k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • Reid CooperR
      Reid Cooper @JaredBusch
      last edited by

      @JaredBusch said in Database held for ransom, anyone experience this before?:

      @donaldlandru someone is screwed.

      Assuming no backups and that it has sensitive data. Might just be Wordpress posts and public already.

      donaldlandruD 1 Reply Last reply Reply Quote 0
      • donaldlandruD
        donaldlandru @Reid Cooper
        last edited by

        @Reid-Cooper said in Database held for ransom, anyone experience this before?:

        @JaredBusch said in Database held for ransom, anyone experience this before?:

        @donaldlandru someone is screwed.

        Assuming no backups and that it has sensitive data. Might just be Wordpress posts and public already.

        Nah they had backups. Not Wordpress lol

        1 Reply Last reply Reply Quote 0
        • 1
          1337
          last edited by 1337

          Sound like this one:
          https://www.csoonline.com/article/3174306/ransomware-attacks-targeted-hundreds-of-mysql-databases.html

          According to the article it's a brute force attack on root account of the mysql database.

          A little more info:
          https://www.guardicore.com/2017/02/0-2-btc-strikes-back-now-attacking-mysql-databases/

          Looks like the database is erased without being dumped somewhere so no sense in paying anything.

          1 Reply Last reply Reply Quote 1
          • dbeatoD
            dbeato
            last edited by

            What Database type was this? an RDS or hosted inside a server?

            JaredBuschJ 1 Reply Last reply Reply Quote 0
            • JaredBuschJ
              JaredBusch @dbeato
              last edited by

              @dbeato said in Database held for ransom, anyone experience this before?:

              What Database type was this? an RDS or hosted inside a server?

              .....

              @donaldlandru said in Database held for ransom, anyone experience this before?:

              This client uses AWS hosted database and found this over the weekend.

              dbeatoD scottalanmillerS 2 Replies Last reply Reply Quote 0
              • dbeatoD
                dbeato @JaredBusch
                last edited by

                @JaredBusch said in Database held for ransom, anyone experience this before?:

                @dbeato said in Database held for ransom, anyone experience this before?:

                What Database type was this? an RDS or hosted inside a server?

                .....

                @donaldlandru said in Database held for ransom, anyone experience this before?:

                This client uses AWS hosted database and found this over the weekend.

                Still very ambiguous...

                1 Reply Last reply Reply Quote 0
                • scottalanmillerS
                  scottalanmiller @JaredBusch
                  last edited by

                  @JaredBusch said in Database held for ransom, anyone experience this before?:

                  @dbeato said in Database held for ransom, anyone experience this before?:

                  What Database type was this? an RDS or hosted inside a server?

                  .....

                  @donaldlandru said in Database held for ransom, anyone experience this before?:

                  This client uses AWS hosted database and found this over the weekend.

                  Assuming that means the SaaS AWS packages and not something else, AWS offers seven categories and 15 unique database options

                  https://aws.amazon.com/products/databases/

                  1 Reply Last reply Reply Quote 0
                  • Emad RE
                    Emad R
                    last edited by Emad R

                    Yup, restore from backups. ARe you using old Drupal or Wordpress Site or shared hosting like TMD ?

                    1 Reply Last reply Reply Quote 0
                    • JaredBuschJ
                      JaredBusch
                      last edited by

                      FFS already.

                      All of you just need to stop. This is nothing that @donaldlandru needs to do.

                      This is not his database.

                      He has no credentials to AWS.

                      He has no credentials to the database with access beyond read only.

                      His company has zero liability or issues.

                      They should have their legal team in on this meeting in the morning.

                      Because this accusation is complete and utter bullshit.

                      dbeatoD 1 Reply Last reply Reply Quote 2
                      • dbeatoD
                        dbeato @JaredBusch
                        last edited by

                        @JaredBusch Yes, you were correct and we discussed this last night on the Telegram group 🙂 .

                        1 Reply Last reply Reply Quote 0
                        • 1 / 1
                        • First post
                          Last post