CrowdStrike issue causes mass global tech disruptions

The #1 community for Gun Owners in Indiana

Member Benefits:

  • Fewer Ads!
  • Discuss all aspects of firearm ownership
  • Discuss anti-gun legislation
  • Buy, sell, and trade in the classified section
  • Chat with Local gun shops, ranges, trainers & other businesses
  • Discover free outdoor shooting areas
  • View up to date on firearm-related events
  • Share photos & video with other members
  • ...and so much more!
  • Eric66

    Plinker
    Rating - 0%
    0   0   0
    Jul 9, 2024
    73
    33
    West Lafayette
    Curious how you did this? Did you go hands on & delete the offending .sys file manually?

    I have hundreds of remote systems that are doing one of the following:
    -Stuck at a BSOD
    -BSOD but building a crash log file, crashing again before it gets to 100%, rebooting and building a log file again
    -Systems displaying a bitlocker pw required page, enter the pw & it crash reboots back to the bitlocker screen

    I've had to give out the bitlocker pw & a local admin username & pw then talk the users through getting into SAFE mode. Getting into SAFE mode has been a real PITA!
    Honestly, I'm not sure what the server side of the recovery looked like. I'm in the group responsible for direct and indirect control of the production lines, vehicle tracking and data collection, once all of the VMs were back up it became our responsibility to get them into a production ready state.
     

    indyblue

    Guns & Pool Shooter
    Site Supporter
    Rating - 100%
    4   0   0
    Aug 13, 2013
    3,904
    129
    Indy Northside `O=o-
    They actually use a backdoor to push their updates and there is no way to stop it short of unplugging from the internet.
    Why can’t it simply be firewalled off at the corporate level? Have one server in a DMZ that gets the updates and then internal staff can copy those and start the process internally so it can either be automated or manually distributed.
     

    ancjr

    1 Kings 18:17-18 KJV
    Rating - 100%
    1   0   0
    Aug 20, 2021
    14,930
    113
    Washington County
    I was in the ER when they announced that they couldn't handle any more patients because of this mess. Drove 30 miles to an ER that still was able to operate pen and paper and was better off all the way around.
     

    Hop

    Grandmaster
    Site Supporter
    Rating - 100%
    16   0   0
    Jan 21, 2008
    5,108
    83
    Indy
    Well Corporate pushed out an emergency group policy change that will allow us Field Service IT administrators to create an unencrypted Windows PE boot stick on any still functional remote PC (we could have manually done this on a remote PC). We have a tool on that stick to pull the Bitlocker pw and also pull the local admin login pw.

    This is SUPER dangerous imo.

    Our users, right now, don't know this USB policy has been pushed out. This puts our pi at risk & is a really bad idea imo.
     

    firecadet613

    Master
    Rating - 100%
    39   0   1
    Dec 24, 2012
    3,157
    113
    I'm amazed so many fellow remote folks on my team (and other teams) are still affected with laptops down, while I wasn't impacted.

    Do that many folks leave their work laptops on 24/7? I shut mine down when I'm done for the day, so I'm assuming I never received the faulty update?
     

    jkaetz

    Master
    Rating - 100%
    3   0   0
    Jan 20, 2009
    2,058
    83
    Indianapolis
    Well Corporate pushed out an emergency group policy change that will allow us Field Service IT administrators to create an unencrypted Windows PE boot stick on any still functional remote PC (we could have manually done this on a remote PC). We have a tool on that stick to pull the Bitlocker pw and also pull the local admin login pw.

    This is SUPER dangerous imo.

    Our users, right now, don't know this USB policy has been pushed out. This puts our pi at risk & is a really bad idea imo.
    Is it possible to free up some disk space on the systems and plant the recovery PE image on the disk itself rather than on USB? Of course you still have an admin PW and bitlocker key in plain text but at least not on a USB drive. Hopefully all your systems have different local admin PWs. Could also mass change the local admin passwords after recovery.
    I'm amazed so many fellow remote folks on my team (and other teams) are still affected with laptops down, while I wasn't impacted.

    Do that many folks leave their work laptops on 24/7? I shut mine down when I'm done for the day, so I'm assuming I never received the faulty update?
    My computers never get turned off. Fortunately we're not using CrowdStrike though even if we were I would have had the knowledge and ability to recover myself. I recognize that most don't. I don't need to save the tiny bit of electricity that they use while idle and makes it easy to pickup the work wherever it left off. It also facilitates the fluidity of work happening around life. Again, other situations may be different.
     

