CrowdStrike Take Down Internet

Looks like CrowdStrike has caused a massive BSOD wave!

They pushed an update yesterday on the falcon sensor which is crashing windows!

Happy Friday!

Yep the amount of P1’s at work this morning is wild.

We had to rollback to 11PM yesterday, that god our DBs are on Linux

1 Like

The MSP I work for is impacted by this however the actual client was smart enough to not use crowd strike and thus were unaffected

Worst part is it’s not a quick fix, some systems wont even boot without manually going into safe mode and removing CrowdStrike. They need to have manual intervention. CrowdStrike have basically hit the red button and locked computers. The computers will not be able to get any updates from CrowdStrike lol

1 Like

image

3 Likes

Yeah apparently the fix is to

  1. Safe boot
  2. Go to C:\Windows\System32\drivers\CrowdStrike
  3. Locate and delete file matching “C-00000291*.sys”

Millions of systems going to be affected, happy funking Friday

Yeah the issue is, can’t remotely deploy that lol.

Same thing happened with Webroot in years gone by. They pushed a dodgy update and exactly the same thing happened.
Needs to be a failsafe mechanism built into Windows that if something causes a BSOD it auto reverts and strips anything that was updated to the last working known configuration. I know this can be done manually but Winblows needs to get good.

Just shows how resilient windows is. This is why major infra should be on Linux.

2 Likes

skynet_azure-cdh

4 Likes

My MSP published just that, to go into safe mode and remove CrowdStrike… Want to know the great thing? It required Admin perms and we are not given Admin perms

1 Like

Yep the amount of P1’s at work this morning is wild.

Try working at a massive law firm with offices all over the UK but base all IT staff in one town… (East Midlands area).

“Fancy flying to Dublin to assist handling this P1?”

Yeah no thanks.

1 Like

I would’ve done that! Heck yeah, no work

Didn’t do much for the share price

1 Like

Buy some shares quick, it’ll be next weeks chip paper and stocks will recover :grin:

1 Like

Wayyyyy ahead of you lol. Didn’t drop much mind you

Oooof

Casually waiting for the perfect point to jump

2 Likes
1 Like