如何从Google Cloud Storage(GCS)恢复未加密的历史文件版本?
Absolutely, you can recover your unencrypted files—thank goodness you had version control enabled on GCS! That feature is exactly what saves the day here. Below are two straightforward ways to get your clean files back:
通过Google Cloud Console操作(适合少量文件)
- Log into your Google Cloud Console, navigate to Cloud Storage > Browser, and locate your target bucket.
- Find the encrypted file, click the three-dot menu (More actions) next to its name, then select Version history.
- You’ll see all 4 retained versions with timestamps. Look for the version created before the ransomware infection (cross-check the timestamp to confirm it’s pre-encryption).
- Select that version and click Restore—this will make it the active current version. For multiple files, you can check boxes next to their valid historical versions and use the bulk restore option.
通过gcloud CLI操作(适合批量文件)
If you’ve got a lot of files to recover, the command line is way more efficient:
First, list all versions of a file to identify the unencrypted one:
gsutil ls -la gs://your-bucket-name/path/to/encrypted-file.extThe output will show each version’s timestamp and version ID. Pick the ID corresponding to the pre-infection version.
Restore a single file:
gsutil cp gs://your-bucket-name/path/to/encrypted-file.ext#<version-id> gs://your-bucket-name/path/to/encrypted-file.extReplace
<version-id>with the actual ID you found in the previous step.Bulk restore example (bash script):
If you need to restore all files in a directory to their latest pre-infection version, use a script like this (adjust the values to match your setup):# Configure your settings BUCKET="your-bucket-name" TARGET_DIR="path/to/affected-directory" # Set the timestamp of when the infection started (ISO 8601 format) INFECTION_START="2024-05-18T00:00:00Z" # Loop through all file versions gsutil ls -la gs://$BUCKET/$TARGET_DIR/** | while read -r line; do # Extract version details VERSION_ID=$(echo "$line" | awk '{print $3}') FILE_TIMESTAMP=$(echo "$line" | awk '{print $1, $2}') FULL_PATH=$(echo "$line" | awk '{print $4}') # Skip the active (non-versioned) file entry if [[ ! "$FULL_PATH" == *"#"* ]]; then continue fi # Get the original file path without the version ID ORIGINAL_FILE=$(echo "$FULL_PATH" | sed 's/#.*//') # Restore if this version is from before the infection if [[ "$FILE_TIMESTAMP" < "$INFECTION_START" ]]; then echo "Restoring $ORIGINAL_FILE from version $VERSION_ID" gsutil cp "$FULL_PATH" "$ORIGINAL_FILE" # Break after restoring the latest pre-infection version per file break fi done
Important Notes
- After restoring, immediately copy the recovered unencrypted files to a separate bucket or create a snapshot—this prevents any accidental re-overwrite from your rsync script.
- Audit your rsync setup: Add checks like verifying file hashes or scanning for unusual file extensions before syncing to avoid repeating this issue.
- If you’re unsure which version is unencrypted, download a test version first to confirm its content before doing bulk restores.
内容的提问来源于stack exchange,提问作者Ian H

