Follow Slashdot stories on Twitter

 



Forgot your password?
typodupeerror
×
Security United States IT

Disgruntled Engineer Hijacks San Francisco's Computer System 1082

ceswiedler writes "A disgruntled software engineer has hijacked San Francisco's new multimillion-dollar municipal computer system. When the Department of Technology tried to fire him, he disabled all administrative passwords other than his own. He was taken into custody but has so far refused to provide the password, and the department has yet to regain admin access on their own. They're worried that he or an associate might be able to destroy hundreds of thousands of sensitive documents, including emails, payroll information, and law enforcement documents."
This discussion has been archived. No new comments can be posted.

Disgruntled Engineer Hijacks San Francisco's Computer System

Comments Filter:
  • Backups? (Score:5, Funny)

    by anonieuweling ( 536832 ) on Tuesday July 15, 2008 @08:53AM (#24194381)
    With backups no data will be lost. Oh, those are encrypted?
  • by dunelin ( 111356 ) on Tuesday July 15, 2008 @08:53AM (#24194391)

    Next thing you know, we'll have some dinosaurs on the Presidio.

  • by Anonymous Coward on Tuesday July 15, 2008 @08:55AM (#24194419)

    Give me my job back and you get your passwords, otherwise I'll just post how I did it on slashdot

  • by Swizec ( 978239 ) on Tuesday July 15, 2008 @09:03AM (#24194517) Homepage
    Is what I say ...
  • Job Posting (Score:5, Funny)

    by Anonymous Coward on Tuesday July 15, 2008 @09:04AM (#24194531)

    Large municipal department of technology seeking software engineer for a multimillion-dollar computer system. At least 5 years of previous experience required. Must be able to gain administrative access to a system where the password is not known. Hiring immediately!

  • I've been in a position to do this (I was still rooted from home in three systems, and though they changed the passwords, they didn't kick active sessions) and all I did was change the MOTD to "When firing a user with root access, make sure to abort existing sessions."

    Professionalism is key if you expect to be trusted with access to big sexy systems.

  • by Anonymous Coward on Tuesday July 15, 2008 @09:11AM (#24194639)

    Aah, yes. The battle cry of the unwashed hippie, flailing around in his white-boy dreads and demanding that "TEH MANG" redistribute the wealth of people who've accomplished something to those who majored in "Gender Studies and Womyn Subjugated by the Phallocracy."

  • by Anonymous Coward on Tuesday July 15, 2008 @09:11AM (#24194641)

    Thats why you run unpatched windows, it will take only 4 minutes to get access.

  • by wild_quinine ( 998562 ) on Tuesday July 15, 2008 @09:13AM (#24194665)

    Number one rule in IT. If i have PHYSICAL access to a system i can get in. Some way, some how.

    Government Agency rule number one: If I have PHYSICAL access to a criminal, I can get information. Some way, some how.

  • by 192939495969798999 ( 58312 ) <infoNO@SPAMdevinmoore.com> on Tuesday July 15, 2008 @09:14AM (#24194679) Homepage Journal

    From TFA: "Prosecutors say Childs, who works in the Department of Technology at a base salary of just over $126,000"

    No wonder he was disgruntled, that's not even a living wage in San Francisco.

  • by martin-boundary ( 547041 ) on Tuesday July 15, 2008 @09:15AM (#24194697)
    Nah, they should just reboot the system. That always works, I've seen it countless times in movies.
  • by Anonymous Coward on Tuesday July 15, 2008 @09:17AM (#24194725)
    So your employer has the right to look at your genitals whenever he wants? I'm glad I'm not your employer.
  • Re:RTFA (Score:5, Funny)

    by alexgieg ( 948359 ) <alexgieg@gmail.com> on Tuesday July 15, 2008 @09:19AM (#24194775) Homepage

    What do you recommend they do next time, use a crystal ball or ouija board to predict who's going to pull such a stunt?

    Minority Report for system administration activities? Sweet! ;-)

  • by MadKeithV ( 102058 ) on Tuesday July 15, 2008 @09:20AM (#24194783)
    +1 worrying ;-)
  • by melikamp ( 631205 ) on Tuesday July 15, 2008 @09:22AM (#24194813) Homepage Journal

    [...] trusted with access to big sexy systems.

