Warning: Constant WP_TEMP_DIR already defined in /var/www/html/blogs/glenn/wp-config.php on line 94

Warning: Cannot modify header information - headers already sent by (output started at /var/www/html/blogs/glenn/wp-config.php:94) in /var/www/html/blogs/glenn/wp-includes/rest-api/class-wp-rest-server.php on line 1902

Warning: Cannot modify header information - headers already sent by (output started at /var/www/html/blogs/glenn/wp-config.php:94) in /var/www/html/blogs/glenn/wp-includes/rest-api/class-wp-rest-server.php on line 1902

Warning: Cannot modify header information - headers already sent by (output started at /var/www/html/blogs/glenn/wp-config.php:94) in /var/www/html/blogs/glenn/wp-includes/rest-api/class-wp-rest-server.php on line 1902

Warning: Cannot modify header information - headers already sent by (output started at /var/www/html/blogs/glenn/wp-config.php:94) in /var/www/html/blogs/glenn/wp-includes/rest-api/class-wp-rest-server.php on line 1902

Warning: Cannot modify header information - headers already sent by (output started at /var/www/html/blogs/glenn/wp-config.php:94) in /var/www/html/blogs/glenn/wp-includes/rest-api/class-wp-rest-server.php on line 1902

Warning: Cannot modify header information - headers already sent by (output started at /var/www/html/blogs/glenn/wp-config.php:94) in /var/www/html/blogs/glenn/wp-includes/rest-api/class-wp-rest-server.php on line 1902

Warning: Cannot modify header information - headers already sent by (output started at /var/www/html/blogs/glenn/wp-config.php:94) in /var/www/html/blogs/glenn/wp-includes/rest-api/class-wp-rest-server.php on line 1902

Warning: Cannot modify header information - headers already sent by (output started at /var/www/html/blogs/glenn/wp-config.php:94) in /var/www/html/blogs/glenn/wp-includes/rest-api/class-wp-rest-server.php on line 1902
{"id":1185,"date":"2017-05-16T10:48:13","date_gmt":"2017-05-16T17:48:13","guid":{"rendered":"http:\/\/3.209.169.194\/blogs\/glenn\/?p=1185"},"modified":"2017-05-16T10:48:13","modified_gmt":"2017-05-16T17:48:13","slug":"guidance-for-wannacryptwannacry-attacks","status":"publish","type":"post","link":"https:\/\/www.sqlskills.com\/blogs\/glenn\/guidance-for-wannacryptwannacry-attacks\/","title":{"rendered":"Guidance for WannaCrypt\/WannaCry Attacks"},"content":{"rendered":"

There has been quite a bit of media coverage about the WannaCrypt\/WannaCry ransomware over the past several days. Microsoft has a new page<\/a> with information about this particular issue and steps that can be taken to protect your systems. I have also collected some more detailed background information about this and about SQL Server security patching in general. <\/p>\n

Just to be clear, there is no known threat to SQL Server from this method, but there was an out of band security update for SQL Server 2012, 2014, and 2016 that was released on November 8, 2016<\/a>. Here are the most current cumulative updates for SQL Server 2012, 2014, and 2016 (which will include that security update). <\/p>\n

\n

SQL Server 2012<\/strong>              SQL Server 2012 SP3 CU9<\/a>            11.0.6598.0                      May 15, 2017 <\/p>\n

SQL Server 2014<\/strong>              SQL Server 2014 SP2 CU5<\/a>            12.0.5546.0                      April 17, 2017 <\/p>\n

SQL Server 2016<\/strong>              SQL Server 2016 SP1 CU3<\/a>            13.0.4435.0                      May 15, 2017<\/p>\n<\/blockquote>\n

  <\/p>\n

WannaCrypt\/WannaCry Information<\/b> <\/p>\n

Here are some links to useful resources about this outbreak. Making sure your servers and client machines are current with their Microsoft Update hotfixes and possibly disabling SMB v1 are the best defenses. <\/p>\n

\n

Alert (TA17-132A) Indicators Associated With WannaCry Ransomware<\/a> <\/p>\n

Microsoft Security Bulletin MS17-010 \u2013 Critical<\/a> <\/p>\n

MS17-010: Description of the security update for Windows SMB Server: March 14, 2017<\/a> <\/p>\n

Windows Update Catalog Download Links<\/a><\/p>\n<\/blockquote>\n

<\/b>  <\/p>\n

SMB v1 Information<\/b> <\/p>\n

Another mitigation measure for this vulnerability is to disable Server Message Block (SMB) v1 (which has been deprecated since Windows Server 2012). Depending on what version of Windows Server you are running, you may be able to do this using various methods. <\/p>\n

\n

The Deprecation of SMB1 \u2013 You should be planning to get rid of this old SMB dialect<\/a> <\/p>\n

