Oleg Shevchenko2017-11-23 16:56:02
Oleg Shevchenko, 2017-11-23 16:56:02

What is the best way to organize a backup server on windows or Linux (whatever the encryptor does not work with)?

Give advice on how to do better. Requires a backup server. There is a supermicro platform for 4 baskets, i5, 16 GB. 4 baskets with 6TB disks. which OS is better to use. What is your opinion about XPE?

Answer the question

In order to leave comments, you need to log in

13 answer(s)
Dmitry, 2017-11-23

bareos on linux

Artem @Jump, 2017-11-23

which OS is better to use
It doesn't matter, all the salt is in the settings, and which axis is unimportant, and is selected based on convenience and other factors. With proper configuration, the encryptor will not work.
What is your opinion about XPE?
Haven't heard of this.

poisons, 2017-11-23


Alexander Chernykh, 2017-11-23

on Linux. raise ftp or rsync. ransomware uses smb

fdroid, 2017-11-23

ZFS + snapshots = profit. In fact, the easiest and most convenient way to organize backups, IMHO. Snapshot ZFS makes instantly. You can take a snapshot of the state at least every second, while the size of the snapshot does not take up the full amount of backed up information, but the difference between the previous snapshot and the new one. Disk space is used very conveniently and rationally. You can poke a wand in NAS4Free, put FreeBSD in production (ZFS is a native system for it) or Linux + ZFS On Linux.

Sergey Gornostaev, 2017-11-23

For backup, it is better to use hardware and software systems such as EMC Data Domain .

Alexey Cheremisin, 2017-11-23

I recommend taking a look at https://www.urbackup.org - very handy for smaller installations. I didn’t put in large ones, in large ones I put bareos (bakula).
It is put both under Windows and under Linux, both the server and clients.

younghacker, 2017-11-24

You can leave the usual samba or ftp
. Just put a cron task that runs through the backup directories and executes one command.
After this command, all files become readonly for everyone, even for root.
And the encryptor will not be able to do anything.

[[email protected] ~]# lsattr test-file.txt
-------------e-- test-file.txt
[[email protected] ~]# chattr +i test-file.txt
[[email protected] ~]# lsattr test-file.txt
----i--------e-- test-file.txt
[[email protected] ~]# rm test-file.txt
rm: remove regular file ‘test-file.txt’? y
rm: cannot remove ‘test-file.txt’: Operation not permitted

Similarly, you can move files to another directory that is readonly or that is not available to clients at all.
You need to clean the directories with the backup with the opposite command.
chattr -i test-file.txt
rm test-file.txt

But BareOS and other specialized products, as advised above, have not been canceled. :)

Victor Taran, 2017-11-24

And so let's figure it out.
1. The distribution itself does not really matter, in fact, any * nix like it will do, preferably, of course, a stable centos debian branch (without fanaticism for mint ubuntu, this can make the most unstable branches)
2. A stable FS ext4 - as an option even ext2 is easier to work with.
3. Cloud backup servers - perhaps more expensive but obviously more reliable than self-made, here you can argue but it's a fact.
4. https://ru.hetzner.com/hosting/storagebox/bx50 - cheap and cheerful, access via ftp webdov (partial ssh) - and if you are a legal entity, the price will be another 13% lower (VAT will be returned)
In the last In two cases, you take the service and not the server and its support in the future, and therefore save your time.
First, you do everything yourself.

fpir, 2017-11-30

I use Acronis because it's convenient and I can. I could not choose an axis on the server, but they gave me money for the backup program. Not complaining. The full archive can be opened by winrar, incremental-differential, everything is as it should be. Cryptographers do not seem to know how yet, but just in case, only the Acronis account has write access.

loderunner84, 2017-11-30

If xpe is xpenology, then I myself use this solution for backup. The main thing is that the disk controller is picked up

Alexey Rusakov, 2017-11-30

You can backup using Windows itself to a connected separate RAID (only for backups), the Windows archiver itself can format it and use it only for backups. You can backup directories, databases, virtual machines. This is not an expensive option and is quite reliable. You only need disks for the required volume.
I use a separate RAID for backups, without formatting with the Windows archiver. And additionally, I backup the script to WD MY CLOUD, which is on Linux.
It is important to know that if the ransomware is run under a user who does not have access rights to the archive, then the ransomware will not encrypt anything. Therefore, we give access to the archive directories only to the Administrator (not even to the Administrators group). Well, we set the password stronger on the Admin.

Fleg, 2017-11-30

Linux + Rsnapshot (more advanced utility than rsync).
A server with its own separate login - password. Collects from other servers everything himself.
Last year, I ran into a ransomware and came up with this scheme.

Didn't find what you were looking for?

Ask your question

Ask a Question

731 491 924 answers to any question