{"id":4115,"date":"2009-01-30T09:13:38","date_gmt":"2009-01-30T14:13:38","guid":{"rendered":"http:\/\/www.shotinthedark.info\/wp\/?p=4115"},"modified":"2009-01-30T10:31:18","modified_gmt":"2009-01-30T15:31:18","slug":"when-i-was-in-radio","status":"publish","type":"post","link":"http:\/\/www.shotinthedark.info\/wp\/?p=4115","title":{"rendered":"When I Was In Radio&#8230;"},"content":{"rendered":"<p>&#8230;stories of disc jockeys who took immense creative revenge on stations that fired them were legion; some locked themselves into the studios and staged epic rants (that, often, improved their careers); others merely beat the crap out of their management (or tried).\u00a0 Smart management started making sure they had security on hand after a few of these stories.<\/p>\n<p>A lesson that IT management seems to be\u00a0 <a href=\"http:\/\/www.theregister.co.uk\/2009\/01\/29\/fannie_mae_sabotage_averted\/\">slow to learn:<\/a><\/p>\n<blockquote><p>Rajendrasinh Babubahai Makwana, 35, of Virginia, concealed the Unix script on Fannie Mae&#8217;s main administrative server on October 24, the same day the Unix engineer was terminated, according to court documents made public Tuesday. His script was programmed to remain dormant for three months, when it would greet administrators with a login message that read &#8220;Server Graveyard&#8221; and systematically replace all data with zeros on every production, administrative, and backup server in the company.Makwana was arrested on January 7 and released on $100,000 bond.<\/p><\/blockquote>\n<p>The plot?\u00a0 Well, it might have done Chloe O&#8217;Brien proud:<\/p>\n<blockquote><p>The allegations also lay out a cautionary tale about the risk of lax security practices at highly sensitive enterprises. Despite his dismissal on October 24, Makwana&#8217;s highly privileged computer access wasn&#8217;t terminated until late into the evening because of bureaucratic procedures in Fannie&#8217;s procurement department, according to court documents.<\/p>\n<p>Shortly after Makwana was informed he was being fired, he logged in to Fannie&#8217;s main development server and embedded a series of malicious scripts inside a legitimate program. To conceal the malicious payload, he created a page worth of blank lines between the legitimate code and the malicious code.<\/p>\n<p>&#8220;When the program ascertained it was January 31, 2009, it would copy the rest of the files from the &#8216;.soti&#8217; file from the dsysadm01 server and run the .y.sh script,&#8221; a FBI special agent wrote in a sworn statement that referred to Fannie as ABC to protect its identity. &#8220;The .y.sh script would place a blocker on the monitoring system disabling any ABC engineers from receiving a monitoring alert for any problems on any machines in the entire ABC environment for 61 minutes.&#8221;<\/p>\n<p>Makwana&#8217;s script would then disable logins to Fannie&#8217;s administrative and backup production servers; remove the root password appliance access; rewrite all data, including backup software, with zeros; and target any &#8220;high availability&#8221; software. It would then replicate itself to each of Fannie&#8217;s 4,000 servers.<\/p><\/blockquote>\n<p>Maybe he needs a government gig.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>&#8230;stories of disc jockeys who took immense creative revenge on stations that fired them were legion; some locked themselves into the studios and staged epic rants (that, often, improved their careers); others merely beat the crap out of their management (or tried).\u00a0 Smart management started making sure they had security on hand after a few [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[7,23],"tags":[],"class_list":["post-4115","post","type-post","status-publish","format-standard","hentry","category-crime-and-punishment","category-geekery"],"_links":{"self":[{"href":"http:\/\/www.shotinthedark.info\/wp\/index.php?rest_route=\/wp\/v2\/posts\/4115","targetHints":{"allow":["GET"]}}],"collection":[{"href":"http:\/\/www.shotinthedark.info\/wp\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.shotinthedark.info\/wp\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.shotinthedark.info\/wp\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"http:\/\/www.shotinthedark.info\/wp\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=4115"}],"version-history":[{"count":0,"href":"http:\/\/www.shotinthedark.info\/wp\/index.php?rest_route=\/wp\/v2\/posts\/4115\/revisions"}],"wp:attachment":[{"href":"http:\/\/www.shotinthedark.info\/wp\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=4115"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.shotinthedark.info\/wp\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=4115"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.shotinthedark.info\/wp\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=4115"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}