Stop using SMB1<\/a> <\/p>\n

How to enable and disable SMBv1, SMBv2, and SMBv3 in Windows and Windows Server<\/a><\/p>\n<\/blockquote>\n

  <\/p>\n

SQL Server Security Update Information<\/b> <\/p>\n

Microsoft now recommends proactively installing SQL Server Cumulative Updates as they become available. The most recent, specific security update (MS16-136) for SQL Server 2012, 2014, and 2016 was released on November 8, 2016. If you are up to date with your SQL Server Service Packs and Cumulative Updates, you will already have that SQL Server security update. Just to be clear, there is no indication that SQL Server is vulnerable to WannaCry. It is merely a best practice to stay current with SQL Server security and other updates. <\/p>\n

\n

Announcing updates to the SQL Server Incremental Servicing Model (ISM)<\/a> <\/p>\n

Where to find information about the latest SQL Server builds<\/a> <\/p>\n

MS16-136: Security update for SQL Server: November 8, 2016<\/a><\/p>\n<\/blockquote>\n

  <\/p>\n

Finally, there are a number of other good reasons to make an effort to keep your SQL Server instances up to date with the latest Service Pack and Cumulative Update. I highlight some of the more important hotfixes for every cumulative update in the blog posts linked below: <\/p>\n

\n

Performance and Stability Related Fixes in Post-SQL Server 2012 SP3 Builds<\/a><\/p>\n

Performance and Stability Related Fixes in Post-SQL Server 2014 SP1 Builds<\/a><\/p>\n

Performance and Stability Related Fixes in Post-SQL Server 2014 SP2 Builds<\/a><\/p>\n

Performance and Stability Related Fixes in Post-SQL Server 2016 SP1 Builds<\/a><\/p>\n<\/blockquote>\n","protected":false},"excerpt":{"rendered":"

