It was 9:30 on the morning of March 4, 2002, and something was terribly wrong at the offices of PaineWebber UBS. Computers in branches all over the country began showing disc errors. A logic bomb buried deep within the machines had wiped their hard drives clean, preventing 17,000 brokers from making trades.
"It was six months after 9/11," says Keith Jones, co-principal of Jones Dykstra and Associates, a computer forensics and expert witness firm. "Back then if anyone so much as sneezed, you thought 'terrorism.'"
The IT staff located the backups and restored the first batch of machines. They got wiped again. The logic bomb had propagated to the backups. The brokers gave up on their computers and went to their other backup plan: paper and pencils. UBS tech staff ultimately figured out how to bypass the bomb and restore computer access, but it was weeks before the company was back to normal. More than $3 million in damage had been done.
The culprit: Roger Duronio, a 60-year-old systems administrator. Unhappy about not receiving compensation he'd been promised, Duronio planted the logic bomb on more than 1,000 Unix machines throughout the company. He then shorted the company's stock, hoping to capitalize financially as PaineWebber's share price dropped. Instead he was convicted of computer sabotage and securities fraud. He's now serving an eight-year sentence.
Other cases speak less of revenge and more of IT workers simply cracking under stress -- such as the saga of Terry Childs, a network administrator for the city of San Francisco who became frustrated by his manager's lack of technical expertise and withheld administrative access to parts of the city's network. That particular incident appears to have been a freak-out rather than a premeditated criminal act. But either way, disgruntled IT workers -- battered by interminable hours and impossible demands -- pose a greater threat than ever.
For every Duronio or Childs that makes it into the press, there are 98 others you never hear about, says Jones, who was a key government witness in the Duronio case.
"People don't realize just how much access senior IT people have," says his partner Brian Dykstra. "The vast majority of system admins don't abuse their privileges -- even if they wanted to, they're too busy. But when someone does go over the edge, they have the ability to do a great deal of damage."
And the consequences can be devastating.
References
- www.jonesdykstra.com
- Unix admin pleads guilty to planting logic bomb
- Debate IT: Could the San Fran network lock-out happen to you?
- Bring out the speaker in you! : Consultation Laurent Duperval Consulting
- Exclusive: Gartner Predicts Huge Increase In Offshore Outsourcing By 2015 -- Offshore Outsoucing
- Home
- Geek.com news site
- www.geekgap.com
- SourceForge.net: Open Source Software
- Identity and Access Management Security Software
- Recognition Management Institute
- Dimension Data
Latest on Passwords
- Access vendor GridSure uses patterns to remember PINs
- Good security in recessionary times
- Tough economic climate can heighten insider threat
- Poll: Two thirds of users never change passwords
- IBM, Secret Service, others study identity/cybercrime issues
- Strange account management at Amazon
- Crimes, anonymity and the Net
- IBM vets ID management, access control on own systems
- Top 10 ways collaboration, mobility amplify data leakage dangers: Cisco study
- After password glitch, Firefox patch due next week
Security Essentials
- Good security in recessionary times
- Security ROI: Fact or Fiction?
- NetWitness releases free version of security software
- Study: critical infrastructure often under cyberattack
- Crooks can make $5M a year shilling fake security software
- Sun exec: IT security should follow business needs
- Clumsy staff more dangerous than hackers: survey
- When the watchdog is the underdog
- Mafiaboy grows up; a hacker seeks redemption
- Ouch! Security pros' worst mistakes
TechWorld Jobs (beta)
Recent Jobs
TechWorld Blogs
-

TalkingTech
The view from the top of IT with TechWorld Editor Rodney Gedda
-

Entrenched
Cooking up better code, IDG's developers reveal some of their secrets
-

Broadband Voice
Darren Pauli digs in from the front line of Australia's broadband battleground
Recent blog posts
- An open storage stack? I like the sound of that
- The mobile clone wars: fighting for a better phone experience
- Stopping the "Clean Feed"
- Identifying web platforms
- Clean Feed ‘not technically possible’
- No Clean Feed - well duh!
- Conroy's content cops still on the cards
- Will open source ruin the economy? Please help
- Linux kernel 2.6.27 is out!
- Falling off the ob_start stack
Recent comments
- Hello this is Brianna
2 hours 57 min ago - Turn any PC into a media center
16 hours 49 min ago - How About the Correct Title?
1 day 8 hours ago - who are you kidding?
1 day 13 hours ago - Seriously, how much did they pay for this advertisement
3 days 3 hours ago - SF Bay Area - free Seminar on Enterprise Cloud Computing
3 days 7 hours ago - video conferening but not telepresence...
3 days 14 hours ago - SAMSUNG OLED 40" TECHNOLOGY
3 days 22 hours ago - What was the question again, oh well this was prepared earlier
6 days 5 hours ago - Worldwide broadband prices continue to drop which means ? in AU
6 days 6 hours ago - Not a Problem Here in Australia and New Zealand
1 week 1 day ago - Clear the air
1 week 2 days ago - Tabbed browsing, Quick Find,
1 week 4 days ago - Microsoft details plans for new social bookmarking tool
1 week 6 days ago - There is a 3rd party tool
2 weeks 23 hours ago - Demise of Windows
2 weeks 1 day ago - new OS
2 weeks 1 day ago - Re: Favicon
2 weeks 2 days ago - Multi Camera Kino
2 weeks 2 days ago - Favicon
2 weeks 3 days ago



