Hướng dẫn cách phòng tránh Ransomware WannaCry với lỗi SMB windows chi tiết nhất

Điểm qua tin tức nóng hổi về virus WannaCry

Một nhóm Hacker tên là Shadow Broker đã hack vào hệ thống của NSA và kéo ra một mớ dữ liệu của một tổ chức do NSA quản lý gọi là Equation Group. Trong mớ dữ liệu này có chứa rất nhiều các exploit 0-days được NSA sử dụng để tấn công, do thám và đánh cắp dữ liệu của rất nhiều người dùng, tổ chức, chính phủ ở khắp nơi trên thế giới để phục vụ cho hoạt động tình báo.

ransomware-wannacry
ransomware wannacry

Trong đó có một 0-days đặc biệt nguy hiểm mới được public đợt tháng 4 vừa rồi nhắm vào tất cả các phiên bản từ XP đến Windows 10. Lỗi này nhắm tới dịch vụ SMB (file sharing) của Windows cho phép attacker thực hiện remote execution, nói một cách nôm na, attacker có thể điều khiển máy tính từ xa, chẳng hạn như gọi lên một cmd với quyền SYSTEM, và thao tác ở đó mà người dùng không hề hay biết.

WannaCry tận dụng exploit này,khi nó lây nhiễm vào được một máy, nó sẽ thực hiện scan các máy khác trong cùng LAN, và thực hiện exploit. Một khi exploit được rối,nó đã có quyền kiểm soát và thao tác trên máy mới, nó sẽ tự động copy bản thân nó sang máy mới kiểm soát được và chạy -> tiếp tục thực hiện đến với tất cả các máy còn lại.

Điểm nguy hiểm nhất dẫn đến việc có thể bị tấn công từ ngoài LAN chính là việc các máy không bật Firewall, chặn port 445 của smb hoặc disable File sharing service. Attacker có thể tạo một hệ thống tự động scan theo dải ip public để tìm các máy mở port 445 để thực hiện exploit.

wannacry-ransomware-decrypt-unlock-files-696x363
wannacry ransomware-decrypt unlock files

 

Hoặc attacker có thể dùng email phising đánh lừa người dùng bấm vào link, hoặc mở file đính kèm chứa một dropper, dropper này download code exploit về và chạy để tạo ra một backdoor, từ đó attacker ung dung tiến vào, hoặc đơn giản hơn nó download luôn WannaCry về và chạy.

Điểm khác biệt khiến WannaCry nguy hiểm chính là việc nó dùng exploit để mở rộng phạm vi lây nhiễm, Và cũng cần nhấn mạnh là exploit này có thể tạo ra một backdoor với quyền SYSTEM ( tương đương với root trong Linux) nên nó có toàn quyền đối với hệ thống, từ việc disable AV, disable Firewall, sửa hoặc xoá file hệ thống, vô hiệu hoá hoàn toàn các cơ chế bảo vệ.

Chỉ cần một node bị nhiễm là tất cả các máy trong cùng mạng nếu chưa được update sẽ dính theo. Lại càng nguy hiểm hơn ở VN khí người dùng xài Win lậu, không update, disable Firewall, và các bản win cũ như XP (MS đã ngừng support cho XP, tuy nhiên lần này vẫn phải tung một bản vá để sửa lỗi này cho XP)

Hướng dẫn cách phòng tránh virus Wannacry

Lưu ý:

Không tải, không mở bất kỳ tập tin nào không rõ nguồn gốc, đặc biệt là các file: exe, pdf

Cách 1: Update Windows

Điều quan trọng nhất là bạn phải Update Windows để cập nhật bản vá mới nhất của Microsoft. Hãy làm ngay lập tức, đừng chần chờ gì nửa.

Cách 2: Sử dụng công cụ RansomFree

Vừa mới đây hãng Cybereason vừa phát hành công cụ RansomeFree giúp bạn phát hiện và tiêu diệt ngay WannaCry khi vừa xuất hiện trên máy tính bạn.

