New user a security nightmare

Daily Newsletters

Sign up to ZDNet UK's daily newsletter.

ANALYSIS
As administrators, we often devote a lot of energy to external security. We install firewalls to protect the network from outside hackers. We use encryption to protect the data we send over the wire. We use group policies to control who has access and when. However, too often, we forget that the greatest threats can come from those who already have access to the network. I'm going to share the story of how one administrator dealt with an internal attack on her network and how it caused a reevaluation of internal security in her organisation. Meet the enemy
Internal security has always been a priority in the company where Debra works as a senior network engineer. Management has made it clear to users that they are not to share passwords and should never attempt to access information they are not intended to access. In fact, breaking either one of these rules can be grounds for termination. Nevertheless, that didn't stop one particular new employee from becoming a nuisance. A new associate in sales came to the IT department shortly after he started working at the company and wanted to talk about an idea he had to save the company money. Upper management encouraged IT to work with him since the idea involved cost savings. The company was considering purchasing an expensive software package. The sales associate claimed he could put together the same system using Linux, some other readily available open source packages, and a little programming. He met with IT and diagramed it all on a white board. It was impressive, and it sounded pretty easy to set up. All he needed to begin was a network connection for his Linux box. Feeling pressured by administration, IT gave him access but explained he would need to work with IT and contact them when he needed assistance. Mistake one
Debra was given the task of working with him on the project. She had been learning Linux and looking for areas where the company could use it on its network. She was excited about the project, but like her boss in IT, she was a little hesitant about the new associate's ideas, which seemed too good to be true. The new associate's office was equipped with two network connections: one to his company-supplied Windows NT PC and the other to his Linux box. He was not given any special access. He was a domain user like any other normal user. He was instructed to contact Debra if he needed additional access. About a week later, an IT employee was walking through the part of the building where the new associate had his office and noticed something out of the ordinary. A small generic network hub was plugged into a nearby network jack and was being used to span the port. A network cable was connected to a nearby server. This server was part of the project the new associate was working on. The hub was removed and the incident was reported. When confronted, the associate apologised and said he just wanted to get going on the project and didn't want to bother IT. Once again, he was informed that he needed to work with IT on this project. IT explained that a cable run was ordered and should be completed the next day. The break-in
A few days later, Debra was given the task of setting up his e-mail. She attempted to connect to his PC via PCAnywhere and received an error that the machine was not present. She checked Server Manager and verified the PC was active on the network. A check of the services on the associate's PC revealed that the PCAnywhere service had been stopped. She started the service without problem. Right away, she became suspicious. The PCAnywhere service typically does not stop unless it has a problem on startup. She checked the event log of the PC and didn't see any messages indicating the service had failed to start. She proceeded to connect and begin the Outlook setup process. At the end of the process, an authentication dialog popped up. Something was wrong. The IT departments has Outlook set to use the NT logon, and the only time the logon will appear is when NT does not recognise the account that is trying to access the mailbox. Debra clicked on the Start button to see who was logged on and was shocked to see "administrator." She turned to her manager in IT, who was standing behind her, and said, "He's changed the administrator password on this machine." To verify this, she logged off and attempted to log on with the administrator password. The password had been changed.

Talkback

Let me get this straight:

1) IT agrees to let this "associate" set up a Linux system
2) IT never gives him a network jack
3) IT is suspicious of Linux and the project even though they agreed to it
4) This associate is discouraged from installing software on his PC, even though IT could easily determine if the software is "safe"
5) The associate is discouraged from connecting his Linux box to the network
6) IT never gives this associate admin access to his own PC.

Why did they hire this guy in the first place? Sounds like a classic case of turf protection to me.

via Facebook 16 December, 2003 22:00
Reply

Post your comment

In order to post a comment you need to be registered and logged in.

You can also log in with Facebook. Log in or create your ZDNet UK account below

  • Login

Will not be displayed with your comment

By signing up for this service, you indicate that you agree to our Terms and Conditions and have read and understood our Privacy Policy. Questions about membership? Find the answers in the Community FAQ

Get ZDNet UK's daily newsletter

Enter your email address to sign up

ZDNet UK Live

Moley

@kevinmchapman. OK, I acknowledge that 'most' was a gratuitous throwaway comment as an afterthought and too presumptuous. As to proof, as you...