There has been quite a bit of media coverage about the WannaCrypt\/WannaCry ransomware over the past several days. Microsoft has a new page with information about this particular issue and steps that can be taken to protect your systems. I have also collected some more detailed background information about this and about SQL Server security […]<\/p>\n","protected":false},"author":7,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[13,343,31,156,246],"tags":[344,346,345],"class_list":["post-1185","post","type-post","status-publish","format-standard","hentry","category-sql-server-cumulative-updates","category-security","category-sql-server-2012","category-sql-server-2014","category-sql-server-2016","tag-security","tag-wannacry","tag-wannacrypt"],"yoast_head":"\nGuidance for WannaCrypt\/WannaCry Attacks - Glenn Berry<\/title>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.sqlskills.com\/blogs\/glenn\/guidance-for-wannacryptwannacry-attacks\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Guidance for WannaCrypt\/WannaCry Attacks - Glenn Berry\" \/>\n<meta property=\"og:description\" content=\"There has been quite a bit of media coverage about the WannaCrypt\/WannaCry ransomware over the past several days. Microsoft has a new page with information about this particular issue and steps that can be taken to protect your systems. I have also collected some more detailed background information about this and about SQL Server security […]\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.sqlskills.com\/blogs\/glenn\/guidance-for-wannacryptwannacry-attacks\/\" \/>\n<meta property=\"og:site_name\" content=\"Glenn Berry\" \/>\n<meta property=\"article:published_time\" content=\"2017-05-16T17:48:13+00:00\" \/>\n<meta name=\"author\" content=\"Glenn Berry\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Glenn Berry\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"3 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.sqlskills.com\/blogs\/glenn\/guidance-for-wannacryptwannacry-attacks\/\",\"url\":\"https:\/\/www.sqlskills.com\/blogs\/glenn\/guidance-for-wannacryptwannacry-attacks\/\",\"name\":\"Guidance for WannaCrypt\/WannaCry Attacks - Glenn Berry\",\"isPartOf\":{\"@id\":\"https:\/\/www.sqlskills.com\/blogs\/glenn\/#website\"},\"datePublished\":\"2017-05-16T17:48:13+00:00\",\"author\":{\"@id\":\"https:\/\/www.sqlskills.com\/blogs\/glenn\/#\/schema\/person\/57a8972435106bac7970692fcf5edfa7\"},\"breadcrumb\":{\"@id\":\"https:\/\/www.sqlskills.com\/blogs\/glenn\/guidance-for-wannacryptwannacry-attacks\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.sqlskills.com\/blogs\/glenn\/guidance-for-wannacryptwannacry-attacks\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.sqlskills.com\/blogs\/glenn\/guidance-for-wannacryptwannacry-attacks\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/www.sqlskills.com\/blogs\/glenn\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Guidance for WannaCrypt\/WannaCry Attacks\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.sqlskills.com\/blogs\/glenn\/#website\",\"url\":\"https:\/\/www.sqlskills.com\/blogs\/glenn\/\",\"name\":\"Glenn Berry\",\"description\":\"Semi-random musings about SQL Server performance\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.sqlskills.com\/blogs\/glenn\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.sqlskills.com\/blogs\/glenn\/#\/schema\/person\/57a8972435106bac7970692fcf5edfa7\",\"name\":\"Glenn Berry\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.sqlskills.com\/blogs\/glenn\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/64bdac8830f25f2f8cc780f8a1286c66ff1182218009271e7a953639596f7e25?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/64bdac8830f25f2f8cc780f8a1286c66ff1182218009271e7a953639596f7e25?s=96&d=mm&r=g\",\"caption\":\"Glenn Berry\"},\"sameAs\":[\"https:\/\/www.sqlskills.com\/blogs\/glenn\/\"],\"url\":\"https:\/\/www.sqlskills.com\/blogs\/glenn\/author\/glenn\/\"}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"Guidance for WannaCrypt\/WannaCry Attacks - Glenn Berry","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.sqlskills.com\/blogs\/glenn\/guidance-for-wannacryptwannacry-attacks\/","og_locale":"en_US","og_type":"article","og_title":"Guidance for WannaCrypt\/WannaCry Attacks - Glenn Berry","og_description":"There has been quite a bit of media coverage about the WannaCrypt\/WannaCry ransomware over the past several days. Microsoft has a new page with information about this particular issue and steps that can be taken to protect your systems. I have also collected some more detailed background information about this and about SQL Server security […]","og_url":"https:\/\/www.sqlskills.com\/blogs\/glenn\/guidance-for-wannacryptwannacry-attacks\/","og_site_name":"Glenn Berry","article_published_time":"2017-05-16T17:48:13+00:00","author":"Glenn Berry","twitter_misc":{"Written by":"Glenn Berry","Est. reading time":"3 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/www.sqlskills.com\/blogs\/glenn\/guidance-for-wannacryptwannacry-attacks\/","url":"https:\/\/www.sqlskills.com\/blogs\/glenn\/guidance-for-wannacryptwannacry-attacks\/","name":"Guidance for WannaCrypt\/WannaCry Attacks - Glenn Berry","isPartOf":{"@id":"https:\/\/www.sqlskills.com\/blogs\/glenn\/#website"},"datePublished":"2017-05-16T17:48:13+00:00","author":{"@id":"https:\/\/www.sqlskills.com\/blogs\/glenn\/#\/schema\/person\/57a8972435106bac7970692fcf5edfa7"},"breadcrumb":{"@id":"https:\/\/www.sqlskills.com\/blogs\/glenn\/guidance-for-wannacryptwannacry-attacks\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.sqlskills.com\/blogs\/glenn\/guidance-for-wannacryptwannacry-attacks\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/www.sqlskills.com\/blogs\/glenn\/guidance-for-wannacryptwannacry-attacks\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.sqlskills.com\/blogs\/glenn\/"},{"@type":"ListItem","position":2,"name":"Guidance for WannaCrypt\/WannaCry Attacks"}]},{"@type":"WebSite","@id":"https:\/\/www.sqlskills.com\/blogs\/glenn\/#website","url":"https:\/\/www.sqlskills.com\/blogs\/glenn\/","name":"Glenn Berry","description":"Semi-random musings about SQL Server performance","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.sqlskills.com\/blogs\/glenn\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/www.sqlskills.com\/blogs\/glenn\/#\/schema\/person\/57a8972435106bac7970692fcf5edfa7","name":"Glenn Berry","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.sqlskills.com\/blogs\/glenn\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/64bdac8830f25f2f8cc780f8a1286c66ff1182218009271e7a953639596f7e25?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/64bdac8830f25f2f8cc780f8a1286c66ff1182218009271e7a953639596f7e25?s=96&d=mm&r=g","caption":"Glenn Berry"},"sameAs":["https:\/\/www.sqlskills.com\/blogs\/glenn\/"],"url":"https:\/\/www.sqlskills.com\/blogs\/glenn\/author\/glenn\/"}]}},"_links":{"self":[{"href":"https:\/\/www.sqlskills.com\/blogs\/glenn\/wp-json\/wp\/v2\/posts\/1185","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.sqlskills.com\/blogs\/glenn\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.sqlskills.com\/blogs\/glenn\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.sqlskills.com\/blogs\/glenn\/wp-json\/wp\/v2\/users\/7"}],"replies":[{"embeddable":true,"href":"https:\/\/www.sqlskills.com\/blogs\/glenn\/wp-json\/wp\/v2\/comments?post=1185"}],"version-history":[{"count":0,"href":"https:\/\/www.sqlskills.com\/blogs\/glenn\/wp-json\/wp\/v2\/posts\/1185\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.sqlskills.com\/blogs\/glenn\/wp-json\/wp\/v2\/media?parent=1185"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.sqlskills.com\/blogs\/glenn\/wp-json\/wp\/v2\/categories?post=1185"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.sqlskills.com\/blogs\/glenn\/wp-json\/wp\/v2\/tags?post=1185"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}