Open cardosec

Case 522273 · Famous breaches · L1 Foundations

WannaCry

Practise as: Explain it · Interview

Interview questionWhy did WannaCry spread so fast in May 2017, and how was it stopped?

  1. 01 What is it?
  2. 02 How is it abused?
  3. 03 How do you stop it?
What a strong answer covers

Try it out loud first. Then check yourself:

  1. Worm launched 12 May 2017 using EternalBlue (SMBv1, MS17-010), a leaked NSA exploit published by Shadow Brokers
  2. Self-propagated over TCP 445 to unpatched Windows hosts; Microsoft had patched it in March 2017
  3. Hit 200,000+ machines in 150 countries; the UK NHS cancelled thousands of appointments
  4. Marcus Hutchins registered a hardcoded kill-switch domain, halting new infections
  5. Attributed to North Korea's Lazarus Group; lessons: patch, disable SMBv1, block 445 at the perimeter

If the interviewer pushes back

  • Why did Microsoft release a patch for unsupported Windows XP, and what does that say about legacy risk?

Go deeper

cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.