Recent Articles

Sys-Admin Services Lacking Social Software
Social Software technologies can improve collaboration and networking within and beyond the enterprise, but a general dearth of system and administrative...

FXCop Checks The Coding Practices Of Your Dot Net...
FXCop is one of the very few free tools you can use to check on the coding practices of a dot net assembly. If your company is building things in dot net, then this...

Understanding How Bitlocker Works
In an ongoing debate on if Bitlocker is truly secure, and if not what are the best ways to hack into the system, you need to understand how bitlocker works and...

Problems With Server Header Status Codes
Members at Webmaster World discusses about the problem of server header status codes. It is one of those topics that aren't touched often! According to the Webmasters World thread, almost every server...

Windows Vista SP1 Warrants Caution
If you're thinking about upgrading to Windows Vista SP1, you may want to think again. Although it was supposed to address users' and administrators' complaints...

IP Address As Personal Information
In some very interesting news coming out of the European Union, the IP Address that you use should be regarded as "personal information" meaning it now...


07.17.08

City System Admin Locks Out Everyone

By Dan Morrill

Terry Childs is cooling his jets in jail, while the city of San Francisco tries to get back control of its FiberWan network, this is why no one single person should ever have total access to anything.

Dark reading is reporting on the story of Terry Childs, a city System Administrator who has locked out just about everyone from the Cities networked computing systems ranging from Payroll to Inmate booking files. He refuses to give up the password, and so far to date cracking the password has not worked, so the city is being held hostage to this very troubled insider.

His actions could cost the city millions of dollars when all is said and done, but an even bigger fear is that he may have set up a logic bomb of sorts to destroy sensitive documents, or may even have an accomplice finishing off his dirty work. No sign of that so far, but the guy did set up a monitoring tool to track what other administrators were doing or saying about his personnel case, according to the report. But officials say the network so far has been humming along just fine without admin access by the city. Source: Dark Reading

Realistically this is troubling for just about any company, and should be setting off warning bells to managers if they have employees that have single person access to anything on the corporate or city networks. While the City tries to regain control of its networks, Childs still has not given up the password, and it is unknown what the city is trying to do to recover the password or why it is taking so long.


The other interesting fear, which is well justified at this point is that Childs might have set up a logic bomb that could potentially destroy or damage the files that the city keeps in electronic records.

What is known through is that Childs was a disciplinary problem, and the city had worked out a way to fire the person until they figured out that he had effectively tampered with the network to set up a form of insurance policy that he could use in the event that they did try to fire him. So while he is in jail, it is also unknown if he will make some kind of deal to reduced charges and less prison time.

With companies starting to fire people or laying them off because of a slowing economy, companies and government need ot make sure that no one has the sole key to the kingdom. People could be unpleasantly surprised if they suddenly wake up to a formatted network, and formatted network systems because someone decided that they wanted to get back at their former place of employment because they were let go.

Comments


About the Author:
Dan Morrill has been in the information security field for 18 years, both civilian and military, and is currently working on his Doctor of Management. Dan shares his insights on the important security issues of today through his blog, Managing Intellectual Property & IT Security, and is an active participant in the ITtoolbox blogging community.
About SysAdminNews
SysAdminNews is a collection of articles, news and commentary designed to keep system administrators informed about the latest trends impacting their profession. Updates and Advice for System Administrators





SysAdminNews is brought to you by:

SecurityConfig.com NetworkingFiles.com
NetworkNewz.com WebProASP.com
SysAdminNews.com SQLProNews.com
ITcertificationNews.com SysAdminNews.com
LinuxProNews.com WirelessProNews.com
CProgrammingTrends.com ITManagementNews.com





-- SysAdminNews is an iEntry, Inc. publication --
iEntry, Inc. 2549 Richmond Rd. Lexington KY, 40509
2008 iEntry, Inc.  All Rights Reserved  Privacy Policy  Legal

archives | advertising info | news headlines | free newsletters | comments/feedback | submit article


Database Forum Updates and Advice for System Administrators SysAdminNews News Archives About Us Feedback SysAdminNews.com About Article Archive News Downloads WebProWorld Forums iEntry Advertise Contact Jayde