    WebSnyper

    Time to make the chimichangas
    Rating - 100%
    64   0   0
    Jul 3, 2010
    16,514
    113
    127.0.0.1
    My computers never get turned off. Fortunately we're not using CrowdStrike though even if we were I would have had the knowledge and ability to recover myself. I recognize that most don't. I don't need to save the tiny bit of electricity that they use while idle and makes it easy to pickup the work wherever it left off. It also facilitates the fluidity of work happening around life. Again, other situations may be different.
    Same here, I leave it run as there are times I need to jump over to a PC from phone in the evening to handle something work related. Even though my machine could boot fast enough, it just makes it easier to leave it on as I do with my home machines, etc.
     

    Hop

    Grandmaster
    Site Supporter
    Rating - 100%
    16   0   0
    Jan 21, 2008
    5,108
    83
    Indy
    Is it possible to free up some disk space on the systems and plant the recovery PE image on the disk itself rather than on USB? Of course you still have an admin PW and bitlocker key in plain text but at least not on a USB drive. Hopefully all your systems have different local admin PWs. Could also mass change the local admin passwords after recovery.

    My computers never get turned off. Fortunately we're not using CrowdStrike though even if we were I would have had the knowledge and ability to recover myself. I recognize that most don't. I don't need to save the tiny bit of electricity that they use while idle and makes it easy to pickup the work wherever it left off. It also facilitates the fluidity of work happening around life. Again, other situations may be different.

    I got some more info about this Corporate Win PE drive today. It has a time bomb built in so it won't boot PE after a predetermined amount of time.

    We also use a LAPS tool that rotates the local admin password. I can expire that password after fixing a remote machine.

    This has been a Monday from Hell. I have people, even in this day, year 2024, that cannot tell the PC from a monitor from a docking station. People are CONSTANTLY calling the PC "box" a modem. I have people calling in new PC setup tickets for a laptop docking station thinking it's their new PC. I have people that "turn off & on" their computer only to see the same frozen screen because they only power cycled the monitor & not the PC.

    They live amongst us. :bash:
     

    DoggyDaddy

    Grandmaster
    Site Supporter
    Rating - 100%
    73   0   1
    Aug 18, 2011
    111,037
    149
    Southside Indy
    I got some more info about this Corporate Win PE drive today. It has a time bomb built in so it won't boot PE after a predetermined amount of time.

    We also use a LAPS tool that rotates the local admin password. I can expire that password after fixing a remote machine.

    This has been a Monday from Hell. I have people, even in this day, year 2024, that cannot tell the PC from a monitor from a docking station. People are CONSTANTLY calling the PC "box" a modem. I have people calling in new PC setup tickets for a laptop docking station thinking it's their new PC. I have people that "turn off & on" their computer only to see the same frozen screen because they only power cycled the monitor & not the PC.

    They live amongst us. :bash:
    Can you help me with my VCR? The clock keeps flashing 12:00. I've turned it off and back on with no luck! :lmfao:
     

    BiscuitsandGravy

    Future 'shootered'
    Site Supporter
    Rating - 100%
    11   0   0
    Nov 8, 2016
    4,041
    113
    At my Hermitage
    I got some more info about this Corporate Win PE drive today. It has a time bomb built in so it won't boot PE after a predetermined amount of time.

    We also use a LAPS tool that rotates the local admin password. I can expire that password after fixing a remote machine.

    This has been a Monday from Hell. I have people, even in this day, year 2024, that cannot tell the PC from a monitor from a docking station. People are CONSTANTLY calling the PC "box" a modem. I have people calling in new PC setup tickets for a laptop docking station thinking it's their new PC. I have people that "turn off & on" their computer only to see the same frozen screen because they only power cycled the monitor & not the PC.

    They live amongst us. :bash:
    Add in a cloud based PAM solution and it gets even more spicy.

    :ugh:
     

    DoggyDaddy

    Grandmaster
    Site Supporter
    Rating - 100%
    73   0   1
    Aug 18, 2011
    111,037
    149
    Southside Indy
    PAM. That is so old fashioned. Just use a modern non stick pan.
    Pam... When I was 4 or 5, these people from the hills of Tennessee moved in next door. They had a daughter named Pam. I had a crush on her even back then, and she was probably 6 or 7 years older than me. She babysat me a few times. She had incredible yayas. Probably not the same PAM.
     

    foszoe

    Grandmaster
    Site Supporter
    Rating - 100%
    24   0   0
    Jun 2, 2011
    17,318
    113
    Pam... When I was 4 or 5, these people from the hills of Tennessee moved in next door. They had a daughter named Pam. I had a crush on her even back then, and she was probably 6 or 7 years older than me. She babysat me a few times. She had incredible yayas. Probably not the same PAM.
    It's okay to have a crush on your babysitter, but to be infatuated with her grandmas is a little over the top.
     
    Top Bottom