• On TechRepublic: 10 cool USB flash drive tricks
September 11, 2008 3:24 PM PDT

Report: SF officials looking for hidden network device

by Elinor Mills

San Francisco officials are trying to find a device on the city's computer network that was allegedly left there by an IT worker who was jailed for refusing to divulge passwords to the city network, the IDG News Service reported on Thursday.

San Francisco network administrator Terry Childs was arrested in July on four felony charges of taking control of the city's computer network and locking administrators out. He remains in jail on $5 million bail despite giving up the passwords to the mayor in a secret jail cell meeting a week later.

The device, which appears to be a router providing remote access to the city's fiber Wide Area Network, was discovered on August 28, the report says.

However, officials didn't know where the device was located and didn't have the user name and password to access it. When they tried to log in, a message was displayed that said the system was the "personal property of Terry S. Childs," according to a screenshot officials filed with the court.

Updated at 5:45 p.m. PT to correct that network is wide area (as in WAN), not wireless.

Elinor Mills covers Internet security and privacy. She joined CNET News in 2005 after working as a foreign correspondent for Reuters in Portugal and writing for The Industry Standard, the IDG News Service, and the Associated Press. E-mail Elinor.
advertisement
Click here!
Recent posts from Security
Microsoft to fix holes in Windows, Office
Google privacy controls: Most people won't care
Zero-day flaw found in Web encryption
Mac Game: Art project or malware?
Corporate bank accounts targeted in online fraud
Hacker breaks into jailbroken iPhones, asks for $7
Malwarebytes accuses rival of software theft
Security firm M86 acquires Finjan
Add a Comment (Log in or register) (9 Comments)
  • prev
  • 1
  • next
by Tassography September 11, 2008 3:46 PM PDT
San Francisco really has a fiber wireless network? Wow, I'd love to see that....

PS You can't create an account or login with IE8 Beta 2...
Reply to this comment
by Solaris_User September 11, 2008 4:26 PM PDT
Uhh.. look the port up on the switches and turn the port off? How hard is that? It seems pretty easy to find the MAC, then match the MAC to the switch and you found it, even if you don't know *exactly* where it is you can easily disable it.. well.. that is if you know what you are doing.. this being national news its pretty apparent the city does not.

I don't really trust this story.. why would someone be arrested (not sued) but actually put in jail and have a secret meeting with not a lawyer but the mayor, for not giving back passwords after he was fired?

He should have the passwords for all this stuff if he is an administrator, there is no shocking revelation here.. there are also good reasons why you wouldn't reveal a password to your supervisor.

*Real* companies don't even do this usually.. there is not one root password but many separate accounts that have access to it. This appears to be SF's own fault for deploying a moronic security policy.. now it's clear they are using the strong arm of the law against this guy with the arrest, jail, $5 mil bond, and secret meetings.

I think there is more to this story then the bureaucrats in SF want to admit.
Reply to this comment
by Dalkorian September 11, 2008 5:03 PM PDT
My thoughts exactly. If they truly can't find this backdoor access router and shut it down, it kinda shows Terry was right after all, doesn't it?
by Travis742 September 11, 2008 5:21 PM PDT
Tracking down a device on the network is NOT hard. Either the San Francisco IT people have no idea what they're doing, or else they're trying to make the jailed network admin look really bad and just toy with the press. Obviously nobody in the press knows the technical questions to ask to prove how silly SF is being... but get any knowledgeable IT admin in there and they'd solve the problem fairly quick.
Reply to this comment
by sanenazok September 11, 2008 5:24 PM PDT
Quick, hire a politically-connected consultant!
Reply to this comment
by Michichael September 11, 2008 6:52 PM PDT
Ok, it is virtually impossible to NOT find the router.

If they can attempt to log into it and get screenshots then they have an IP. If they have an IP they have an associated MAC address in the MAC address tables of the router. If they have an associated MAC Address, they can find what port of what switch it is connected to, EASILY.

I'm calling ******** on this - It's planted or fictitious.
Reply to this comment
by gtalbott September 13, 2008 11:06 AM PDT
If they have the MAC address they can find the port... _Unless_ the City of San Francisco is so cheap that they bought un-managed switches and they can't see the MAC address tables or disable individual ports. Maybe they are still using 10Mbps Baseband Ethernet on COAX with Vampire taps no less... :-)
by raveboy12000 September 11, 2008 11:53 PM PDT
To put the back-story into a nut shell. The Sys. Admin locked every one out of the SF Fiber Wide Area Network. Which spans the city and handles all the cities secured info.

There is more to it than just blocking port on a switch. If the guy is smart enough he can wright a script that puts out fake IP.

The guy got fed up with stupid people screwing up the WAN.
Reply to this comment
by SirRobinOfPennsynvania September 12, 2008 6:27 AM PDT
This is an interesting problem SF faces. The device does not belong on the network and has to be found and removed. As long as it remains on the network it remains a threat. The device can bypass firewall and other security measures. Searching for the device will be expensive considering the network is city wide and the router could be interfacing with the network wirelessly. No one will disputer the device is considered apart of the network. Blocking the device is also expensive and ongoing with every upgrade. There is no indication that Terry S Childs was working alone. The device is also secondary to the fact that the administrators have been locked out indicates he took control of the network. Ofcouse this has to be proven. Anyone with administrator access could have easily pinned this incident on Terry Childs considering the only evidence they have is what is that the device displays his name.
Reply to this comment
(9 Comments)
  • prev
  • 1
  • next

FAQ: Buying the right Windows 7 upgrade

Readers still have lots of questions on just which version of the software they need to buy in order to upgrade their PC. CNET News tries to offer some answers.

N.Y. lawsuit details Intel's 'largesse' toward Dell

Attorney General Andrew Cuomo's federal antitrust case filed Wednesday alleges a longstanding symbiotic relationship between Intel and Dell.

About Security

Online security is threatened by more than hacking and phishing attempts. Check here for the latest updates on software vulnerabilities, data leaks, and rapidly spreading viruses--and learn how to protect your systems.

Add this feed to your online news reader

Security topics

advertisement
advertisement

Inside CNET News

Scroll Left Scroll Right