IT admin locks up San Francisco's network

2 comments | 15I like it!
July 15, 2008, 12:15 PM —  IDG News Service — 

A network administrator has allegedly locked up a multimillion-dollar computer system for the city of San Francisco that handles sensitive data, and he is refusing to give police the password

Terry Childs, 43, was arrested Sunday and has been charged with four counts of tampering with a computer network. According to the office of San Francisco District Attorney Kamala Harris, Childs made changes to the city's Fibre WAN (wide area network), allegedly rendering it inaccessible to administrators. He also "set up devices to gain unauthorized access to the system," the DA's office said in a statement.

The Fibre WAN is used to connect computers in buildings throughout the city and carries about 60 percent of the networking traffic for the city government. On Tuesday it was functioning normally, but the city no longer has administrative access to the switches and routers on the network, according to Ron Vinson, chief administrative officer with the city's Department of Telecommunication Information Services. "It was a little unnerving to discover that this person had created this fiefdom of access to our network," he said.

"We continue to monitor the system to make sure that we do maintain the integrity of the network," he added. "The issue at hand is the access codes that we are trying to get our hands around."

Childs was arrested on Sunday at his home in Pittsburg, California, the DA's office said.

In the days leading up to his arrest, his behavior had become erratic and he had become hostile toward his colleagues, according to a source familiar with the situation. After his arrest, he first gave some bogus passwords to police and then refused to reveal the real passwords, the source said.

Childs is a network administrator with the city's Department of Telecommunication Information Services, which runs the city's critical IT operations, including the e-mail system, Web site, 311 call center and telecommunications infrastructure.

Childs remains in custody, Harris said in a Monday afternoon news conference. "The bail has been set at [US]$5 million, and the exposure in this case if he were convicted on all counts would be seven years in prison," she said. He is set to be arraigned on Thursday.

Harris said it's unknown why Childs allegedly tampered with the system.

Vinson said his department recently hired a new security chief who oversaw an assessment of the group's security. Over the past few weeks that assessment discovered evidence of tampering. "It was escalated to the police department, who brought their own forensics team that came in to do their own investigation of our network," he said.

That investigation led to Childs' arrest, he said.

The city is now working with Cisco Systems to repair the problem, but if it has to replace the routers and switches that have been tampered with, it could easily face a $250,000 bill for the incident.

The situation doesn't reflect well on San Francisco's IT staff, said Andrew Storms, director of security operations with security vendor nCircle. "His managers should have known better," he said via instant message. "Some safety nets and best practices were probably overlooked if one person could have caused this much damage."

San Francisco began rolling out the Fibre WAN about four years ago as a less-costly alternative to leased data lines, Vinson said. To date the city has spent more than $3 million on the project.

With administrative access to switches and routers, could Childs now seize control of the city's network? "Not where he's sitting now," Vinson said.

IDG News Service

I like it!
Comments

I had a predecessor do this

I had a predecessor do this and if I'm not mistaken this false under the federal Cyber Terrorism Act that was defined prior to 9/11/2000. It would fall under the Patriot Act allowing far more reaching penalties and sentencing in light of shutting down a law enforcement agency, not to mention the rest of the city. This is a complete breech in ethics for anyone in IT, we are given the keys to the castle because we can be entrusted with them and the data contained there in or flowing across our network.
| reply

I give props to this guy.

I give props to this guy. This guy is my hero. Keep rocking Terry Childs. WOOT!
| reply
Resources
White Paper

Symantec Backup Exec 12 and Backup Exec System Recovery 8 deliver industry leading Windows data protection and system recovery. Download this whitepaper to find out the top reasons to upgrade and how to get continuous data protection and complete system recovery.

Webcast

Data and system loss — from a hard drive failure, malicious attack, natural disaster, or simple human error — can happen anytime. Don’t leave your business vulnerable. Make sure you have a secure recovery strategy in place. Symantec's latest backup and system recovery technology can efficiently restore critical applications, individual emails and documents and even restore your entire system in minutes in the event of a loss.

White Paper

Businesses face a growing challenge to ensure that the IT environment is properly protected. Backup Exec 12 integrates with other applications in the Symantec family of products, to complement your current data protection strategy, keep your data securely backed up and make it recoverable when you need it most.

Free stuff

Enterprise 2.0 Implementation
By Aaron C. Newman, Jeremy Thomas
Published by McGraw-Hill
Learn more!

Deploying Cisco Wide Area Application Services
By Zach Seils, Joel Christner
Published by Cisco Press
Learn more!

Featured Sponsor

AISO founders envisioned a Web hosting company that was environmentally friendly. While the company employed energy-efficient innovations like solar panels, its infrastructure produced unacceptable power and cooling requirements. Find out how AISO leveraged AMD technology to overcome their challenge in this case study white paper.

In this whitepaper, Scalar explores the opportunity to change the landscape with respect to mission critical databases built around Oracle. Leveraging technologies such as Linux, high-end commodity processing power and Oracle RAC technology to architect, design, build and maintain database infrastructure that delivers maximum availability, reliability and performance at a fraction of traditional cost.

On a typical day, weather.com, the Web site for The Weather Channel in Atlanta, serves up between 15 million and 20 million page views. But in September 2004, when back-to-back hurricanes ransacked Florida, the peak traffic on one day more than tripled: over 70 million page views by more than 7 million unique visitors. Read the full success story now.

More Resources