Data held to ransom
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page
- Plusnet Community
- :
- Forum
- :
- Other forums
- :
- Tech Help - Software/Hardware etc
- :
- Data held to ransom
Data held to ransom
14-11-2016 11:37 AM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
An acquaintance I work with has just been hacked and his data is being held to ransom.
I've since heard this is not an unusual event.
What precautions can be taken to prevent this type of hacking. Does virus protection work against it?

Re: Data held to ransom
14-11-2016 11:43 AM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
Frequent backups, and common sense are the only things I can suggest. AV might help in some regards but it's not always the case, Word Document (Macros) are now being used to deliver this type of payload, there is also an exploit that targets outlook that uses place holders to select a name from your address book to imply that you know the sender.
If there is a back up available revert to it and don't pay anything.
Re: Data held to ransom
14-11-2016 12:20 PM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
Could this still happen if you only used Linux whilst online ?

Re: Data held to ransom
14-11-2016 1:08 PM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
Yes, Linux is not immune to ransomeware, as I've said in another thread this (ransomeware) can be done using only javascript so the platform is of no consequence.
Re: Data held to ransom
14-11-2016 3:41 PM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
But you could only encrypt files that you were authorised to write to in Linux.
So the basic system and other users would be protected.
"In The Beginning Was The Word, And The Word Was Aardvark."
Re: Data held to ransom
14-11-2016 4:05 PM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
The basic system is not targeted on Windows - so that you still have an intact computer with which to pay the ransom! I don't know about other users.
Re: Data held to ransom
14-11-2016 9:21 PM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
@Anonymous wrote:
Yes, Linux is not immune to ransomeware, as I've said in another thread this (ransomeware) can be done using only javascript so the platform is of no consequence.
Yeah I got hit by one of those javascript ransom pages a few weeks ago. It kept calling a javascript alert box which made closing the tab frustrating. When I did eventually crash it and close the tab and looked at the source code, I couldn't believe just how well it had been obfuscated.
I actually called the number on the page too and got through to someone... where I proceeded to tell them exactly what I thought of them - with several profanities included before making it known that I'd got around their little hijacking session.
Anyhow.. yes regular backups are a good thing (and I should learn from that too) but the usual don't click links, don't open unknown attachments etc etc still applies. Using webmail is also a good idea as it keeps any payloads on a remote server instead of downloading it straight to your PC.
Ultimately for the super paranoid you could always browse the web using a virtual machine and have a network share on the desktop so that you can move files between it and the host PC. Or you could do it the other way around - use a virtual machine for file storage (again with a network connection) and have any external USB drives connected to it instead of the host (if you chose not to store the files inside the VM). Then you could simply copy the VM over to multiple external drives for backup.. and if your main system gets hit then you can have it up and running again with minimal fuss - just install a vm player.
If for whatever crazy reason you do ring up and make the payment be sure to remove all excess funds from that account and then have the card cancelled straight after (perform a chargeback if possible too).
Re: Data held to ransom
15-11-2016 8:50 AM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
For data held to ransom you are usually requested to make a transfer payment in bitcoins - which is an exercise in itself.

Re: Data held to ransom
15-11-2016 9:13 AM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
@7up wrote:
Yeah I got hit by one of those javascript ransom pages a few weeks ago. It kept calling a javascript alert box which made closing the tab frustrating. When I did eventually crash it and close the tab and looked at the source code, I couldn't believe just how well it had been obfuscated.
I actually called the number on the page too and got through to someone... where I proceeded to tell them exactly what I thought of them - with several profanities included before making it known that I'd got around their little hijacking session.
@7up - I for one would be interested to hear how you manage to get round the hijack, as you normally don't know anything till it's too late!
Also if you were asked to pay by credit card this sounds to me like a lame attempt at a hijack as @ReedRichards says most, if not all, ransoms are paid in bitcoins so it's untraceable.
Re: Data held to ransom
15-11-2016 10:44 AM - edited 15-11-2016 10:47 AM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
I've had that several times.
Each time I simply turned off the pc and deleted the usual cache and cookies etc. After starting back up there was never any sign of anything bad.
A bluff maybe, there was no sign my virus checker had stopped anything?
If there was a problem I would have just installed the partition backup.
I assume there is hard core ransomware and also bluffware which depends on the reputation of the other.
Re: Data held to ransom
15-11-2016 12:49 PM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
We seem to be getting confused between web pages (which may or may not use Java) designed to scare you into calling a telephone number and the data ransom software which runs actively on your computer for some time, encrypts all your user files and only then tells you about it. Where I have seen this done, the security software only managed tor remove some of the encryption software and not enough to stop it working.
Re: Data held to ransom
15-11-2016 2:11 PM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
@billnotben wrote:
I've had that several times.
Each time I simply turned off the pc and deleted the usual cache and cookies etc. After starting back up there was never any sign of anything bad.
A bluff maybe, there was no sign my virus checker had stopped anything?
If there was a problem I would have just installed the partition backup.
I assume there is hard core ransomware and also bluffware which depends on the reputation of the other.
I've never had anything like that, but if I did I could just use the
killall firefox command (in Linux) and save myself from a possible corrupt filesystem.
"In The Beginning Was The Word, And The Word Was Aardvark."
Re: Data held to ransom
15-11-2016 8:24 PM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
Re: Data held to ransom
15-11-2016 9:25 PM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
Doesn't do anything.
Windows is still insecure.
"In The Beginning Was The Word, And The Word Was Aardvark."
Re: Data held to ransom
16-11-2016 7:49 AM
- Mark as New
- Bookmark
- Subscribe
- Subscribe to RSS Feed
- Highlight
- Report to Moderator
I see plenty of Mac computers running fake security software or fake downloaders or with the default browser search engine hijacked. MacOS is supposed to be derived from Linux, isn't it? If you or your teenage kids can be tricked into installing the wrong software then it will happen on any OS.
- Subscribe to RSS Feed
- Mark Topic as New
- Mark Topic as Read
- Float this Topic for Current User
- Bookmark
- Subscribe
- Printer Friendly Page