What's new

Global IT Outtage-Microsoft/CrowdStrike

Ohhhf. Pack up boys, you're headed home today. Never a fun to watch another race crew pack in early.
1000029697.jpg
Kurtz was on Jim Cramer this morning, I was wondering if the broadcast was from VIR or if he has headed back to HQ already.

Guessing my $400 call options will expire worthless today. :grinpimp:

Good luck mate
 
This was my morning, or watching a movie. Same blue screen. Restart just brought a different blue screen. Fuckers had it fixed before lunch though. :flipoff:
Yup. Called in for my 2 Friday morning calls, but blind as can be.

Email still working on mobile. Last update is all affected will receive a call from IT to walk thru the fix. But I’m away most of the afternoon, so who knows when it’ll get wrapped up. :lmao:
 
Alex Jones calls another one. He said there'd be a major crash this week. Not a fan but he's been more right than wrong.


.
 
Our whole accounting system is fuxored. Other than that, we are doing fine.
 
This isn't really related to Microsoft at all. This is 100% a CrowdStrike EDR fuck up. They sent a channel file out that was full of Null. This is essentially a small driver file that is loaded at the kernel level of the OS, BEFORE everything, including the network stack. The kernel attempts to load the null driver and to protect itself, it blue screens, as it is designed to do.

The primary issue here is that this happens before the network stack is loaded, so there is no way to send an updated channel file before the BSOD hence the fix HAS to be manual intervention. The reboots thing may or may not work. I've heard reports of people rebooting 20+ and still nothing. The issue is also more complicated if a whole disk encryption is used like BitLocker.

I don't envy IT right now. :beer: And for the first time I am glad we use Trellix for EDR and not CrowdStrike :laughing::flipoff2:

Probably have to boot the affected into safe mode and update the driver via USB. I don’t do MS stuff, so just a guess.

It’s a goat rope at best.
 
I'm stuck in Raleigh trying to get home. Delta flights cancelled. Can't rent a car, they are down or not allowing one ways.

Found a southwest flight to Atlanta, then going to get a ride home and go pick up my car from Chattanooga later.

Fuck computers
 
Probably have to boot the affected into safe mode and update the driver via USB. I don’t do MS stuff, so just a guess.

It’s a goat rope at best.
basically boot to safe mode without networking, remove a set of files, reboot.
the issue is that those of us with bitlocker encryption can't always boot into safe mode
 
Probably have to boot the affected into safe mode and update the driver via USB. I don’t do MS stuff, so just a guess.

It’s a goat rope at best.
1. Boot Windows into safe mode or the Windows Recovery Environment.

2. Navigate to the C:\Windows\System32\drivers\CrowdStrike directory.

3. Locate the file matching “C-00000291*.sys” and delete it.

4. Reboot
 
1. Boot Windows into safe mode or the Windows Recovery Environment.

2. Navigate to the C:\Windows\System32\drivers\CrowdStrike directory.

3. Locate the file matching “C-00000291*.sys” and delete it.

4. Reboot
Exact instructions our IT sent out this morning. But everyone in the company has bitlocker.:homer:

And for the IT challenged, the file starts with "C-00000291". It has some more numbers after that.
 
Exact instructions our IT sent out this morning. But everyone in the company has bitlocker.:homer:

And for the IT challenged, the file starts with "C-00000291". It has some more numbers after that.
Can you still do a DOS style command from the root so you don't have to hunt it down?
 
Exact instructions our IT sent out this morning. But everyone in the company has bitlocker.:homer:

And for the IT challenged, the file starts with "C-00000291". It has some more numbers after that.
Fixt it for ya.

1. Boot Windows into safe mode or the Windows Recovery Environment.

2. Navigate to the C:\Windows\System32\drivers\CrowdStrike directory.

3. Locate the file matching “C-00000291*.sys” and delete it.

4. Reboot

5. If you have BitLocker, jump of a bridge.


But really, if the enterprise was keeping the BitLocker recovery keys in Active Directory (like they should be), it shouldn't add but a little more time telling someone over the phone their 48 digit key :lmao::lmao: "No, I said E, not C"
 
Fixt it for ya.