Nếu lỡ máy tính bạn có đang dính Ransomware WannaCry, thì  RansomeFree cũng sẽ giúp bạn hạn chế bị lây lan qua các tập tin khác, tránh bị mã hóa toàn bộ dữ liệu

Xin lưu ý: tùy thuộc vào vị trí, một số tệp tin vẫn có thể bịmã hóa bởi ransomware WannaCry. Tuy nhiên, như được trình bày trong đoạn video này, phần lớn các tệp tin được bảo vệ, và ransomware không còn phát tán nữa.

Hoặc cài đặt và cập nhật các phần mềm AntiVirus mới nhất như: Kaspersky, Avast, Avira…

Cách 3: Chặn Port 

Dùng Firewall có sẵn trên Windows, hoặc Firewall của các chương trình antivirus chặn các port sau:

  • TCP ports 137, 139, and 445
  • UDP ports 137 and 138

Dùng lệnh PowerShell

Vào Run: gõ lệnh Powershell rồi dán đoạn lệnh dưới đây

Dùng trên giao diện

Cách dùng Firewall trên Windows:

Vào Control Panel –> Firewall

fw - Hướng dẫn cách phòng tránh Ransomware WannaCry chi tiết nhấtChọn Advanced setting

fw2 - Hướng dẫn cách phòng tránh Ransomware WannaCry chi tiết nhất

Thực hiện lần lượt cho cả 2

Inbound Rules và Outbound Rules

Nhấn phải chuột vào Inbound Rules, chọn New Rule…

fw3 - Hướng dẫn cách phòng tránh Ransomware WannaCry chi tiết nhất

Check vào Ô Port rồi nhấn Next

fw4 - Hướng dẫn cách phòng tránh Ransomware WannaCry chi tiết nhất

Tiếp tục chọn vào TCP, trong phần Specific local ports: 137,139,445

fw5 - Hướng dẫn cách phòng tránh Ransomware WannaCry chi tiết nhất

Chọn Block Connection

fw6 1 - Hướng dẫn cách phòng tránh Ransomware WannaCry chi tiết nhất

Tiếp tục cứ nhấn Next,

fw7 - Hướng dẫn cách phòng tránh Ransomware WannaCry chi tiết nhấtTới ô Name đặt gì cũng được.

fw8 - Hướng dẫn cách phòng tránh Ransomware WannaCry chi tiết nhất

Rồi tương tự thực hiện lại Bước 1, block port UDP137,138

Sau đó đến Outbound Rules, thực hiện như Inboud Rules

Cách 4: Tắt chế độ SMB

Bạn cần khởi động Power Shell lên, vào run gõ lệnh PowerShell

pw - Hướng dẫn cách phòng tránh Ransomware WannaCry chi tiết nhất

Máy tính cá nhân sử dụng Windows Vista, Windows Server 2008, Windows 7, Windows Server 2008 R2, Windows 8, and Windows Server 2012

Copy lệnh dưới đây vào PowerShell

Chỗ nào lỗi thì cứ bỏ qua, copy xong thì nhấn Enter nha

Server sử dụng Windows 8 và Windows Server 2012

Copy lệnh dưới đây vào PowerShell

  • Disable SMBv1
  • Disable SMBv2

 

Server sử dụng Windows 7, Windows Server 2008 R2, Windows Vista, and Windows Server 2008

Copy lệnh dưới đây vào PowerShell

  • Disable SMBv1
  • Disable SMBv2

Bạn cần phải khởi động lại máy tính để hoàn tất nhé

Remove SMB v1 in Windows 8.1, Windows 10, Windows 2012 R2, and Windows Server 2016 bằng giao diện

Windows Server: Vào Server Manager

4014204 en 1 - Hướng dẫn cách phòng tránh Ransomware WannaCry chi tiết nhất

 

Windows Server: Sử dụng PowerShell

4014205 en 1 - Hướng dẫn cách phòng tránh Ransomware WannaCry chi tiết nhất

Máy tính cá nhân: Vào Control Panel chọn Add or Remove Programs

4014206 en 1 - Hướng dẫn cách phòng tránh Ransomware WannaCry chi tiết nhất

Máy tính cá nhân:

Dùng PowerShell

4014207 en 1 - Hướng dẫn cách phòng tránh Ransomware WannaCry chi tiết nhất

Nếu lỡ bị nhiễm Ransomware WannaCry rồi thì sao?

