Image
 
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 25 guests and 1 member online
EH-Net Donations

Enter Amount:
$

Google Ads
EH-Net News Feeds
Latest Additions
Book Recommendations





 
Advertisement

You are here: Home arrow Forum arrow Resourcesarrow News from the Outside Worldarrow SF Mayor Breaks Up IT Standoff
Ethical Hacker Community Forums
December 01, 2008, 06:38:17 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: ChicagoCon 2-Day Ethical Hacking Conference with MS Blue Hats Oct 31 - Nov 1. Tickets Only $100! www.chicagocon.com/content/view/103/51/
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: SF Mayor Breaks Up IT Standoff  (Read 1421 times)
0 Members and 1 Guest are viewing this topic.
don
Editor-In-Chief
Administrator
Hero Member
*****
Online Online

Posts: 2380


Editor-In-Chief


View Profile WWW
« on: July 24, 2008, 10:34:39 PM »

Quote

Nine days after locking down the city's IT system, a disgruntled network administrator invites Mayor Newsom to his cell and gives him the access codes.

San Francisco Mayor Gavin Newsom demonstrated his negotiating prowess July 22 by breaking a nine-day-long standoff between an overly protective city network administrator and the city's attorney and IT department.

The San Francisco Chronicle reported that Newsom obtained the access codes to the city's IT system switches and routers after conferring with embattled network administrator Terry Childs, who has been in jail since July 13 on four felony counts of computer tampering in lieu of $5 million bail.

Childs, a certified Cisco Systems network administrator, changed access passwords for administrators above him because he claimed they were negligent about viruses and malware getting into the system. When he was threatened with suspension and loss of his job for insubordination, he locked down the system and kept the access codes to himself.

Childs was the chief designer of the system's FiberWAN (Fibre Channel-connected WAN), which contains about 60 percent of the city's sensitive HR, payroll and other personal data. The system has been running on virtual autopilot for the last 10 days while Department of Technology head Ron Vinson and others have been trying to regain access. Vinson declined to return numerous messages left on his office phone by eWEEK.

Childs, 43, a resident of Pittsburg, Calif., pleaded not guilty in court July 17 at his arraignment. He will have a bail hearing July 23 in hopes of lowering the $5 million bail levied by a judge last week.

He has worked for the city for five years and makes $127,000 per year.

Last week, the network administrator gave city officials what turned out to be incorrect passwords. On July 21, Childs' defense attorney, Erin Crane, approached the mayor's office about a secret meeting with Newsom, the Chronicle reported.

The visit was so hush-hush that Newsom did not tell District Attorney Kamala Harris or law enforcement officials he was going to do it, Newsom spokesperson Nathan Ballard told the Chronicle.

The city system also handles confidential law enforcement documents, inmates' bookings, payroll records, and departmental e-mail. Apparently, it has no backdoor access, even for highly authorized administrators.

Cisco engineers brought in by the city worked for days trying to break Childs' codes but with only minor success.

San Francisco Chronicle columnists Phil Matier and Andrew Ross have more details on how the standoff ended here.


Original story:
http://www.eweek.com/c/a/Security/SF-Mayor-Breaks-Up-IT-Standoff/

Don
Logged

CISSP, MCSE, CEH, Security+ SME
slimjim100
EH-Net Columnist
Sr. Member
*****
Offline Offline

Posts: 365



View Profile WWW
« Reply #1 on: July 26, 2008, 11:59:13 AM »

At first I thought this was a lame story since I figured you could just password rover the routers and switches but... It is possible... even with password recovery that is on by default, can be changed so that the boot break process in all the routers and switches could not accessible.. In highly secure networks you might want to turn off the boot break process and this prevents access to the confreg commands that can allow you to reset the password. So if the City really wanted in they would have to wipe all the devices and reset them. To re build a large network from scratch it could take weeks to months since 90% of the people on the network do not know the per-port design and how the VLAN's and links are routed. Now I am not agreeing with the administrator for locking other officials out but with sensitive records like HR he really could of been protecting the city to meet compliance like PIC,SOX, hippa & more...

Interesting little story...


Brian
Logged

CISSP, CCSE, CCNA, CCAI, Network+, Security+, JNCIA, & MCP
ChrisG
EH-Net Columnist
Hero Member
*****
Offline Offline

Posts: 1042


View Profile WWW
« Reply #2 on: July 27, 2008, 08:05:08 AM »

it will be interesting if they ever release how they got into that mess
Logged

...tests i took go here...

http://carnal0wnage.blogspot.com/
g00d_4sh
Sr. Member
****
Offline Offline

Posts: 295



View Profile
« Reply #3 on: July 28, 2008, 04:15:33 PM »

I don't remember where I saw it... may have been info world, but there is another article that has quotes from an 'insider' which paints the guy as a bit paranoid, but good intentioned.  He considered his bosses, and appearently a number of his compatriots, as a bit naive and ignorant to be messing around with the routers.  After some big arguments.... he wouldn't give them the 'keys to the kingdom' and they had him arrested over it.  Obviously, stupid idea his side.  On the bright side, the network was working wonderfully while no one could touch it.  Appearently he's an increadibly skilled network engineer.  Has his CCIE and such.
Logged

"Bad.. Good?  I'm the guy with the gun"
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.7 | SMF © 2006-2008, Simple Machines LLC
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.045 seconds with 23 queries.
 
Sponsors

cwnp_moto__120x90.gif

Polls
During the most recent election, I:
 
Support EH-Net


Support EH-Net by
Buying all of your
Amazon items using
the search bar above.

cbtnuggets_logo_125.jpg
Try CBT Nuggets Free!
Recent Forum Topics
Vote For EH-Net

progenic.com
Click here to Vote!

Sadikhov.com
Top IT Cert Sites

binarica.com
Binarica Logo

Add to Technorati Favorites
technorati fave

 
         
Advertisement

© 2008 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.