3 hours ago by Moley on A tale of two distros: Ubuntu and Linux Mint
Jack Schofield

@BrownieBoy > Works really well for thieves.... >> Nice attempt to deflect the argument by tossing in a point that's totally >> irrelevant, even...

4 hours ago by Jack Schofield on AMD Ultrathins to challenge Intel Ultrabooks
raskolnikof

fantastic that the so called piracy bills have been withdrawn. however, these anti-democracy supporters are still in the shadows so lets be alert...

5 hours ago by raskolnikof on SOPA, Protect IP support wavers in face of online protest
Tony Douglas

Please God no; teach them anything you like - thinking rationally, the uses and misuses of data, what data is and what it's not - but leave the...

7 hours ago by Tony Douglas via Facebook on Kids are the future. Teach ’em to code.
BrownieBoy

@Jack, > Works really well for thieves.... Nice attempt to deflect the argument by tossing in a point that's totally irrelevant, even it were...

21 hours ago by BrownieBoy on AMD Ultrathins to challenge Intel Ultrabooks
bootlegger

Make that 13 people now - I got refused today at Manchester airport. I thought I was up to date on this legislation - I knew of the EU ruling from...

1 day ago by bootlegger on UK airport body scans will not be opt out
tinycg

Don't forget to check out apps like GoodReader or SlideShark either, they're indispensible for people on the go in presentation situations. Best...

1 day ago by tinycg on Four top iPad apps for people on the move
TerryRK

Well it seems there is something a number of us agree on. Why is the Ubuntu Unity launcher so ugly? I thought perhaps it was something to do with...

1 day ago by TerryRK on A tale of two distros: Ubuntu and Linux Mint
Freebies202

Duplicate comments are not made intentionally. Its very good to know that now you are keeping check on this problem because sometimes a commenter...

2 days ago by Freebies202 on Microsoft fixes blog comments, speeds up blogs with open source
kevinmchapman

"the very significant number of users" and "many (most) of us" - you have no evidence for these statements. It is a fact that most users are saying...

2 days ago by kevinmchapman on A tale of two distros: Ubuntu and Linux Mint
Marg Menzies Harrison

Another grammar faux pas is the improper use of "you". When sitting down down in a restaurant, for example, I get cringe when the waitress...

2 days ago by Marg Menzies Harrison via Facebook on 10 flagrant grammar mistakes that make you look stupid
zdnetukuser

And NOW, folks, for Canonical's next trick... Kubuntu is late. Here's a pencil. Draw your own conclusions. cf.:...

2 days ago by zdnetukuser on Linux Minterface
Moley

@kevinmchapman. The discussion here reflects the very significant number of users who really do like the traditional menu system and who wish to...

2 days ago by Moley on A tale of two distros: Ubuntu and Linux Mint
kevinmchapman

Er, no... It is an efficient means of finding the application/file/setting you need in one place. The icons are a simply a fallback for when you...

2 days ago by kevinmchapman on A tale of two distros: Ubuntu and Linux Mint
TerryRK

Isn't the provision of a text based search an admission by the developers that the mass of icons approach does not work? I don't need to use a...

2 days ago by TerryRK on A tale of two distros: Ubuntu and Linux Mint
kevinmchapman

"Unity and GNOME 3 both abandon the old text-based cascading menus in favour of a graphical icon-driven system." Point truly missed. Both use a...

2 days ago by kevinmchapman on A tale of two distros: Ubuntu and Linux Mint
TerryRK

whs001 - Thank you, I'm glad you liked the article. I absolutely agree with you on your first point. I should perhaps have made it clearer that...

2 days ago by TerryRK on A tale of two distros: Ubuntu and Linux Mint
Dennis Nilsson

If we allow corporate interest to dictate the way our government circumvents due process against foreign entities then we should accept the same...

2 days ago by Dennis Nilsson via Facebook on ACTA stumbles in Germany
GHar123

I totally dislike pirating of works, I fear that artists will be deterred from creating works if they think that they are going to get ripped off....

2 days ago by GHar123 on ACTA stumbles in Germany
JCB33

How dare film makers, artists or anybody that invests in creativity stop us pirating their works for free. I want to be able to walk into my local...

3 days ago by JCB33 on ACTA stumbles in Germany