CrowdStrike: When an antivirus update took down the world

preview_player
Показать описание
CrowdStrike released a faulty update that crashed (BSOD) almost 8.5 million systems worse than any ransomware could, cough wannacry, causing the largest IT outage in history, hitting airports, emergency services and countless organizations. This video explores the incident and presents my take.

If you are affected by the issue go to safe mode cmd and use: del "C:\Windows\System32\drivers\CrowdStrike\C-00000291*.sys" to fix.

Рекомендации по теме
Комментарии
Автор

If you are affected by the issue go to safe mode cmd and use: del to fix.
....and Biden dropped out literally while I was uploading this video, not a dull moment this week. (Also, my voice sounds weird cause I have a cold)

pcsecuritychannel
Автор

My rage at everyone downplaying this for CrowdStrike is immeasurable. This is a billion dollar company, with a B, trusted by critical government, public, and private services and they shafted each and everyone. The lack of outrage from our authorities is absolutely disgusting. Speaks a lot to the state of cybersecurity and tech in general

EmperorShang
Автор

CrowdStrike: 62 minutes could bring your business down, HERE'S A QUICK DEMONSTRATION

sergeikrivenko
Автор

CrowdStrike: You can’t get malware on your system if you can’t boot up your system.

Robertganca
Автор

It feels to me that we are in an era of zero accountability. Corporations have grown to make such ridiculous sums of money that they can pay off any fines they get for screwing up, and the legal system is so broken they can get away with making outrageous contracts that free them from any responsability. That's how Crowdstrike can get away with bricking millions of PCs, Netflix and many other movie production houses can get away with not paying their screenwriters or even ACTORS, videogame producers can get away with half-baked games with full-price tags. They can because all of that is legal.

juanin
Автор

In almost any other situation, this mess would be a declaration of bankruptcy.

And no ... the irony of a "we protect you" company bricking millions of computers is not lost on me.

Douglas_Blake_
Автор

Do test before production kids.
-sun tzu, art of war

rekire___
Автор

The thing that annoys tme the most is any kind of basic testing would've revealed this bug before they released it. It shows a drastic lack of QA and CroudStrike deserves the criticism for what I feel is coorporate negligance.

Plazmal
Автор

CrowdStrike took a page from Adobe's playbook and found out.

Mionwang
Автор

My hospital got affected, and we in my IT department have spent the last three days getting everything back to "functional." We're exhausted.
We've been calling them Clownstrike, too. :|

Ms_Cheesecake
Автор

0:35 I DID notice that their 'channel files' are in a 'Clownstrike' folder. I move that there be a mandatory rename of the company to 'Clownstrike' for pushing an update on a Friday to ALL customers, not rolling out to a few to test.

stagefan
Автор

CrowdStrike: 62 minutes could bring your business down


Also, CrodStrike: *Hold my beer*

pauljoseph
Автор

Why TF this stupid piece of software is even used by all these companies in the first place.
All this software do is create a bunch of fancy looking stupid charts and graphs and shows how much "work" it has done and thats enough to fool company executives to sign a deal with em 😑.

exnozgaming
Автор

The one thing that made it possible for CrowdStrike software to cause these blue screen of death operating system crashes was that CrowdStrike software was written as a Microsoft Windows Device Driver, which allows CrowdStrike software to run at the privilege level of the operating system kernel. Ordinary software programs that run at a lower privilege level can only crash themselves and not crash the operating system.

davidgrisez
Автор

Waiting until Riot updates Vanguard and something like this happens

jnemeth
Автор

If only Crowdstrike's clients had used Kaspersky ... Crowdstrike have officially earned the title "Boeing of the S/W Industry".

sven
Автор

Who needs foreign actors with systems like these. 😅

MikaelKKarlsson
Автор

"i thought we had enough historic events for the week after this but i guess not."

Boy you ain't lie.

LARKXHIN
Автор

CrowdStrike need to pay, everyone should sue them. It's nice to charge billion of systems with nice dollars, but if make mistake just pretend is ok. It's not OK. If you buy a car with a defect and there is an accident, car company pay for damage, actually in every system or product, everyone is Accountable, only software company is NOT. Enough is Enough !

blynktest
Автор

Huge thanks for the brief mention! 💙

(PS, I'm not certain how viable the Group Policy deployment option is, but I'm happy to be schooled -- I believe that would require your domain controller (or whatever machine you push GPO changes out from) to not be stuck in the BSOD boot loop... as well as all the other downstream endpoints actually being in a stable enough state to receive and run those GPO changes... i.e., also not stuck in a BSOD boot loop 😅)

_JohnHammond