    Mmm, fat chicks... <drool>

  • by bickerdyke ( 670000 ) on Tuesday July 15, 2008 @09:33AM (#24194941)
    "going municipal"?
  • by Anonymous Coward on Tuesday July 15, 2008 @09:37AM (#24195015)

    he will probably get a sentence more than a rapist but less than a murderer. The state considers screwing with it the highest crime

    I think that answers the question.

  • by Minwee ( 522556 ) <dcr@neverwhen.org> on Tuesday July 15, 2008 @09:39AM (#24195049) Homepage
    To say nothing of the obvious error in step 4.
  • by bigstrat2003 ( 1058574 ) * on Tuesday July 15, 2008 @09:41AM (#24195075)

    ...no need to hold the passowrd holder out the window by his ankles 'til he squeals.

    Yeah, but it's fun!

  • by Beat The Odds ( 1109173 ) on Tuesday July 15, 2008 @09:50AM (#24195247)

    Nah, they should just reboot the system. That always works, I've seen it countless times in movies.

    no, no, no..... You have to ESCAPE the system. What movie's you been watchin'?

  • by thelexx ( 237096 ) on Tuesday July 15, 2008 @09:53AM (#24195293)

    Well, if they had nothing to hide then they have nothing to worry about right?

  • by GottaDIY ( 1301323 ) on Tuesday July 15, 2008 @09:55AM (#24195311)
    It only works when you have to run past a pack of Raptors.
  • Re:Backups? (Score:4, Funny)

    by omnichad ( 1198475 ) on Tuesday July 15, 2008 @09:58AM (#24195365) Homepage
    I hear the University of Illinois is building a computer to help crack it!
  • by Anonymous Coward on Tuesday July 15, 2008 @09:59AM (#24195409)

    Meh, just use the password cracker that figures out one letter at a time. It takes half a minute, tops.

  • Re:Frankly (Score:4, Funny)

    by damburger ( 981828 ) on Tuesday July 15, 2008 @10:01AM (#24195443)
    Yes, I've heard something along the lines of 'the Republican party say that government doesnt work, and when they get elected they try to prove it'
  • Step 1: make bomb
    Step 2: go to spice market
    Step 3: asplode self and random shoppers
    Step 4: Prophet

  • Re:Backups? (Score:5, Funny)

    by Anonymous Coward on Tuesday July 15, 2008 @10:08AM (#24195575)

    I'll put good money on him cracking before this article gets 200 comments.

    We're at 204. Pay up.

  • by rodney dill ( 631059 ) on Tuesday July 15, 2008 @10:10AM (#24195613) Journal
    ...the police did give the codes back, but now the city is mysteriously spending 20% more on police salarys.
  • by jason.sweet ( 1272826 ) on Tuesday July 15, 2008 @10:14AM (#24195679)

    Unless they are totally incompetent

    They couldn't event successfully fire the guy.

    -- Firefox isn't as as great as people claim it is.

  • by celle ( 906675 ) on Tuesday July 15, 2008 @10:15AM (#24195689)

    When I was still in college I had heard of a programmer at one of the nearby companies had rigged the payroll system she wrote. I guess they hired her on little more than a vocal agreement and fired her after they thought the job was finished. Oddly enough she thought she had a long term job, go figure. Anyway, her payroll system was setup to payout $100,000 checks to every employee on payday one month after her name was off the rolls. Suffice it to say they had to hire her back with real terms of employment and she made them follow through with their previous agreement as well.

    Just remember, capitalism is a dog eat dog system. If you don't protect yourself, no one else will. Business and government are notorious for screwing people when its convenient and even when its not, even those they depend upon. Just remember, even if you have a glowing employee record, there's always going to be some prick above or even below you that can intentionally or unintentionally mess things up, that's when you don't do it yourself.

  • Re:Backups? (Score:2, Funny)

    by Anonymous Coward on Tuesday July 15, 2008 @10:15AM (#24195697)

    You download audio files containing pornographic content?

    This is disturbing.

  • by Anonymous Coward on Tuesday July 15, 2008 @10:23AM (#24195817)

    What the heck is an unsuccessful attempt to fire?

