p858snake Posted December 26, 2009 Posted December 26, 2009 Inmate gets 18 months for thin client prison hack A former prison inmate has been ordered to serve 18 months for hacking the facility's computer network, stealing personal details of more than 1,100 of its employees and making them available to other inmates. Francis G. Janosko, 44, received the sentence earlier this week in federal court in Boston after pleading guilty to the hacking offenses in September. In 2006, Janosko hacked a thin client that was connected to a prison server to access the employee database for the Plymouth County Correctional Facility in Massachusetts, prosecutors alleged. After obtaining the names, addresses, dates of birth, social security numbers and telephone numbers of the employees, he made them accessible to other inmates. Although the machine was configured only to run a legal research program, the prisoner managed to use it to get free rein over a variety of unauthorized services. In addition to the employee database, Janosko was also able to access the internet to download videos and photographs of prison employees, inmates and aerial shots of the prison, according to court papers. The hacking took place between October 2006 and February 2007. Janosko was imprisoned in 2006 for a parole violation following a conviction on child pornography charges. He was convicted of harassing an underage girl and taking pictures of her in a public library the year before. Source: The Register
powdarrmonkey Posted December 26, 2009 Posted December 26, 2009 Why in the world was the inmates network connected to the administration network even physically? duh!
mac_shinobi Posted December 26, 2009 Posted December 26, 2009 Why in the world was the inmates network connected to the administration network even physically? duh! vlan's etc ?
mcloum Posted December 26, 2009 Posted December 26, 2009 Why in the world was the inmates network connected to the administration network even physically? duh! Why have the inmates even got a network! Especially one whos convicted of child pornography!
SYNACK Posted December 26, 2009 Posted December 26, 2009 vlan's etc ? VLANs are not entirely secure, they rely on packet tagging which is usually done by the switch with varying levels of security. The issue is that this tagging is vunrable to corruption and spoofing if you know enough about it and the switch is not 100% secure (a feat that no software based system seems to be able to manage). For instance certain NIC drivers (eg HP Teaming stuff) allow creation of subinterfaces to assosiate with multiple VLANs if the switch allows it and depending of the switch software involved can be achived on ports not configured absoloutly correctly. Being a prison getting access to a trunk link is not as likely but these are very vunrable as simple packet injection of tagged frames will get right past almost all of the security measures. If they were going to insist on using a VLANed system in an environment like that at the very least they should have implemented full IPSEC encryption on all communication on the administration network. Its like a handful of group policies and really shows up the lack of care that was implemented when desigining a network in such a data sensitive location. They probably had the whole lot running on the same network segment with a single layer of 'security' (the thin client settings) and just relied on the inmates being unskilled at such things to keep them safe. Of course on this occation they ran up against a rather unlikely element, a highly skilled user
powdarrmonkey Posted December 26, 2009 Posted December 26, 2009 vlan's etc ? The only way to ensure total isolation is to unplug it
mac_shinobi Posted December 27, 2009 Posted December 27, 2009 (edited) VLANs are not entirely secure, they rely on packet tagging which is usually done by the switch with varying levels of security. The issue is that this tagging is vunrable to corruption and spoofing if you know enough about it and the switch is not 100% secure (a feat that no software based system seems to be able to manage). For instance certain NIC drivers (eg HP Teaming stuff) allow creation of subinterfaces to assosiate with multiple VLANs if the switch allows it and depending of the switch software involved can be achived on ports not configured absoloutly correctly. Being a prison getting access to a trunk link is not as likely but these are very vunrable as simple packet injection of tagged frames will get right past almost all of the security measures. If they were going to insist on using a VLANed system in an environment like that at the very least they should have implemented full IPSEC encryption on all communication on the administration network. Its like a handful of group policies and really shows up the lack of care that was implemented when desigining a network in such a data sensitive location. They probably had the whole lot running on the same network segment with a single layer of 'security' (the thin client settings) and just relied on the inmates being unskilled at such things to keep them safe. Of course on this occation they ran up against a rather unlikely element, a highly skilled user I've got all the ccna cbt nuggets to go through - got a very very very long road to go before I totally understand what you just posted above although if they used something like pf sense, m0n0wall or the likes ( smoothwall ) or even a hardware firewall they could have locked it down a lot more - I'm still learning a lot about everything so will get there eventually like a lazy susan lol The only way to ensure total isolation is to unplug it Sounds good to me Edited December 27, 2009 by mac_shinobi
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now