TelkomUseless
Honorary Master
- Joined
- Mar 13, 2006
- Messages
- 16,139
- Reaction score
- 10,552
It is uploaded to your current system state.
That state is backed up and the next one is backed up etc.
Eventually all your backups are infected.
There is no recovery, hence why the ransom is paid, or you start from scratch.
hmm. I'm not sure how they work... but there is no access to servers (and password access on ports). If I open ransomware, only I will get infected (not servers). And If the server is infected, it can't spread because servers are locked down.
Their SQL server backups should be offsite backed up etc. Can't be infected with it. And you should always had a release build ready to restore any time.
I look at the environment were I work... no way this would happen. Everything is locked down. And if it does, we can rollback data to hour before. And release the live branch.
I still think can't imagine being offline for days due to this if they took security serious.