  • by wattrlz ( 1162603 ) on Tuesday July 15, 2008 @10:31AM (#24195973)
    Especially if he's the only guy who knows what he's doing.
  • by BigDaddyOttawa ( 948206 ) on Tuesday July 15, 2008 @10:32AM (#24195991) Homepage
    Paul, is that you? Could you come to Meeting Room 1 for an important staff meeting. Ignore John standing behind you with that box, he's just collecting them to build a fort.
  • by Anonymous Coward on Tuesday July 15, 2008 @10:33AM (#24196021)

    He should be waterboarded. He'll give up those passwords REAL quick.

  • Re:Backups? (Score:5, Funny)

    by wild_quinine ( 998562 ) on Tuesday July 15, 2008 @10:35AM (#24196047)

    I'll put good money on him cracking before this article gets 200 comments.

    We're at 204. Pay up.

    Alright, it's in an untraceable paypal account. Obviously I'm not handing over the password.

  • by Rocketship Underpant ( 804162 ) on Tuesday July 15, 2008 @10:36AM (#24196065)

    Yes, but that involves a perilous trip through the cavernous sub-basement to some rarely touched master reboot switch, and while the system is restarting all the perimeter fences will be de-electrified and the motion sensors inactive. In movies, this situation inevitably leads to lots of screaming and mayhem.

  • by Chibi ( 232518 ) on Tuesday July 15, 2008 @10:42AM (#24196179) Journal
    If they (the technology department) were smart, they would make it a practical interview. Ask the interviewee if they can gain administrative access to the system. If they say yes, let them try. If they can't do it, you thank them, but let them know that they aren't qualified for the position. If they *can* gain access, you thank them, and let them know that the position is no longer required.~
  • by wattrlz ( 1162603 ) on Tuesday July 15, 2008 @10:49AM (#24196287)
    I know a guy who has a similar story, except he said something that amounted to, " I'm now a consultant, please add a zero to what you were paying me and I'll gladly come in and change the password on your system."
  • Re:Backups? (Score:5, Funny)

    by Anonymous Coward on Tuesday July 15, 2008 @10:52AM (#24196343)
    Unfortunately, he said he would put "good money" on it and all he has is US Dollars.
  • by Anonymous Coward on Tuesday July 15, 2008 @10:55AM (#24196407)

    I'm glad I'm not your employer.

    I'm glad you're my employee ;). Now show me your genitals [youtube.com]

    I'm glad you're mine. Now get back to work.

  • by phorm ( 591458 ) on Tuesday July 15, 2008 @10:58AM (#24196445) Journal

    Here it is...

    Dear Mr. Baker,

    As an employee of an institution of higher education, I have few very basic expectations. Chief among these is that my direct superiors have an intellect that ranges above the common ground squirrel. After your consistent and annoying harassment of my co-workers and me during our commission of duties, I can only surmise that you are one of the few true genetic wastes of our time.

    Asking me, a network administrator, to explain every nuance of everything I do each time you happen to stroll into my office is not only a waste of time, but also a waste of precious oxygen. I was hired because I know how to network computer systems, and you were apparently hired to provide amusement to your employees, who watch you vainly attempt to understand the concept of "cut and paste" as it is explained to you for the hundredth time.

    You will never understand computers. Something as incredibly simple as binary still gives you too many options. You will also never understand why people hate you, but I am going to try and explain it to you, even though I am sure this will be just as effective as telling you what an IP is. Your shiny new iMac has more personality than you ever will.

    You wander around the building all day, shiftlessly seeking fault in others. You have a sharp dressed, useless look about you that may have worked for your interview, but now that you actually have responsibility, you pawn it off on overworked staff, hoping their talent will cover for your glaring ineptitude. In a world of managerial evolution, you are the blue-green algae that everyone else eats and laughs at. Managers like you are a sad proof of the Dilbert principle.

    Seeing as this situation is unlikely to change without you getting a full frontal lobotomy reversal, I am forced to tender my resignation; however, I have a few parting thoughts:

    When someone calls you in reference to employment, it is illegal for you to give me a bad recommendation as I have consistently performed my duties and even more. The most you can say to hurt me is, "I prefer not to comment." To keep you honest, I will have friends randomly call you over the next couple of years, because I know you would be unable to do it on your own.

