Case 522273 · Famous breaches · L1 Foundations
WannaCry
Practise as: Explain it · Interview
Interview questionWhy did WannaCry spread so fast in May 2017, and how was it stopped?
- 01 What is it?
- 02 How is it abused?
- 03 How do you stop it?
What a strong answer covers
Try it out loud first. Then check yourself:
- Worm launched 12 May 2017 using EternalBlue (SMBv1, MS17-010), a leaked NSA exploit published by Shadow Brokers
- Self-propagated over TCP 445 to unpatched Windows hosts; Microsoft had patched it in March 2017
- Hit 200,000+ machines in 150 countries; the UK NHS cancelled thousands of appointments
- Marcus Hutchins registered a hardcoded kill-switch domain, halting new infections
- Attributed to North Korea's Lazarus Group; lessons: patch, disable SMBv1, block 445 at the perimeter
If the interviewer pushes back
- Why did Microsoft release a patch for unsupported Windows XP, and what does that say about legacy risk?
Go deeper
cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.