Started By
Message

Crowdstrike

Posted on 7/19/24 at 4:53 pm
Posted by TAMU-93
Sachse, TX
Member since Oct 2012
1071 posts
Posted on 7/19/24 at 4:53 pm
Are any of y'all having to deal with this?

Statement on Today's Outage
Posted by Roy Curado
Member since Jul 2021
1356 posts
Posted on 7/19/24 at 5:24 pm to
Yes. Millions are having to deal with this since 12:30am this morning.
Posted by TAMU-93
Sachse, TX
Member since Oct 2012
1071 posts
Posted on 7/19/24 at 5:44 pm to
Are you having to physically intervene at each affected system? How many systems did you get fixed today? Have you been working since 12:30am?
Posted by Kracka
Lafayette, Louisiana
Member since Aug 2004
41581 posts
Posted on 7/19/24 at 5:44 pm to
I work in the IT dept for a Utility company, and we had over 600 computers affected by this. Been fixing machines all day.

quote:

Are you having to physically intervene at each affected system? How many systems did you get fixed today?


Yes we had to touch every affected system. Some were fixed with a hard reboot, other we had to log in and remove a crowd strike file. Crowd strike sent up a patch this morning that saved a lot of work. Made it even more tedious to have to navigate Bitlocker while trying to get into the machines.
This post was edited on 7/19/24 at 6:03 pm
Posted by GrammarKnotsi
Member since Feb 2013
9839 posts
Posted on 7/19/24 at 6:26 pm to
quote:

Are you having to physically intervene at each affected system? How many systems did you get fixed today? Have you been working since 12:30am?



we had 800 servers affected and im only on a Cyber team, wtf is your question ? go to the OT if you want details of how local people are dealing with it, ffs
Posted by TAMU-93
Sachse, TX
Member since Oct 2012
1071 posts
Posted on 7/19/24 at 6:37 pm to
quote:

wtf is your question


Well you just quoted three of them. I'm trying to have a tech discussion on the tech board about a tech issue, ffs.
Posted by Roy Curado
Member since Jul 2021
1356 posts
Posted on 7/19/24 at 7:03 pm to
quote:

we had 800 servers affected and im only on a Cyber team, wtf is your question ? go to the OT if you want details of how local people are dealing with it, ffs


I think this dude has been working since 12:30 am

Mr. Grumpy pants.
Posted by LSshoe
Burrowing through a pile o MikePoop
Member since Jan 2008
4297 posts
Posted on 7/19/24 at 8:28 pm to
Our mgmt software was configured to remove the affected files immediately upon coming online and checking in. Which meant for some we just had to get end users to boot into safe mode with networking, wait a few seconds and have them reboot. Sometimes easier said than done. Some we had to manually go in and purge.
Posted by VABuckeye
NOVA
Member since Dec 2007
37483 posts
Posted on 7/19/24 at 8:38 pm to
Deltek was down for us until 5 pm.
Posted by BabySam
FL
Member since Oct 2010
1528 posts
Posted on 7/19/24 at 8:41 pm to
Yep, shitstorm since 0035 for us and ruined my buttoning-up mindset for friday...on call bridge before i could even pour a coffee
Posted by TAMU-93
Sachse, TX
Member since Oct 2012
1071 posts
Posted on 7/19/24 at 9:24 pm to
quote:

Our mgmt software was configured to remove the affected files immediately upon coming online and checking in. Which meant for some we just had to get end users to boot into safe mode with networking, wait a few seconds and have them reboot. Sometimes easier said than done. Some we had to manually go in and purge.


Well that's fortunate. Having to manually delete that .sys file from every PC would have been an absolute nightmare.
Posted by bluebarracuda
Member since Oct 2011
18836 posts
Posted on 7/19/24 at 10:33 pm to
quote:

Our mgmt software was configured to remove the affected files immediately upon coming online and checking in.


What software is this?
Posted by TigerGman
Center of the Universe
Member since Sep 2006
12370 posts
Posted on 7/20/24 at 9:20 am to
Posted by Korkstand
Member since Nov 2003
28997 posts
Posted on 7/20/24 at 9:49 am to
quote:

quote:

Our mgmt software was configured to remove the affected files immediately upon coming online and checking in.
What software is this?
Can't most RMM tools do this?
Posted by hashtag
Comfy, AF
Member since Aug 2005
30062 posts
Posted on 7/20/24 at 12:17 pm to
quote:

Can't most RMM tools do this?
I'd think most would be disabled in Safe mode, no? Maybe using pxe boot would be an option?

I wrote a script that uses wmi to remove the file and then reboot the host. But, we had to get them in Safe Mode with networking first for that to work.
Posted by bluebarracuda
Member since Oct 2011
18836 posts
Posted on 7/20/24 at 2:04 pm to
quote:

But, we had to get them in Safe Mode with networking first for that to work.


Yep, same here for our hosts and our script.
Posted by finkle
Kansas City
Member since Jul 2016
67 posts
Posted on 7/20/24 at 4:49 pm to
I’ve been out of town and haven’t fired up home laptop or desktop, is bad code pulled? Will I be ok to start them up now?
Posted by Roy Curado
Member since Jul 2021
1356 posts
Posted on 7/20/24 at 5:04 pm to
Is your laptop or home desktop connected to a Falcon sensor?
Posted by finkle
Kansas City
Member since Jul 2016
67 posts
Posted on 7/20/24 at 5:34 pm to
I don’t know? So I’d say not, just personal home computers. I’d not heard of “Falcon” sensors until this event.
Posted by LemmyLives
Texas
Member since Mar 2019
9981 posts
Posted on 7/20/24 at 6:17 pm to
You will almost certainly be fine. CrowdStrike is a paid tool, so if you didn’t pay for it, you don’t have it. The angst is among people with company issued assets that do pay and install it. Our intranet says to contact your local office, which is either in Ohio or New Jersey. So my work laptop is a brick.
first pageprev pagePage 1 of 2Next pagelast page

Back to top
logoFollow TigerDroppings for LSU Football News
Follow us on X, Facebook and Instagram to get the latest updates on LSU Football and Recruiting.

FacebookXInstagram