• FiveMacs
    link
    fedilink
    English
    52 months ago

    Wow…who could have predicted eggs in one basket is a BAD idea.

  • @over_clox
    link
    English
    52 months ago

    CrowdStrike fucked up big time didn’t they?

    • @jordanlundOPM
      link
      English
      42 months ago

      Oh, man, it’s bad. Been on a call at work all day.

      • @over_clox
        link
        English
        3
        edit-2
        2 months ago

        Damn. Did you catch the quick fix?

        CrowdStrike Fix
        
        1. Boot Windows into Safe Mode or WRE.
        
        2. Go to C:\Windows\System32\drivers\CrowdStrike
        
        3. Locate and delete file matching "C-00000291*.sys"
        
        4. Boot normally.```
        
        Edit: I'm not even about to figure out the formatting glitch here, this information just needs to be shared to help fix the problem.
        • @jordanlundOPM
          link
          English
          32 months ago

          Yup. The problem is a) rebooting in safe mode on remote/cloud servers. b) rebooting in safe mode if you’re also using BitLocker. :(

          An alternate suggestion from Microsoft is “reboot up to 15 times”.

          • @over_clox
            link
            English
            52 months ago

            Meanwhile, last I heard is Microsoft themselves uses Linux to run their Hotmail servers…

            Yeah, perhaps things aren’t the same today, but hell!

            • @Entropywins
              link
              English
              22 months ago

              I don’t blame Microsoft at all for having a Linux mail server…

          • @over_clox
            link
            English
            22 months ago

            Oh fuck, 15 times? That’s a fucking delay tactic to try to keep their phone lines from getting clogged, no joke.

    • @jordanlundOPM
      link
      English
      32 months ago

      I mean, it only took CrowdStrike to bring it all down.

      I don’t know how close you’ve been following it, but CrowdStrike pushed an updated config file that contained 42kb of 0’s.

      On reboot, Windows machines BSOD.

      • @thouartfrugal
        link
        English
        22 months ago

        Not closely at all; blissfully ignorant here in the peanut gallery :) Just read up a bit:

        CrowdStrike says users should boot the computer into Safe Mode or Windows Recovery Environment, navigate to the CrowdStrike directory, and delete the faulty file “C-00000291*.sys.”

        I read “users” as “IT support”, and “the computer” as “every affected computer in your organization”. I don’t envy those poor folks in IT. Well I often do actually, but not today!

        • @jordanlundOPM
          link
          English
          12 months ago

          Yeah, the alternate solution is to try re-booting 15 times.

  • @almar_quigley
    link
    English
    22 months ago

    Happy to say we have absolutely zero windows installations at my company. I feel like I have to be vigilant about keeping it that way. We do use crowdsteike but Linux for servers and containers and macOS for desktop clients.

    • @jordanlundOPM
      link
      English
      12 months ago

      We had a major service running on the Azure cloud that was impacted. :( It was back up by Saturday, fortunately.

      The whole “reboot into safe mode” was complicated by being in the cloud and further complicated by BitLocker. But we got it done!