– Ngắt ngay đường mạng wifi internet và LAN nội bộ để không lây nhiễm các máy khác trong mạng.

– Cài đặt ngay RansomFree (ở Cách 2) để tránh bị lây nhiễm.

Kết Luận:

  • Wannacry là một virus có tốc độ lây lan chóng mặt
  • Wannacry rất nguy hiểm đối với những máy có chứa dữ liệu quan trọng có thể gây tổn thất nặng nề vì vậy bạn không nên chủ quan

Cuối cùng chúc các bạn vui vẻ và đừng quên ghé thăm góc nhìn kiến thức thường xuyên nhé.

Hướng dẫn cách phòng tránh Ransomware WannaCry với lỗi SMB windows chi tiết nhất
5 (100%) 3 votes

182 BÌNH LUẬN

  1. hello there and thank you for your info – I’ve definitely picked up something new from
    right here. I did however expertise a few technical points using
    this web site, since I experienced to reload the
    website many times previous to I could get it to load properly.
    I had been wondering if your web host is OK? Not that I’m
    complaining, but sluggish loading instances times will sometimes affect your placement in google and could damage your high
    quality score if ads and marketing with Adwords. Well I’m
    adding this RSS to my email and could look out for a
    lot more of your respective exciting content. Make sure you update this again soon.

  2. Woah! I’m really loving the template/theme of this website.

    It’s simple, yet effective. A lot of times it’s hard
    to get that “perfect balance” between usability and visual appearance.
    I must say you’ve done a superb job with this. Also, the blog loads super quick for me on Safari.
    Exceptional Blog!

  3. I really love your site.. Great colors & theme.
    Did you build this amazing site yourself? Please reply back as I’m
    wanting to create my very own blog and would like to know where you
    got this from or what the theme is called. Cheers!

  4. Write more, thats all I have to say. Literally, it seems as
    though you relied on the video to make your point.
    You definitely know what youre talking about, why throw
    away your intelligence on just posting videos to your blog when you could be giving us something
    enlightening to read?

  5. I was wondering if you ever thought of changing the page layout of
    your site? Its very well written; I love what youve got to say.
    But maybe you could a little more in the way of content so people could connect with it better.
    Youve got an awful lot of text for only having 1 or
    2 pictures. Maybe you could space it out better?

  6. Attractive section of content. I just stumbled upon your blog and
    in accession capital to assert that I get in fact enjoyed account your blog posts.
    Anyway I’ll be subscribing to your augment and even I achievement you
    access consistently fast.

  7. Thank you for every other informative website. The place else could I get that type of info written in such a perfect
    way? I have a undertaking that I am simply now running on,
    and I have been at the look out for such info.

  8. Today, I went to the beachfront with my kids. I found
    a sea shell and gave it to my 4 year old daughter and said “You can hear the ocean if you put this to your ear.”
    She put the shell to her ear and screamed. There
    was a hermit crab inside and it pinched her ear.

    She never wants to go back! LoL I know this is completely off topic
    but I had to tell someone!

  9. This is very interesting, You are a very skilled blogger.
    I’ve joined your rss feed and look forward to seeking more of your fantastic post.
    Also, I’ve shared your site in my social networks!

  10. Awesome blog! Do you have any tips for aspiring writers?
    I’m hoping to start my own site soon but I’m a little lost on everything.
    Would you recommend starting with a free platform like WordPress or go for a paid option? There are so many options out there that I’m totally confused ..
    Any suggestions? Bless you!

  11. Excellent blog! Do you have any tips and hints for
    aspiring writers? I’m planning to start my own blog soon but I’m
    a little lost on everything. Would you suggest starting with a free platform like WordPress or
    go for a paid option? There are so many options out there that I’m completely overwhelmed ..
    Any recommendations? Cheers! natalielise plenty of fish

  12. Oh my goodness! Amazing article dude! Many thanks, However I am going through problems with your RSS. I don’t understand why I cannot join it. Is there anyone else getting similar RSS problems? Anyone that knows the answer will you kindly respond? Thanx!!