1. Boot Windows into safe mode or the Windows Recovery Environment.

2. Navigate to the C:\Windows\System32\drivers\CrowdStrike directory.

3. Locate the file matching “C-00000291*.sys” and delete it.

4. Reboot

5. If you have BitLocker, jump of a bridge.


But really, if the enterprise was keeping the BitLocker recovery keys in Active Directory (like they should be), it shouldn't add but a little more time telling someone over the phone their 48 digit key :lmao::lmao: "No, I said E, not C"
you just email it in plain text
cause that's easier.
:laughing:
 
Got into work to find my computer in a blue screen loop. Oh well for the stuff I was trying to run overnight.
Same but I got pissed, ripped the power cord out, plugged it in and it fixed it. Next step if that didn't was punching it.
Had no idear about crowds trike or whatever till now.
 
I'm stuck in Raleigh trying to get home. Delta flights cancelled. Can't rent a car, they are down or not allowing one ways.

Found a southwest flight to Atlanta, then going to get a ride home and go pick up my car from Chattanooga later.

Fuck computers

Where you headed. Im into a 6-8 hour delay.

Hoping it will hold, and maybe home tonight
 
Our son and family were red-eye flying out from California to Georgia last night, and made it as far as their first leg to Denver They had boarded their connection flight to Houston, then were told to deplane due to a "glitch". They slept at the airport. Just found out at 6:30 pm that they finally made to Houston, but there were further delays for final destination to Atlanta. So far they have logged 30 hours of little travel, on what would normally have been a 4.5 hour flight....
 
Fixt it for ya.

1. Boot Windows into safe mode or the Windows Recovery Environment.

2. Navigate to the C:\Windows\System32\drivers\CrowdStrike directory.

3. Locate the file matching “C-00000291*.sys” and delete it.

4. Reboot

5. If you have BitLocker, jump of a bridge.


But really, if the enterprise was keeping the BitLocker recovery keys in Active Directory (like they should be), it shouldn't add but a little more time telling someone over the phone their 48 digit key :lmao::lmao: "No, I said E, not C"

This was my entire day and we use bitlocker (keys are in intune)

I found that the recovery environment with command line is the most efficient method to do this, and most users were able to follow my specific instructions (we had to fix over 3k, 1 by 1)
 
Where you headed. Im into a 6-8 hour delay.

Hoping it will hold, and maybe home tonight
Need to end up back in Chattanooga to get my car at some point, but my house is halfway better Atlanta and Chattanooga, if I can just get home today I'll be happy.

Delta offered me tomorrow at 1pm with 3 legs and 14 hours total time or 8pm with 3 legs and 11 hours flight time. Southwest got a lot of business today
 
Our son and family were red-eye flying out from California to Georgia last night, and made it as far as their first leg to Denver They had boarded their connection flight to Houston, then were told to deplane due to a "glitch". They slept at the airport. Just found out at 6:30 pm that they finally made to Houston, but there were further delays for final destination to Atlanta. So far they have logged 30 hours of little travel, on what would normally have been a 4.5 hour flight....
Fuuuuuuck!
 
Our son and family were red-eye flying out from California to Georgia last night, and made it as far as their first leg to Denver They had boarded their connection flight to Houston, then were told to deplane due to a "glitch". They slept at the airport. Just found out at 6:30 pm that they finally made to Houston, but there were further delays for final destination to Atlanta. So far they have logged 30 hours of little travel, on what would normally have been a 4.5 hour flight....

That's crazy. Atlanta is Deltas momma airport. Usually they have multiple flights into there.

Need to end up back in Chattanooga to get my car at some point, but my house is halfway better Atlanta and Chattanooga, if I can just get home today I'll be happy.

Delta offered me tomorrow at 1pm with 3 legs and 14 hours total time or 8pm with 3 legs and 11 hours flight time. Southwest got a lot of business today

Damn, sounds doable with a car. Safe travels.
 
Our GPS systems are active, but the electronic logs aren't transmitting. violation reports are rolling in left and right, as the server isn't being told of any status changes where the drivers went to sleep after midnight and the mainframe thinks they have been driving up to 18 hours straight..
Yep. Exact same with our system (Samsara)
 
Top Back Refresh