1202
submitted 4 months ago* (last edited 4 months ago) by rxxrc@lemmy.ml to c/technology@lemmy.world

All our servers and company laptops went down at pretty much the same time. Laptops have been bootlooping to blue screen of death. It's all very exciting, personally, as someone not responsible for fixing it.

Apparently caused by a bad CrowdStrike update.

Edit: now being told we (who almost all generally work from home) need to come into the office Monday as they can only apply the fix in-person. We'll see if that changes over the weekend...

you are viewing a single comment's thread
view the rest of the comments
[-] Sylence@lemmy.dbzer0.com 24 points 4 months ago

There is a fix people have found which requires manual booting into safe mode and removal of a file causing the BSODs. No clue if/how they are going to implement a fix remotely when the affected machines can't even boot.

[-] letsgo@lemm.ee 10 points 4 months ago

Probably have to go old-skool and actually be at the machine.

[-] VieuxQueb@lemmy.ca 4 points 4 months ago

And hope you are not using BitLocker cause then you are screwed since BitLocker is tied to CS.

[-] Freefall@lemmy.world 3 points 4 months ago

Exactly, and super fun when all your systems are remote!!!

[-] Passerby6497@lemmy.world 3 points 4 months ago

It's not super awful as long as everything is virtual. It's annoying, but not painful like it would be for physical systems.

Really don't envy physical/desk side support folks today....

[-] EncryptKeeper@lemmy.world 3 points 4 months ago

You just need console access. Which if any of the affected servers are VMs, you’ll have.

[-] CanadaPlus@lemmy.sdf.org 3 points 4 months ago

Yes, VMs will be more manageable.

[-] ChefKalash@lemmy.dbzer0.com 2 points 4 months ago

Do you have any source on this?

[-] Sylence@lemmy.dbzer0.com 11 points 4 months ago

If you have an account you can view the support thread here: https://supportportal.crowdstrike.com/s/article/Tech-Alert-Windows-crashes-related-to-Falcon-Sensor-2024-07-19

Workaround Steps:

  1. Boot Windows into Safe Mode or the Windows Recovery Environment

  2. Navigate to the C:\Windows\System32\drivers\CrowdStrike directory

  3. Locate the file matching “C-00000291*.sys”, and delete it.

  4. Boot the host normally.

[-] Passerby6497@lemmy.world 9 points 4 months ago

I can confirm it works after applying it to >100 servers :/

[-] victorz@lemmy.world 4 points 4 months ago

Nice work, friend. 🤝 [back pat]

[-] CanadaPlus@lemmy.sdf.org 2 points 4 months ago

It seems like it's in like half of the news stories.

this post was submitted on 19 Jul 2024
1202 points (99.5% liked)

Technology

59454 readers
1870 users here now

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related content.
  3. Be excellent to each another!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, to ask if your bot can be added please contact us.
  9. Check for duplicates before posting, duplicates may be removed

Approved Bots


founded 1 year ago
MODERATORS