Jump to content

Recommended Posts

Posted

Inmate gets 18 months for thin client prison hack

A former prison inmate has been ordered to serve 18 months for hacking the facility's computer network, stealing personal details of more than 1,100 of its employees and making them available to other inmates.

 

Francis G. Janosko, 44, received the sentence earlier this week in federal court in Boston after pleading guilty to the hacking offenses in September.

 

In 2006, Janosko hacked a thin client that was connected to a prison server to access the employee database for the Plymouth County Correctional Facility in Massachusetts, prosecutors alleged. After obtaining the names, addresses, dates of birth, social security numbers and telephone numbers of the employees, he made them accessible to other inmates.

 

Although the machine was configured only to run a legal research program, the prisoner managed to use it to get free rein over a variety of unauthorized services. In addition to the employee database, Janosko was also able to access the internet to download videos and photographs of prison employees, inmates and aerial shots of the prison, according to court papers. The hacking took place between October 2006 and February 2007.

 

Janosko was imprisoned in 2006 for a parole violation following a conviction on child pornography charges. He was convicted of harassing an underage girl and taking pictures of her in a public library the year before.

 

Source: The Register

Posted
Why in the world was the inmates network connected to the administration network even physically? duh! :rolleyes:

 

Why have the inmates even got a network! Especially one whos convicted of child pornography!

Posted
vlan's etc ?

 

VLANs are not entirely secure, they rely on packet tagging which is usually done by the switch with varying levels of security. The issue is that this tagging is vunrable to corruption and spoofing if you know enough about it and the switch is not 100% secure (a feat that no software based system seems to be able to manage). For instance certain NIC drivers (eg HP Teaming stuff) allow creation of subinterfaces to assosiate with multiple VLANs if the switch allows it and depending of the switch software involved can be achived on ports not configured absoloutly correctly.

 

Being a prison getting access to a trunk link is not as likely but these are very vunrable as simple packet injection of tagged frames will get right past almost all of the security measures.

 

If they were going to insist on using a VLANed system in an environment like that at the very least they should have implemented full IPSEC encryption on all communication on the administration network. Its like a handful of group policies and really shows up the lack of care that was implemented when desigining a network in such a data sensitive location. They probably had the whole lot running on the same network segment with a single layer of 'security' (the thin client settings) and just relied on the inmates being unskilled at such things to keep them safe. Of course on this occation they ran up against a rather unlikely element, a highly skilled user :)

Posted (edited)
VLANs are not entirely secure, they rely on packet tagging which is usually done by the switch with varying levels of security. The issue is that this tagging is vunrable to corruption and spoofing if you know enough about it and the switch is not 100% secure (a feat that no software based system seems to be able to manage). For instance certain NIC drivers (eg HP Teaming stuff) allow creation of subinterfaces to assosiate with multiple VLANs if the switch allows it and depending of the switch software involved can be achived on ports not configured absoloutly correctly.

 

Being a prison getting access to a trunk link is not as likely but these are very vunrable as simple packet injection of tagged frames will get right past almost all of the security measures.

 

If they were going to insist on using a VLANed system in an environment like that at the very least they should have implemented full IPSEC encryption on all communication on the administration network. Its like a handful of group policies and really shows up the lack of care that was implemented when desigining a network in such a data sensitive location. They probably had the whole lot running on the same network segment with a single layer of 'security' (the thin client settings) and just relied on the inmates being unskilled at such things to keep them safe. Of course on this occation they ran up against a rather unlikely element, a highly skilled user :)

 

I've got all the ccna cbt nuggets to go through - got a very very very long road to go before I totally understand what you just posted above although if they used something like pf sense, m0n0wall or the likes ( smoothwall ) or even a hardware firewall they could have locked it down a lot more - I'm still learning a lot about everything so will get there eventually like a lazy susan lol

 

The only way to ensure total isolation is to unplug it ;)

 

Sounds good to me

Edited by mac_shinobi

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...