A cautionary tale of virtual floppies and all too real credentials
- Reference: 1603700110
- News link: https://www.theregister.co.uk/2020/10/26/who_me/
- Source link:
Our reader, Regomised as Dave, told us of his time working in the IT department of a bank "at the end of the eighties or the early nineties."
Dave toiled away in a small team, responsible for automation in the foreign branches of the institution. His use of Turbo Pascal (of which this hack has many fond memories) dates things somewhat, and the tools he wrote were used to connect the bank's software (running on Datapoint gear) to PCs and SWIFT ST200 terminals.
SWIFT, the Society for Worldwide Interbank Financial Telecommunication, is now approaching its 50th anniversary and is a key part of the world's financial infrastructure. It lobs transaction information around between over 11,000 institutions, although at the time of our story it enjoyed approximately 3,000 customers.
"The ST200 wasn't directly linked," explained Dave, "but data was transferred to and from with floppies that were prepared or read on a PC."
A simple, if time consuming process compared to the connectivity of today.
Dave was in an overseas branch and needed to make some modifications to the PC application.
"The branch's sysadmin was so kind to set me up a PC under his usercode," he told us, "and because the PC he used had no floppy drive he mapped a network subdirectory as the A: drive."
While floppy drives have all but disappeared nowadays, they were ubiquitous back in the day. Not having one was a sign of either a bean-counter let loose at the specifications or some decent network hygiene.
The usercode thing though? We're not so sure about that.
Novell was the networking software of choice for the branches, and it took but a simple map command to create that virtual floppy drive.
Dave got to work: "When preparing a floppy that had to go to the ST200 my application first deleted all files and directories (recursively) that were on that thing.
"So when it started doing that, I expected it to be quickly finished as my test 'virtual floppy' was empty."
It was, after all, just an empty network directory, right?
Let the arse-swooping panic commence!
"I was horrified when I saw a parade of filenames flashing by, including some things that really resembled user data files and network software files.
"I've never hit Ctrl+C so fast in my life!"
Dave began the walk of shame to the sysadmin's office, but before he reached the door "I saw one person after the other go into his office to complain about problems with the network. He was bewildered."
Regular readers will have guessed what had happened by now; the sysadmin had forgotten to map the network directory as [2]"root" . Worse, Dave was using the sysadmin's usercode and so his application was able to start a recursive deletion adventure down to the very bowels of Netware. Even Novell's own system files had not been spared.
"If I would have looked at 'A:' from a command prompt I would have noticed," sighed Dave.
The gang eventually managed, with the help of a second server and oh so many backup tapes, to get things up and running again, "but we learned to use 'map root' and, more importantly, that even a sysadmin should have a normal user account for the non-sysadmin stuff..."
Ruefully, Dave added: "and nowadays you don't even think about giving anyone access to your environment."
Wise words. Just a shame it took the near takedown of the bank's branch to learn them.
Ever found yourself with a bit more power than expected and abused it in the proper manner? Or felt the world drop out of your bottom as the names of irreplaceable files whizzed by? We've done at least one of those things. Surely your experience is worth a confession to [3]Who, Me?
Get our [4]Tech Resources
[1] https://www.theregister.com/Tag/who-me
[2] http://support.novell.com/docs/Tids/Solutions/10027779.html
[3] mailto:whome@theregister.com
[4] https://whitepapers.theregister.com/
Waddayamean "nowadays"?
"and nowadays you don't even think about giving anyone access to your environment."
Even in those days I would have opened an account with appropriate privileges for the interloper visitor to muck about in[0]. What's the point of having separate accounts if you share them willy-nilly?
[0] With logging. Lots of logging. All of the logging. Paranoid? Me? Not yet, but I was getting there ...
Re: Waddayamean "nowadays"?
He was working at a financial institution. You couldn't just go creating user accounts willy nilly.
Getting a user account setup in that kind of institution was a hugely bureaucratic process involving lots of forms which had to filled in and passed around and signed off by lots of people. It took about two weeks minimum.
Re: Waddayamean "nowadays"?
Not so sure about that. When started working for an investment bank in the early noughties, I recall users regretting how IT had lost the freedom to do things like in the "old times" (i.e., early to mid 90's) where they would sit alongside the developer who would hammer changes directly in the production environment and the users would test along until everyting was OK (with appropriate changes to accounting tables, etc., as needed to correct any previous fumble). So, yeah, a new user account might take 2 weeks of paperwork, but really dangerous stuff was readily available.
Re: Waddayamean "nowadays"?
There is a UK bank where the business side told IT they didn't want a new system to update reference tables, because it would be slower and require logging of changes.They quite like being able to go in and amend production data themselves, direct access to the data warehouse.
This is in 2020.
Re: Waddayamean "nowadays"?
Used to work for a financial software developer - even seniors weren't allowed near the production environments, both physically and 'logically'. Several layers of test / verification and re-test etc.
Re: Waddayamean "nowadays"?
lots of places new users still take weeks to action.
A few jobs back took 3 month for my access, 3 long months basically twiddling thumbs 8 hours a day.
so glad to do some actual work!!!!
Here is one command you dont want to type in
I remember being in the machine room late one night, and I was chatting to one of the bored operators. He was showing off his knowledge, and what he could do with his all powerful userid. He said, as he typed - this is one command you never want to issue "PURGE SYSTEM ALL", then automatically pressed enter!.
Whoops.
Next morning when I came in there was a logon message for all users "Due to a technical fault - all spool files were lost last night".
Over the next few weeks they implemented very granular command security, so it could not happen again.
under his usercode
Whoops! That sysadmin who gave his creds should have been shown the door.
Networked office
Remember the days when programs would be run from network drives to save the space on the local hard disks?
I'll never _ing forget... As a fresh faced PFY I had a problem with my local PC office, and it was suggested that I un install and re install.
Unfortunately with my rights it decided to completely un install office, including the networked version that everyone was using.
Fortunately quickly fixed with the /admin install back to the network location, with a lesson well learned that could have gone a LOT worse.
For various reasons connecting to the file server at our Australian office is most easily accomplished via NET USE.
I always follow this by DIR W: just in case I've connected to the wrong share!
That wouldnt have helped the guy in the story.
he'd have seen what he expected to see at the last folder in the mapped drives path.
Then his software deleted from W:\ ( as opposed to W: )
[edit]
Although if he actually went to w: in cmd he might have noticed the full path , as noted in the story.
ha , i said "folder" . Iv'e gone all user.
Are we calling them folders now? or sticking stubbornly to 'directory' ?
FTP config files...
While at uni, I was doing something where I had to FTP some files to or from one of the Unix servers. After typing in the server name to the FTP client GUI, I spotted the server name already having a configuration defined. With the username "root". With a password filled in. I looked at my mate. He looked at me. I hit "connect" and promptly got logged into the server, as root. Rather naively, I tested the access by downloading /etc/passwd, deleting it and recreating it (in retrospect, this was incredibly dangerous. I didn't know Unix that well in those days...). Evidently, the shared FTP client config had been used by the lecturer at some point and he'd saved the root password for ease of use, not realising it was available to all the students. We reported it to the lecturers and it was removed from the config soon after that...
Worth noting this was about '97 when security processes weren't as strict as they are these days. FTP as root? *shudder*
Re: FTP config files...
err, you mean there are other users?
I'd forgotten all about that map 'root' thing.
It happens by default these days that the path on the mapped drive starts at the mapped location
Seems silly that a map would show you the full path of the destination machines folder - IN the path of the mapped drive rather than 'behind' it
As soon as...
..I saw the line "my application first deleted all files and directories (recursively)" I knew we were in for some "fun"!