When forgetting to set a password for root is the least of your woes
- Reference: 1643617811
- News link: https://www.theregister.co.uk/2022/01/31/who_me/
- Source link:
Today's plea for forgiveness comes from a reader Regomised as "Doug" and is a warning to careless administrators.
"Back in the days when terminals were still fairly common," said Doug, "the company I worked for provided 'local' data based on the result of a search run on the client's main dataset held on their server."
[3]
"We could telnet from these terminals to our box – and frequently had to in the early days," he recalled. The client itself was nationally known in back then and had spanked millions getting this remote site up and running.
[4]
[5]
Things were going swimmingly. Right up until a month after go-live when Doug and a pal were stuck at the client site on a Friday evening. The client's own engineer had long gone, and Doug was finishing up the last checks to allow a weekly backup to kick off.
He ambled up to a darkened terminal near the server room and tapped the return key to bring it to life. The prompt was odd, something he'd not seen before. Tappity tap: whoami
[6]
.
It transpired he was logged in as root. On THE server. "Y'know," he said, "the one that held all the billing information, delivery records and the kind of useful stuff that kept a company running."
At this point he could have logged off. Instead he called over his chum.
[7]
"We spent a happy few minutes playing about with the login prompt before having the wonderful idea that typing something along the lines of ' /etc/shutdown -t0 -h now ' and leaving the terminal to go to sleep would be a jolly jape."
"Like me, most people used the 'return' key to wake up a terminal."
Doug and pal went off to do whatever techies did on weekends in those days. It wasn't until Monday morning when all hell broke loose and he (now on another site) was summoned to HQ for a talking-to. It transpired that the client's main (and only) database server had unexpectedly shut down.
Any protestations of innocence were shortlived as logs were produced showing commands attributed to the terminal on the site where Doug and friend had been.
"Awkward," understated Doug.
However, Doug was saved by his manager who asked a simple question: how could 'his' engineers have possibly known the login for the client's mainframe? "...and was shamefacedly told that they hadn't set a password on the root account..."
So, in a way, Doug was actually the hero of the hour, right? Hm.
[8]Pop quiz: The network team didn't make your change. The server is in a locked room. What do you do?
[9]Hmmmmm, how to cool that overheating CPU, if only there was a solution...
[10]Updating in production, like a boss
[11]The future is now, old man: Let the young guns show how to properly cock things up
These days, neither employer nor client are still trading "although not because of this, I hasten to add," said Doug.
"The moral of this sorry tale is simple: Junior techs with a little Unix knowledge are dangerous if they get bored so be careful if your hardware attaches to client servers.
"Oh, and secure your root access – and never, ever, leave superuser accounts logged in."
Ever left something logged in that you shouldn't? Leaving something explosive on the command line certainly ups the ante of the witty desktop background switcheroo of today. Let us know your misdemeanours with an email to [12]Who, Me? ®
Get our [13]Tech Resources
[1] https://www.youtube.com/watch?v=0FacYAI6DY0
[2] https://www.theregister.com/Tag/Who,Me?/
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/servers&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YffBXRgJ87nU4ZB@aGO8yAAAAMg&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/servers&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YffBXRgJ87nU4ZB@aGO8yAAAAMg&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/servers&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YffBXRgJ87nU4ZB@aGO8yAAAAMg&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/servers&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YffBXRgJ87nU4ZB@aGO8yAAAAMg&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/servers&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YffBXRgJ87nU4ZB@aGO8yAAAAMg&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[8] https://www.theregister.com/2022/01/24/who_me/
[9] https://www.theregister.com/2021/06/28/who_me/
[10] https://www.theregister.com/2021/06/21/who_me/
[11] https://www.theregister.com/2021/05/17/who_me/
[12] mailto:whome@theregister.com
[13] https://whitepapers.theregister.com/
Re: Nobody told me I wasn't allowed to do it.
Thank you Gordon, you truly were Entropy's Little Buddy.
In my case the guy was named Keith. I think most places have one and they really help you improve things (after causing chaos).
Re: Nobody told me I wasn't allowed to do it.
Yeeeeeees... This is what QA is *meant* to do. Try anything, everything, see what happens. Even if that doesn't make sense to a developer and they rant on about how QA are trying all sorts of crap instead of testing the software.
No love, that *is* testing the software. If you do not sanitise your inputs, and you don't make sure your software doesn't let silly things like that happen, then yes, love, your software is going to do stupid things.
QA were, as much as they were the bane of the developers, my best friends because they highlighted pathways in the software that hadn't been thought of during the design/development process that needed to be... fixed/accomodated.
And yes. Unguarded prompts? Oh boy!
Re: Nobody told me I wasn't allowed to do it.
You mean Testers don't do this type of thing as standard? I've beta tested several products in my time. Knowing the product inside out meant that I could think up many a devious way to try and break it by doing something "unusual".
The mantra goes thus: "If a thing is possible, a user will do it. If a thing is impossible, a user will find a way do it anyway".
Re: Nobody told me I wasn't allowed to do it.