  13. Superb site you have here but I was curious if you knew of any
    user discussion forums that cover the same topics discussed here?
    I’d really like to be a part of group where I can get
    comments from other experienced individuals that share the same interest.
    If you have any suggestions, please let me
    know. Bless you!

  14. My partner and I absolutely love your blog and find nearly all of your post’s
    to be what precisely I’m looking for. Does one offer guest writers to write content
    available for you? I wouldn’t mind writing a post or elaborating
    on a number of the subjects you write related to here.
    Again, awesome web site!

  15. Thanks for your publication. One other thing is always that individual states in the United states of america have their particular laws which affect home owners, which makes it very hard for the our elected representatives to come up with a whole new set of recommendations concerning property foreclosure on people. The problem is that every state possesses own guidelines which may interact in an adverse manner in terms of foreclosure plans.

  16. I liked up to you’ll obtain performed right here. The comic strip is tasteful, your authored material stylish. however, you command get bought an shakiness over that you wish be handing over the following. ill surely come more beforehand once more since precisely the same just about very continuously within case you defend this increase.

  17. Thanks for the different tips shared on this blog site. I have noticed that many insurance firms offer prospects generous special discounts if they favor to insure a couple of cars with them. A significant volume of households own several cars these days, specially those with elderly teenage children still residing at home, as well as the savings upon policies can easily soon begin. So it is a good idea to look for a bargain.

  18. It’s a pity you don’t have a donate button! I’d definitely donate to this superb blog! I suppose for now i’ll settle for bookmarking and adding your RSS feed to my Google account. I look forward to brand new updates and will share this site with my Facebook group. Talk soon!

  19. It’s a shame you don’t have a donate button! I’d most certainly donate to this outstanding blog! I suppose for now i’ll settle for book-marking and adding your RSS feed to my Google account. I look forward to fresh updates and will talk about this website with my Facebook group. Chat soon!

  20. When I originally commented I clicked the “Notify me when new comments are added” checkbox and now each time a comment is added I get four emails with the same comment. Is there any way you can remove people from that service? Many thanks!

  21. Hey there just wanted to give you a quick heads up.
    The words in your post seem to be running off the
    screen in Safari. I’m not sure if this is a format issue or something to do with
    internet browser compatibility but I thought I’d post
    to let you know. The style and design look great though!

    Hope you get the issue fixed soon. Cheers

  22. It’s perfect time to make some plans for the future and it’s time to be happy. I have learn this put up and if I could I desire to recommend you some interesting issues or suggestions. Maybe you could write next articles referring to this article. I wish to learn even more things about it!

  23. Thanks for discussing your ideas with this blog. Furthermore, a fairy tale regarding the lenders intentions any time talking about foreclosure is that the traditional bank will not getreceive my installments. There is a certain quantity of time the bank will take payments every now and then. If you are far too deep inside the hole, they should commonly desire that you pay that payment entirely. However, that doesn’t mean that they will have any sort of payments at all. If you and the loan company can find a way to work something out, the particular foreclosure approach may end. However, in the event you continue to neglect payments underneath the new program, the foreclosed process can just pick up where it was left off.

  24. I will also like to express that most of those that find themselves with out health insurance can be students, self-employed and those that are without a job. More than half of those uninsured are really under the age of 35. They do not feel they are requiring health insurance since they are young in addition to healthy. Their particular income is normally spent on houses, food, and also entertainment. A lot of people that do represent the working class either 100 or not professional are not given insurance by means of their work so they get along without due to the rising tariff of health insurance in america. Thanks for the ideas you reveal through your blog.

  25. Can I simply say what a aid to seek out someone who truly is aware of what theyre speaking about on the internet. You positively know the way to carry a difficulty to mild and make it important. Extra people have to read this and perceive this facet of the story. I cant consider youre no more standard because you definitely have the gift.

  26. Hmm it seems like your blog ate my first comment (it was super long) so I guess I’ll just sum it up what I had written and say, I’m thoroughly enjoying your blog. I too am an aspiring blog blogger but I’m still new to the whole thing. Do you have any recommendations for newbie blog writers? I’d definitely appreciate it.

