|
|
|
Tinkerisk:
Doesn't that ultimately matter to the end user? Some even claim that Windows itself is a virus. 😁
Facts don't matter to a lot of people. Doesn't mean they shouldn't be slapped around a bit with a large trout.
IRC days... seem so long ago now.
MadEngineer:
Anyone on the coalface for fixing this? I suspect a few machines (1-3% of fleet) were suffering from this fault a few weeks ago. BSOD then randomly fixing themselves after numerous reboots and power cycles. Sample size unfortunately has been too small and no details of the BSOD error.
Don't know what you are asking about. Below are Event log entries showing bugcheck 0x7e which is mentioned in multiple articles online.
=====
Log Name: System
Source: Microsoft-Windows-WER-SystemErrorReporting
Date: 21/07/2024 10:43:07
Event ID: 1001
Task Category: None
Level: Error
Keywords:
User: SYSTEM
Computer: pcname.domain.tld
Description:
The computer has rebooted from a bugcheck. The bugcheck was: 0x0000007e (0xffffffffc0000005, 0xfffff8002ece41cd, 0xffffc00bc62eead8, 0xffffc00bc62ee2f0). A dump was saved in: C:\WINDOWS\MEMORY.DMP. Report Id: 39e57a4c-826b-41fd-8294-5256dd5180b5.
===
Log Name: System
Source: Microsoft-Windows-WER-SystemErrorReporting
Date: 19/07/2024 17:08:27
Event ID: 1001
Task Category: None
Level: Error
Keywords:
User: SYSTEM
Computer: pcname.domain.tld
Description:
The computer has rebooted from a bugcheck. The bugcheck was: 0x00000050 (0xffffcc84000000b0, 0x0000000000000000, 0xfffff805791a14ed, 0x0000000000000002). A dump was saved in: C:\WINDOWS\Minidump\071924-32921-01.dmp. Report Id: 19b83832-eb41-4439-8639-801f25c0ad9e.
=====
We've basically finished getting our PC's & servers back online by deleting the C-00000291*.sys files.
Please keep this GZ community vibrant by contributing in a constructive & respectful manner.
SirHumphreyAppleby:
Facts don't matter to a lot of people. Doesn't mean they shouldn't be slapped around a bit with a large trout.
IRC days... seem so long ago now.
I'm sure you're right about that. However, that also says more about their general level of education and information than it does about catching trouts.
freitasm: Having a drink with friends at a Wellington bar last night, heard the bartender explaining this even to a couple of patrons as "a bad Windows Update, that usually comes on Wednesdays but was released on Friday."
Unless it was IT people, it's good enough. I'm sure he didn't criticise the fact that you asked for a Screaming Viking when every bartender would know the proper name is Drowned Fly.
Crowdstrike has posted their initial post incident report - https://www.crowdstrike.com/falcon-content-update-remediation-and-guidance-hub/
While what they say they are going to do going forward to ensure no invalid files will be shipped again sounds good. I'm rather shocked that they weren't doing a lot of what they propose already prior to shipping the files.
Security software companies are like shares. If every housewife (aka big company) gets in, you should get out as quickly as possible. Because it's not the admin who decides, but the one with the wallet, and he rarely has enough technical knowledge.
The past has shown that “too famous to fail” is a misconception when it comes to software. The bigger a dinosaur gets, the further away its brain is from its hands.
alavaliant:
I'm rather shocked that they weren't doing a lot of what they propose already prior to shipping the files.
Pretty much every RCA I've been involved with is like that. After the fact the question is "why the hell weren't we doing that in the first place?"
Usually it comes down to "we never had this happen before so didn't really think about it."
ANglEAUT:I meant for those machines with a similar fault from weeks ago I unfortunately didn't have the details for. I'm asking if anyone that has been working on this has had machines exhibiting the fault at an earlier time
MadEngineer:
Anyone on the coalface for fixing this? I suspect a few machines (1-3% of fleet) were suffering from this fault a few weeks ago. BSOD then randomly fixing themselves after numerous reboots and power cycles. Sample size unfortunately has been too small and no details of the BSOD error.
Don't know what you are asking about. Below are Event log entries showing bugcheck 0x7e which is mentioned in multiple articles online.
According to this exMicrosofter.
Its noted below that Apple does not allow any third party to play at this boot kernel level?
Provides services/API at a lower privaledge level only.
Apple being Apple you are not changing their mind.
Where Linux and Windows these companies play at boot kernel level which is easier for the security companies.
They have borked Linux systems on a number of occasions, but due to different kernels etc it was not 'everything all at once'.
CrowdStrike Update: Latest News, Lessons Learned from a Retired Microsoft Engineer
https://www.youtube.com/watch?v=ZHrayP-Y71Q
Then...
Here is a $10 Uber eats gift card for all the loss and extra work.
Oh those cards don't work as they cancelled them or Uber did thinking so many low value cards was a scam.
Diving into the embarrassing engineering behind CrowdStrike
Theo - t3․gg
https://www.youtube.com/watch?v=7rx4U5TlaqE
|
|
|