Petya
Not sure where exactly to post this question, so this is as good a spot as any. Listened to the webcast on petya - Alex stated that the worm has the ability to use password hashes to log into other workstations whose credentials are available on the infected computer. Does anyone know which credentials (or all) are vulnerable to being hijacked. I can think offhand of local login credentials, credentials used to connect to mapped drives, and credentials used for remote desktop. There are probably more. We have several contacts whitelisted in our fortimail, which could pose a direct threat to our system. Our backups run continuously day and night, so disconnecting them is not feasible, and running separate full backups would take days. I need to formulate a reasonable response to this threat so that our backups are protected, from what I see as a gross violation of security built into windows. It would help if I knew which credentials can be used for spreading the attack to other computers on the network.
