Jump to content

Recommended Posts

Posted
One of our highschools were hacked. 2 kids finally found a way around our network. apperantly, the had full access to the ENTIRE domain, had a few virsus ready. The school tech caught them, but not sure how much damage was done before they were caught. Now I have the luxury of the principal at my school asking me to try to figure out how they got access to our entire domain. I dont even know where to start.
Posted

Interogation of the culprits would be the first step. Read them the riot act, quote the Computer Misuse Act etc etc.

 

I hope that those caught are being suitably punished.

Posted
The details are pretty sketchy. From what I have been told, The one kid somehow got admin level rights, then gave his friend the same level of rights, and away they went. We just went to 2003 server roughly last year. The cops were call yesterday, so they're being charged, but thats about all the info I know. As of right now, all the techs are being left in the dark about this whole situtation. I dont even think that many techs know about this. I only know because the principal here is friends with the principal at the school that it happened. So only know of what he has told me.
Posted

You dont wish it on anyone, its one of the worse things that can happen!

 

I read somewhere majority of hacking is caused by people leaving machines logged on!! or someone knowing credentials of admin account.

 

I always try and check my admin groups members every so often, as if they go undetected could simply use to gain infromation rather than damage.

 

From the damage done you can normally track back to specific times etc, perhaps look at when files were deleted then you can tell how login was acheived from event logs etc.

 

I take it you share the domain accross multiple sites ? Or have i miss understood? If so may be worth looking at creating sub domains and keep trusts between them, may limit damage.

 

good luck!

Posted

First things to do depend on whether you want to contain any possible problem or search for the entry point.

 

If you want to contain any problem and ock things down then what you need to do is to check any group with admin level access ... change passwords of all admin accounts on a machine known to be clean of viruses, trojans and so on.

 

Then start looking at machines known to be logged on to by staff with admin level access. Check for key logging software. Ensure all your AV software is up to date. Get a trial of enterprise level anti-spyware software to run a clean of all machines.

 

I know of one school that was worried about similar after a former tech left under a cloud and they had a few strange things happening. They asked Securus for a 2 week trial and put the old admin password (and a few other bit) in the monitor list to see if anyone was trying to log on with admin level accounts. They caught a few students, who had been given information by a friend of the former tech, trying to change a number of things ... and then they didn't bother with Securus after that, but it did the job :-)

 

If the students have been charged then it is likely that the police (and someone at the school) has information about what was being done. Even if it means the Techies find out that they drop a ball somewhere it is important to get the information and clean house.

Posted

Yeah, if I read the Computer Misuse Act right, they could get up to 15 years :D .

up to 5 for attempting to get access

up to 5 for unauthorised modification of data

up to 5 for setting it up so they can get further access.

For each time they got in!!

Posted

Articles under the same act tend to run consecutively for offences that carry up to 5 years or £3000 fines ... it is up to the sentencing judge and depending on the age this is very unlikely.

 

Shame really ...

Posted

What sort of punishment will fall on the manager who is overall responsible for the network to start with..... ?

Of course - said Tongue In Cheek.... :-)

Posted

Meh. I had access to the admin account when I was at school. And my friend did. We didn't have an ICT Technician at the time, the network was run by the ICT Teacher/Head of ICT and he never found out that we knew the password. It was an RM network and the admin account had some cool controls such as remote control of other networked PCs which we used reguarly to scare people (we used to randomly eject their CD drives and laugh in the corner as they became highly confused).

 

We never attempted to damage the network in any way though. I wasn't -that- immature.

 

The only reason we knew the password was because on the RM network they had installed, there was two admin accounts (administrator and admin2). The head of ICT used the administrator account with his own password, but even though he knew about the admin2 account, he never changed it from its default password, which, ironically was "removed". My friend and I of course found out about it and we had full admin rights for over two years. The head of ICT obviously believed in security though obscurity.

 

[ password removed - just in case, plus used in a few things ;) - tarquel ]

Posted

so it's a standard thing from RM to have "removed" then? Successmaker has it as default as well

 

[ edited for the reason above - tarquel ]

Posted
One of our highschools were hacked. 2 kids finally found a way around our network. apperantly, the had full access to the ENTIRE domain, had a few virsus ready. The school tech caught them, but not sure how much damage was done before they were caught. Now I have the luxury of the principal at my school asking me to try to figure out how they got access to our entire domain. I dont even know where to start.

 

I pay the students for information.. an couple of pound here and there goes a long way...

 

They grass up hackers, hacker tricks and rogue teacher passwords :-)

Posted
so it's a standard thing from RM to have "removed" then?

 

Yes. But there's no excuse for people ignoring RM's advice and common sense of changing these ASAP :)

Posted

Well i must admit, i used to "PLAY AROUND" with the network we had at school, and i must admit the techys we had always used to know it was me (and another friend), We NEVER did and i personally never would do anything malicous to the network that was never my intention it was basically find the loopholes in the network and stop other users doing the same, which the techy's appreciated!

 

Must admit though paying the students a few quid to grass on there mates is a brilliant idea!

Posted

I think it might be an idea to set passwords to words that people really wouldnt want as passwords, im thinking passwords such as bad swear words etc. I would think that people might want to change these. Or default passwords such as "vCF&£g45n" that might wind ppl up enough to change. Or potentially secure enough to leave (as long as its undocumented)

 

fooby

Posted

Sorry to hear about it Gambit. It's horrible when that sort of thing happens.

And you would have thought that a password that is telling your to change it would make some people think to change it but thats not always the case. I think RM should put some sort of "Force change of password after a few logons" rule for their admin passwords, but alas that would not help you now.

 

As well as doing all those other things the guys have suggested I would actually recommend running a couple of anti-spyware and virus programs as just one of each does not always cut it. Use some of the freeware ones like Spybot and Avast.

Also, if you think there may still be backdoors in the system then maybe try setting up a honeypot trap to see if anyone goes for it. I would use something like Helix Linux boot disk to do this. Alternatively if the server is severly comprimised then it might be quicker to just start again from scratch with it. Still.. better you than me. :p

 

Oh, and you might want to take a copy of some of the more relevent logfiles if you haven't already done so before they start to overwrite themselves with newer logs.

Posted

If the police are involved, they will probably take the DC as evidence.

 

Therefore, you need a full backup from prior to the incident and some spare hardware to restore to.

 

While were here, I'd like to remind everyone of the Enterprise best practises security guides available on Technet.

 

http://www.microsoft.com/technet/security/secnews/articles/enterprisesecbp.mspx

 

Further help and assistance can be had in the Security forum for anyone who wants it.

Posted
Guys, probably not a good idea to list those default passwords here.

 

Quite right.

 

done :)

 

Whether people should change default passwords or not, it's one I've seen in alot of things, and people are imperfect so accidentally leaving a default password can happen.

 

Nath.

Posted
I can understand the point of removing the passwords, but personally I am not sure if it is worth it. I imagined myself in a position of a malicious student trying to hack into my school network and my immediate reaction was to to do a google search using terms related to the above discussion. Guess what? The very first result gave away all :). If I can do that within 10 seconds, I'm sure other people can as well ;).

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...