  27. One thing I want to touch upon is that weight loss program fast can be carried out by the appropriate diet and exercise. Your size not simply affects appearance, but also the quality of life. Self-esteem, depressive disorder, health risks, plus physical ability are damaged in extra weight. It is possible to do everything right and still gain. If this happens, a condition may be the primary cause. While an excessive amount food and never enough workout are usually responsible, common medical ailments and traditionally used prescriptions might greatly add to size. I am grateful for your post right here.

  28. I have observed that online diploma is getting well-known because getting your college degree online has developed into a popular alternative for many people. Numerous people have not really had a possible opportunity to attend a traditional college or university yet seek the increased earning potential and career advancement that a Bachelor’s Degree gives you. Still some others might have a diploma in one discipline but would like to pursue one thing they now develop an interest in.

  29. It’s the best time to make some plans for the future and it’s time to be happy. I’ve read this post and if I could I wish to suggest you few interesting things or advice. Perhaps you could write next articles referring to this article. I desire to read more things about it!

  30. Simply desire to say your article is as astonishing.

    The clarity in your post is just cool and i can assume
    you are an expert on this subject. Fine with your permission let
    me to grab your RSS feed to keep up to date with forthcoming post.

    Thanks a million and please carry on the enjoyable work.

  31. A further issue is that video games can be serious in nature with the most important focus on studying rather than leisure. Although, there’s an entertainment part to keep your sons or daughters engaged, each one game is generally designed to work on a specific group of skills or area, such as instructional math or science. Thanks for your article.

  32. My partner and I absolutely love your blog and
    find a lot of your post’s to be just what I’m looking for.
    Does one offer guest writers to write content for you? I wouldn’t mind writing a post or elaborating on a lot of the subjects you write regarding here.
    Again, awesome blog!

  33. I acquired more something totally new on this losing weight issue. One particular issue is a good nutrition is highly vital whenever dieting. A big reduction in junk food, sugary foods, fried foods, sweet foods, beef, and white flour products may perhaps be necessary. Keeping wastes parasitic organisms, and poisons may prevent targets for losing belly fat. While certain drugs temporarily solve the situation, the awful side effects will not be worth it, and they also never supply more than a momentary solution. It can be a known proven fact that 95 of fad diets fail. Many thanks sharing your ideas on this web site.

  34. In line with my research, after a foreclosures home is offered at a bidding, it is common for the borrower to be able to still have a remaining unpaid debt on the bank loan. There are many creditors who seek to have all expenses and liens paid off by the next buyer. Even so, depending on specified programs, restrictions, and state legal guidelines there may be a number of loans that are not easily fixed through the exchange of financial loans. Therefore, the duty still lies on the client that has got his or her property in foreclosure process. Many thanks sharing your opinions on this weblog.

  35. I am really enjoying the theme/design of your site. Do you ever run into any web browser compatibility problems? A couple of my blog audience have complained about my site not working correctly in Explorer but looks great in Chrome. Do you have any ideas to help fix this problem?

  36. Do you mind if I quote a couple of your posts as long as I provide credit and sources back to your site? My website is in the very same niche as yours and my users would genuinely benefit from a lot of the information you present here. Please let me know if this okay with you. Regards!

  37. Thanks for the new stuff you have uncovered in your article. One thing I’d prefer to discuss is that FSBO associations are built over time. By bringing out yourself to owners the first few days their FSBO can be announced, ahead of masses start off calling on Wednesday, you build a good association. By sending them instruments, educational supplies, free accounts, and forms, you become an ally. Through a personal fascination with them and also their predicament, you produce a solid connection that, oftentimes, pays off if the owners decide to go with an agent they know plus trust – preferably you actually.

  38. I truly love your website.. Excellent colors & theme. Did you make this amazing site yourself? Please reply back as I’m attempting to create my own personal site and would like to know where you got this from or exactly what the theme is named. Kudos!

  39. Please let me know if you’re looking for a article
    writer for your site. You have some really good posts and I think I would
    be a good asset. If you ever want to take some of the load off, I’d absolutely love to write some articles for your blog in exchange for a link back to
    mine. Please send me an e-mail if interested. Thank you!

BÌNH LUẬN

Please enter your comment!
Please enter your name here