    I have all the passwords to every account on the system and I know every password you have used for the last five years. If you decide to get cute, I will publish your "Favorites," which I conveniently saved when you made me "back up" your useless files. I do believe that terms like "Lolita" are not viewed favorably by the university administrations.

    When you borrowed the digital camera to "take pictures of your mother's b-day," you neglected to mention that you were going to take nude pictures of yourself in the mirror. Then, like the techno-moron you are, you forgot to erase them. Suffice it to say, I have never seen such odd acts with a ketchup bottle. I assure you that those photos are being kept in safe places pending your authoring of a glowing letter of recommendation. (And, for once, would you please try to use spellcheck? I hate correcting your mistakes.)

    I expect the letter of recommendation on my desk by 8:00 am tomorrow. One word of this to anybody and all of your twisted little repugnant obsessions will become public knowledge. Never f*ck with your systems administrator, Mr. Baker! They know what you do with all that free time!

    Sincerely

    David Blocker

    Network Administrator

  • by Anonymous Coward on Tuesday July 15, 2008 @11:10AM (#24196651)

    For a small amount you can own the only password to SAN FRANSISCO computer systems.

    starting bid: $500,000.00

  • by Anonymous Coward on Tuesday July 15, 2008 @11:13AM (#24196697)

    They couldn't event successfully fire the guy

    Irony, thy name is jason.sweet.

  • by thc4k ( 951561 ) on Tuesday July 15, 2008 @11:25AM (#24196899) Homepage

    1. declare him a terrorist
    2. torture him
    3. ???? [redacted for national security reasons]
    4. password!

  • by operagost ( 62405 ) on Tuesday July 15, 2008 @11:39AM (#24197131) Homepage Journal

    They should have put him in the basement and stopped paying him.

    I understand the fatal mistake was taking his red stapler.

  • by Skapare ( 16644 ) on Tuesday July 15, 2008 @11:54AM (#24197403) Homepage

    They basically told me that if I didn't give them my password I was fired. I absolutely REFUSED. Never do you ever need to have someone give you their password. A so-called security expert should know this.

    So eventually I drove over there, typed in my password for them, and drove back to my office. They didn't find anything, obviously, and I got the machine back completely wiped two weeks later.

    What you should have done was give them some random string of gibberish (write it down and keep it yourself so you can repeat the same exact string when asked again). They still won't be able to get in. Finally, when you have to go over there and help them, pull out that little piece of paper and type that random gibberish in again. When you also get access denied, repeat a few times more slowly. Then finally turn around and look at the idiots and say "You broke it!".

  • Re:Backups? (Score:2, Funny)

    by JWSmythe ( 446288 ) * <jwsmythe@[ ]mythe.com ['jws' in gap]> on Tuesday July 15, 2008 @11:55AM (#24197431) Homepage Journal

    You don't need a live cd. Just about every version of *nix I've worked with has some way to get root locally. Almost all of them have a single user mode, or some way to change init to /bin/sh.

        For windows .. well heck, why am I going to give up all the answers. If they want the answers, they can hire me and my own select team of sysadmins to go through and clean up that mess. The contact page is on my site. :)

        But yes, I've had to do quite a bit of cleanup over the years with lost passwords, or ex-employees "forgetting" them. Usually I don't need a disk.

        He obviously didn't do his job very well. They should have been able to lock him out at a moment's notice, and the other admins would keep running the show. It may be bad for job security through extortion, but it's good security practice. So what if you don't want to leave the job, it's your employers network, not yours.

  • Re:Backups? (Score:5, Funny)

    by Hognoxious ( 631665 ) on Tuesday July 15, 2008 @11:58AM (#24197495) Homepage Journal
    Shhhhhh!
  • Re:Backups? (Score:2, Funny)

    by Anonymous Coward on Tuesday July 15, 2008 @12:00PM (#24197531)

    Imagine if the payrolls have been tampered with (payroll files are mentioned in the article) rather than destroyed. And the law (and other) documents have had the word "not" randomly removed in 0.5% of the occurrences ;), and a few numbers changed by a few percent.

