Beware the hacker next door
After many years in the IT industry I’ve learned that hackers don't always fit the stereotype. In fact, the most common type of hacker is sitting in the cubicle next to you, right now. According to Carnegie Mellon University’s Software Engineering Institute CERT Program study, up to 90% of incidents in business relating to the loss of assets results from staff that have privileged access to IT systems and applications.
This is someone who gets to work early, takes his or her turn cleaning out the office fridge, tells funny stories at lunch and, at some point, makes a very dumb move. It often starts when this hacker-next-door sees a file directory or workstation that’s just too juicy to pass by, like one named “Salary Comparison.” It’s simply too tempting NOT to peek inside.
How do these attackers get access to critical systems? All too easily.
Once that hacker-next-door decides to break into a target system, their next stop is a search engine. A few keywords later, and anyone can discover that the most common -- and effective -- type of hack into a target system is to become what’s called a “script kiddie.” Script kiddies use default lists of privileged passwords, or the superuser/administrative codes built into every piece of hardware and software. Have you ever noticed the “Administrator” ID next to your name when you login to your workstation? That’s a privileged user and password, a backdoor into your system built by the manufacturer. It cannot be disabled or destroyed.
Let’s turn back to our hacker-next-door who wants to get into the “Salary Comparison” workstation. He doesn’t know who owns this workstation, but he can search to find what the default Administrator passwords are for a Dell Latitude D600. If the built-in default doesn’t work, the would-be hacker may try some simple passwords like CompanyName123. You’d be stunned how often these basic password scenarios -- also available as mini computer programs on the Web -- are the fastest way into any organization’s data.
Once the hacker enters a target system with a privileged password, he now has more access to data than the system’s legitimate users. I know of one company, for example, where a disgruntled IT professional changed every password on the network. All software had to be reloaded. The company was basically shut down for days. Meanwhile, the angry ex-employee denied all knowledge of the incident. And who could prosecute him? The deed was done under an anonymous identity, the Administrator.
This lead to another question I am commonly asked: Why do most enterprises leave their privileged passwords, the keys to their kingdom, open and unmanaged? The reason is simple: manually changing these codes is extremely time-consuming. Visit professional hacker sites, and their biggest complaint about script kiddies is not that they exist, but that once these amateurs do something flagrant and dumb with privileged passwords, these wonderful secret passages into a company’s data get closed.
Of course there are automated ways to securely change privileged passwords, but until such solutions become standard tools in most enterprises, I’d keep a close eye on the folks around you. You never know who is privileged to YOUR information!
Calum Macleod is European director of Cyber-Ark.
» posted by ITworld staff
Cyber-Ark
Symantec Backup Exec 12 and Backup Exec System Recovery 8 deliver industry leading Windows data protection and system recovery. Download this whitepaper to find out the top reasons to upgrade and how to get continuous data protection and complete system recovery.
Data and system loss — from a hard drive failure, malicious attack, natural disaster, or simple human error — can happen anytime. Don’t leave your business vulnerable. Make sure you have a secure recovery strategy in place. Symantec's latest backup and system recovery technology can efficiently restore critical applications, individual emails and documents and even restore your entire system in minutes in the event of a loss.
Businesses face a growing challenge to ensure that the IT environment is properly protected. Backup Exec 12 integrates with other applications in the Symantec family of products, to complement your current data protection strategy, keep your data securely backed up and make it recoverable when you need it most.
Crimeware: Understanding New Attacks and Defenses
By Markus Jakobsson, Zulfikar Ramzan
Published Apr 6, 2008 by Addison-Wesley Professional. Part of the Symantec Press series.
Enter now! | Official rules | Sample chapter
Securing VoIP Networks: Threats, Vulnerabilities, and Countermeasures
By Peter Thermos, Ari Takanen
Published Aug 1, 2007 by Addison-Wesley Professional.
Enter now! | Official rules | Sample chapter








Please cite your source for
Please cite your source for your claim that "According to the FBI, internal hacker attacks make up 70 percent of all security breaches."The FBI has never published such an assertion.
More at...
http://70percenters.googlepages.com/
P.S. Welcome to the 70 Percenters Hall of Shame
Dear Anonymous, Thank you
Dear Anonymous,Thank you for pointing this out to us. It seems we at Cyber-Ark have fallen into a common trap. Having heard and seen this FBI stat from reputable industry analysts and publications alike, we didn’t dispute it as a trustworthy report. Since the origin of this source is under question, however, we have replaced it with one of many compelling statistics from a Carnegie Melon CERT study to demonstrate the growing threat internal hackers represent.
Thank you,
Adam Bosnian
Vice President
Cyber-Ark Software