Posts
2353
Following
513
Followers
1230
A drunken debugger

Heretek of Silent Signal
repeated

Dear buttplug.io users:

We apologize for the current downtime.

If your butt is BSOD’ing, please try rebooting it a few times.

5
3
0
repeated

Just reiterating, because this is getting lost in a lot of the coverage: the original Azure outage and the Crowdstrike Windows bug are NOT related. That said, a significant number of corps run Windows servers on Azure with Crowdstrike Falcon. Wired coverage has more.
https://www.wired.com/story/crowdstrike-outage-update-windows/

0
1
0
repeated

So I just happened to read a blog discussing some PoC crashes in Office (https://code610.blogspot.com/2017/10/microsoft-outlook-2016-rwra-crash.html) & what I do? I sent them to @expmon_ immediately (https://pub.expmon.com/analysis/110243/).

ht: I've found real exploitable bugs w/ the power of EXPMON, it's not just a 0day detection system.:)

0
1
1
repeated

Graham Sutherland / Polynomial

pour one out for the homies who can't head to the pub tonight because they're stuck unfucking hundreds of computers

2
3
0
repeated

you can outsource the work, but you cant outsource the risk

1
3
0
repeated

LittleAlex 🇺🇦🇮🇱🇩🇪🇳🇴

Too funny: In 2010 McAffe caused a global IT meltdown due to a faulty update. CTO at this time was George Kurtz. Now he is CEO of

https://www.zdnet.com/article/defective-mcafee-update-causes-worldwide-meltdown-of-xp-pcs/

20
45
1
"Google is no longer trying to index the entire web. In fact, it's become extremely selective, refusing to index most content. This isn't about content creators failing to meet some arbitrary standard of quality. Rather, it's a fundamental change in how Google approaches its role as a search engine."

https://www.vincentschmalbach.com/google-now-defaults-to-not-indexing-your-content/

This pretty much confirms my previous assessment:

https://infosec.place/notice/AjnQ7fYpkwNnsgcLLc
1
2
4
repeated
Edited 2 months ago

Here is a GPO that can apparently run in safe mode to automate the removal of the problematic crowdstrike driver: https://gist.github.com/whichbuffer/7830c73711589dcf9e7a5217797ca617

EDIT: despite my indication that this for running in safe mode, many people seemed to have missed that I said it is for safe mode. So, here is the clarification: IT IS FOR SAFE MODE

H/T @p4gs

1
2
0
repeated

When I said "one day my stance on EDR / AV / IPS will be vindicated" I didn't mean for half the Internet to melt down but I am soooooo enjoying this moment.

Thank you for giving me my day of glory. Now I will have a story to tell my grandchildren.

2
4
0
repeated
repeated

Rairii (bootloader unlocked, MSR_LE set)

so I happen to have a 0day downgrade attack bitlocker bypass, which would be very helpful for people dealing with the crowdstrike issue and have more than about a dozen systems with tpm+secure boot bitlocker lol

the downgrade attack part is why i never publicly documented the original issue yet

also I bet MS are very annoyed that everyone’s saying its their fault

1
2
0
repeated

Explaining to reporters that this is not a Microsoft issue but a Crowdstrike issue - interesting how different the "non tech" world looks at this

2
1
1
repeated

I recall reading a "computer horror story", most probably around 2005-2010 but dated earlier, maybe much earlier, that involved a computer room with floor tiles and a short circuit, probably below those tiles. The story described the long process of investigating the issue and I was thrilled to read it.

It was comparable to the Unix recovery legend and to VAXen, my children, just don't belong in some places.

Please boost and if you know that story or anything that sounds at least close to it -- please share! If you help me find the one I'm looking for, you'll be my hero for at least a week!

0
2
0
repeated

EDR bug crashes all your points of access.

Vendor investigation and Incident Response processes are started, risking the exposure of your operation.

0
2
0
repeated

Nobody got fired for buying and ...

that's because the HR systems are down.

1
13
0
"Mild chaos at Sydney Airport"

I think "mild chaos" is my new favorite phrase for describing anything.
1
1
3
"many 911 and non-emergency call centres are not working correctly across the State of Alaska"

Periodic reminder that "security by shoving in more complexity" is an especially bad idea in case of critical infrastructure...

#CrowdStrike
1
3
8
repeated

Major issue with CrowdStrike Falcon Sensor causing massive Windows 10 outages globally.

Fleets of 50k+ machines stuck in BSOD loop. 70%+ laptops down in some orgs.

Workaround:
1. Safe Mode
2. Delete C:\Windows\System32\drivers\CrowdStrike\C-00000291*.sys
3. Reboot

Regions impacted: EU-1, US-1, US-2, US-GOV-1, AU, MY, NZ

Check systems & invoke IR plans ASAP!

0
6
0
repeated
Edited 2 months ago

The BBC is running a live blog on the 'worldwide IT outage'

It's only been up 20 minutes at the time of writing, but no mention of Crowdstrike as I type this.

Update: Now Crowdstrike is mentioned

https://www.bbc.co.uk/news/live/cnk4jdwp49et

1
2
0
My condolences to the CrowdStrike team...

https://www.youtube.com/watch?v=88l9tjkTBwQ
0
0
2
Show older