    Yeah. I heard that the new blood alcohol limit in San Fran is 3.08%. What's up with that??!?!

  • by NathanE ( 3144 ) on Tuesday July 15, 2008 @12:32PM (#24198173)

    Hey, I have a FANTASTIC idea: lets let the goverment run our healthcare! I'm told it is the land of milk and honey.

  • by Holi ( 250190 ) on Tuesday July 15, 2008 @12:32PM (#24198181)

    Oh please Italy has had RI since before I was born.

  • Re:Backups? (Score:4, Funny)

    by jddj ( 1085169 ) on Tuesday July 15, 2008 @01:10PM (#24198923) Journal

    he just went from being fired to Fed-pound-you-Penn

    Where he'll doubtless learn what it's like to be gruntled

  • Re:Backups? (Score:3, Funny)

    by goofyspouse ( 817551 ) on Tuesday July 15, 2008 @01:26PM (#24199205)
    They are significantly better than Zimbabwe Dollars at the moment...
  • Re:Backups? (Score:5, Funny)

    by nospam007 ( 722110 ) on Tuesday July 15, 2008 @01:36PM (#24199383)

    >You are being disingenuous at best. Are your roads in order, is the traffic calm and orderly? Do you have electricity in your home? Are you being raided by armed bandits? what about clean water, can you drink the water coming out of your faucet? What about the mail, is it being delivered?

    Are you saying if he gives up the password the potholes will be fixed, the traffic will flow, the mail will be on time and the water from the tap won't stink anymore?

  • Re:Backups? (Score:3, Funny)

    by Faylone ( 880739 ) on Tuesday July 15, 2008 @01:54PM (#24199755)
    WAIT A MINUTE! You mean it CAN be unchecked?!
  • by cbreaker ( 561297 ) on Tuesday July 15, 2008 @02:10PM (#24200017) Journal

    Hey AC.

    Not very insightful at all. I thought it would be pretty obvious to infer the following from my post:

    - That I was an Admin
    - That web mail and general internet surfing was not banned
    - That there was no written procedure to go through; this guy was just a schmuck
    - Obviously it was the work PC. It was easier saying "My PC" than "The PC that sits at my desk that I use every day which was designated for my use during the work day."

    The PC was connected to OUR domain, at our department. By taking the PC to their office, which I firewalled from ours (we had patch management, software deployment, locked down PC's; a fully managed system - they still have Win95 machines running) so they couldn't login to our domain.

    I was asked for the "Administrator" password first. I told them that it was Vista, and that I never assigned one to "Administrator." They didn't believe me. Eventually they asked for my password, which I didn't give them.

    You're as much of a moron as they are.

  • Two words (Score:3, Funny)

    by pjt33 ( 739471 ) on Tuesday July 15, 2008 @02:27PM (#24200325)
    Damp matches.
  • by torkus ( 1133985 ) on Tuesday July 15, 2008 @04:45PM (#24202897)

    Unless there was the possibility of the general public finding out of course. Does anyone seriously thing WW2 tactics mentioned by parent would fly in today's government? I mean ... we're at WAR and the news papers were (and to a large degree still are) more interested in individual casualty counts than progress being made.

    Now, as long as the TLA's are assure they won't get called out...they'll gladly keep this a secret.

    The real problem is the password is probably stupid/embarassing '1.l0v3.g@y-t33n@ge^b0yZ' or similar. I think i'd rather sit in jail at that point too.

  • Actually I ended up being heavily involved in the death throes of the company as the proxy of the one partner who I liked. Miserable experience. They made his life a living hell, and mine slightly hellish by association.

    Two months after they folded the same jackass who fired me tried to offer me a partnership deal for some software app that I was supposed to write from the ground up for him to market through his shady incestuous contacts with the local government.

    Despite the half-hearted "Maybe we shouldn't have treated you like shit" apology, and the recent glaring example of what a monumentally stupid thing it would be to get involved with them on any level greater than a mere employee, I managed a polite, "No thank you" and I haven't heard from the bastards since.

egrep -n '^[a-z].*\(' $ | sort -t':' +2.0

Working...