News: 1601882113

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Big IQ play from IT outsourcer: Can't create batch files if you can't save files. Of any kind

(2020/10/05)


Who, Me? The end of a damp weekend (for the UK at least) heralds a new instalment in our ongoing series of Register reader confessions. Welcome back to [1]Who, Me?

Today's story comes from a reader Regomised as "Alan" and concerns the time he was instrumental in the accidental near-shutdown of an entire department of Her Majesty's Government (HMG).

While our tale takes place some decades ago, we'll draw a discreet veil over the department concerned, suffice to say it had outsourced much of its IT services (desktops, servers, mainframes et al) to one of the big boys, as was the fad of the time (and remains so today).

Alan was working for the government in the role of IT Security Consultant. While dutifully reviewing the list of security requirements issued by the Powers That Be, he noted one that stated that DOS commands must not be available to users.

It all seemed to have been implemented as specified, but Alan was a curious chap. Was there another way of firing off a cheeky command or two?

"I had a thought," he said, "and booted up MS Word, and wrote the following text:" dir | files.txt

Next, he simply saved the file as plain text and named it list.bat .

The batch file was simple stuff. Double-clicking list.bat fired it off. The operating system recognised it and dutifully ran it. The result was "a nice listing of the contents of the directory" in the freshly created files.txt

"This has proved useful for delivery of sets of documents to many customers since," he added.

It did, however, highlight a gaping hole in security. Alan had been able to get at the verboten commands via the medium of a common-or-garden batch file combined with the trusting nature of the OS of the time.

"I showed my work to my civil servant manager, the head of IT Security," Alan said, "pointing out that had I used the instruction command.com I would have obtained a command-line interface window allowing use of DOS commands directly."

We imagine that strong words were then had with the supplier of all things IT who, in a rare moment of efficiency, took rapid action.

Alan turned up for work the next day to find his account only had read-only access. He could not save any files anywhere. At all.

Neither could anyone else in the department for the rest of the day.

In order to stop naughty batch files from being created, the IT outsourcer had simply stopped the saving of any files, solving Alan's problem, but creating a huge swathe of new ones.

"There were," recalled Alan, "some forthright 'discussions' concerning what had actually been asked for versus what had been delivered.

"Moral: be careful what you wish for, and from whom you wish it."

Ever issued a smug "there, I fixed it" for one problem, only to create near limitless user pain? Or been on the receiving end of one of those IT "fixes"? Share your tale of woe with all at [2]Who, Me? ®

Get our [3]Tech Resources



[1] https://www.theregister.com/Tag/who-me

[2] mailto:whome@theregister.com

[3] https://whitepapers.theregister.com/

WIPRO and Powershell..

lansalot

As you may recall, WIPRO had an embarassing "security incident" a year or two ago. I was one of the users on the ground who felt the repercussions - because the miscreants had used Powershell to gain a foothold, they simply blocked Powershell EVERYWHERE to "Improve security".

Apart from of course not being able to run or develop anything any more (hi, automation guy here), I also was blocked from even opening my .ps1 files in notepad, so I couldn't copy the work to an off-domain dev machine and continue the work. Months that took to sort out...

Hubert Cumberdale

Sledgehammer, meet nut.

Anonymous Coward

I'd have hoped that resulted in boot meet ass....

Idiocy

Terry 6

Office software's ability to access files anywhere on a system a decade or two back was well known. I'd used it myself - so there had been no excuse for leaving that open.

And no one with an ounce of sense turns off core functions (like save and print).

All of which does rather suggest that issues around outsourcing, and the kinds of people who run public IT must be pretty long standing.

And then we wonder why public projects never seem to work, let alone on time or within budget.

Re: Idiocy

Olivier2553

One of the problem with outsourcing is that it is taken as a solution to the wrong problem.

Often outsourcing is seen as a way to save the cost of doing something. While it should only b a way of saving on the burden of doing that thing, but knowing well it will cost you more.

Re: Idiocy

Anonymous Coward

Smoke and mirrors.

Its not saving cost at all - its just accounted for on somebody else's spreadsheet!

Re: Idiocy

Doctor Syntax

The deeper problem is that IT is seen as an unwelcome cost of doing something whilst not recognising that it's part of the core of what you do. (Hi, there, banks.)

More than once ...

jake

... I've had the fix the end result of a junior admin deciding that things would be a lot more secure if he changed the permissions of the contents of the likes of /bin, /sbin, /etc and/or /var. Usually when they get this brilliant idea, they manage to do it recursively ...

It's more secure, all right.

Re: More than once ...

Anonymous Coward

I accidently changed all the file properties to read only across an entire hard drive. I'd intended to do it on a floppy but typed the wrong drive letter in the path. I realized my oopsie when my Win3.11 suddenly locked up tighter than an accountant's personal purse strings. I fixed it by restoring a backup of the system I'd made earlier that morning.

Posting anon because I still feel embarrassed by the !DOH! event...

Chris Miller

I'm surprised at an outsourcer swiftly implementing a change rather than responding with the standard: "This is not covered under our contract and must therefore be charged at our (outrageous) daily rate." But, this being the civil service, probably the conversation did take place and produced the response: "Don't worry, the taxpayer will cover it."

Anonymous Coward

Probably near renewal time and the outsourcer mindful to present a good customer impression by doing everything asked for promptly.

The customer not being exacting and specific was just a bonus for the outsourcer as their account managers could up sell and offer to do that security role thereby saving the company future issues as the security team clearly where not experienced enough.

Doctor Syntax

A similar issue:

Users were dropped into the Informix ISQL menu system at log-on end logged out when they quit the program. However the menu system allowed them to shell out by hitting '!'.

Solution? A quick program to mimic the menu system using the same sysmenu tables but without the shell-out option.

Couldn't happen now?

phy445

I'd like to think that HMG had learned from issues like this over the years. This weekend's IT 'glitch' hints at this not been the case

Not a true Who Me

Pascal Monett

He just reported the problem. He's not the one who bungled the fix.

If imprinted foil seal under cap is broken or missing when purchased, do not
use.