Forgot your password?

typodupeerror
IT

Searching for Backdoors from Rogue IT Staff->

Submitted by WHiTe VaMPiRe
WHiTe VaMPiRe writes "When IT staff are terminated under duress, there is often justification for a complete infrastructure audit to reduce future risk to a company. sysadmin1138 recently answered a question on Server Fault that provides a through exploration of the steps necessary to maintain security. Read more at How do you search for back doors from previous IT?"
Link to Original Source

Comment: Re:Take some time and think (Score 1) 537

by George Beech (#32036182) Attached to: Juror Explains Guilty Vote In Terry Childs Case

"At one point he was concerned about the security of the FiberWAN routers in remote offices, so he had them set up without saving the config to flash. "If they go down, I'll get alerted, and connect up to them and reload the config." Great, except we have power outages all the time in this city, some of those devices aren't on UPSs, and what happens if you're on vacation? And what about the 15 to 60 minutes it might take you to connect up and reload? He eventually conceded and (ahem) decided that disabling password recovery was sufficient security."

After reading that would you reboot any of those routers? Source

Comment: Re:Not trying to be a troll here, but... (Score 4, Insightful) 418

by George Beech (#32022870) Attached to: Rough Justice For Terry Childs
No that's a twist on what happened to suit the ideas of slashdot. What happened was he was locked up and said "I'll only give these passwords to the Mayor" Now what he was required to do by the state policy was provide the passwords to Information Security for inclusion in the central password management database due to them being production passwords. He obviously did not do this as none of this would have happened if he did.

Comment: Re:Poor jerk. (Score 1) 982

by George Beech (#32009618) Attached to: Terry Childs Found Guilty
... Actually he expressly did NOT follow policy.

All production system-level passwords must be part of the security administered global password management database.

In fact, if the passwords had been in that database, then he would A) probably never had been asked for them and B) would have been able to say "you need to request access from the security department" Now HE may have thought they were "user" passwords because the system was his baby, but if you truly agree with that ... then well this is going to be like arguing with a religious person about the existence of god.

Comment: Re:Depressing, but not uncommon (Score 1) 1251

by George Beech (#28941211) Attached to: Student Sues University Because She's Unemployable
They actually do track these things. It's reported under "Alternative measures of labor under-utilization" Here's the latest report I can find right now

So In July 09 it seems that the "count everyone" unemployment rate was 16.5% with the "official" rate was 9.5% That includes discouraged workers, Those who took part time job and anyone else classified as a marginally attached worker.

Never underestimate the bandwidth of a station wagon full of tapes. -- Dr. Warren Jackson, Director, UTCS

Working...