In my most recent incarnation, developing software for an automated cat feeder, I spent a long long time thinking up ways things might confuse the feeder. And yet, every now and then, something surprised us, like a cat simply beating up the feeder, or hiding toys in it, or in one case, an owner who rather than pushing the 'open' button simply picked up his kitten and let the feeder detect it to open the lid...
Re: Nobody told me I wasn't allowed to do it.
So did you cat or tail the files for that software?
Re: Nobody told me I wasn't allowed to do it.
I sometimes get paid for destructive testing, hard, firm and software. Paid quite well. Funny thing is I'd do it for free, in some cases. Don't tell anyone :-)
Re: Nobody told me I wasn't allowed to do it.
This reminds me of the episode of Cabin Pressure (can't remember which one) where Douglas challenges Martin to find out how many of the safety features they can disable and still fly.
"Hey, chief, I might be wrong, but I think we're flying into a mountain. This makes me feel... scared of the mountain. One thing we could do is pull up and fly over the mountain. How does that sound to..."
Hitting Enter....
Is exactly why Boots and the Co-Op Dept store in my home town were often filled with white noise of a saturday:
10 Goto 10 :Goto 10 :Goto 10 :Goto 10 :Goto 10 :Goto 10 :Goto 10 :Goto 10 :Goto 10 :Goto 10 :Goto 10 :Goto 10 :Goto 10 :Goto 10 :Goto 10 :Goto 10 :Goto 10 :Goto 10 :Goto 10 :Goto 10
was left on the BBC Micro, waiting for so less bright kid to hit enter :-)
Re: Hitting Enter....
I did indeed at one point type something into a demonstration computer in a store.
10 print "hello"
20 goto 10
run
Re: Hitting Enter....
I remember "a friend" "accidentally" plugging a PC keyboard back into a Dixons demo machine, and "accidentally" deleting autoexec.bat so that the machine would not start the demo next time it was powered on.
Back in the early 1980s when "Dixons Reject!" was a powerful term of abuse for someone who was completely stupid. Sorry Dixons, RIP.
Re: Hitting Enter....
As per the article..
"Like me, most people used the 'return' key to wake up a terminal."
Yes. Used to. These days its shift key, backspace, or something like that for that very reason.
Re: Hitting Enter....
We used to go into the big box computer chain in the days of (locked) scrolling screensavers being standard for display. Quick reboot got you out of the screensaver, change text, then _unplug the keyboard_ and wait for someone to notice.
Re: Hitting Enter....
Many years ago, but many years after lessons should have been learned, I remember playing with a PC that was running GORILLA.BAS under QBASIC as a floor demonstration, and it was fun making inputs that blew the map up in unexpected ways, but it was even more fun dropping to the editor and changing random things. Like showing my name at the top instead.
Don't do that!
Worked in an organisation that used smartcard and pins for authentication. I was in the office where the system admins worked. This was not a secure office. The admins regularly left their cards in the reader and buggered off. They usually had a loooong timeout set too. (saves having to put that long and complex four digit pin in.)
Procedures dictated that unattended smartcards be removed and reported. The System Mangler wasn't happy, the paperwork was a pain, and said to stop it.
So we (I) did stop. Didn't stop us (me) adding clear sticky tape to the chip or trimming the edges of the card so it was to small for the ID card holder. Or adding facial hair in indelible ink to the picture on the card.
Turns out this was more effective than them getting bollockings!
Anonymous for obvious reasons!
Re: Don't do that!
Oh yeah.
The number of contacts , switches and orifices to which the new fangled invisible sticky tape could be applied.
Jolly japes on a roll.
Re: Don't do that!
The matte Scotch is brillianr. when properly affixed, can be very difficult to spot.
Re: Don't do that!
I did like the way SunRays did it and your session "followed" you with the card. insert your card to another SR elsewhere in the office... or in another office in another country.
similar...
While at university in the mid 90s, my mate and I were doing some work and needed to FTP a file to/from one of the servers, so we opened up the supplied FTP client (stored on a Novell fileshare IIRC), typed in the server name and found an auto-completed config set for that server. With the root account. And a password saved in the config. We looked at each other and hit "connect"... and promptly had an FTP session on the server as root.
After confirming we were definitely in as root (by downloading, deleting and re-uploading /etc/passwd - yes, a bad choice in retrospect, we could have FUBAR'd the machine), we decided we'd better tell the lecturer who looked after that box about the issue. The config in the FTP client was removed that day.
Re: similar...
For some reason, probably to provide a maintenance window, the Unix box we were using for an assignment had user logins disabled for an hour at lunchtimes, just when we wanted to use it.
Fortunately a friendly sysadmin (yes, they do exist) had let slip the password for su so we could use that, then connect to our own accounts.
There were too many fellow students using the same box for anybody to do anything silly with the access, tempting though rm * (no need for the -r back then) may have been.
Marketing Company
We used to send data to a third party marketing company for them to prepare mailshots for us. This was done via FTP. One day after uploading our file, I decided to cd ../ and much to my surprise, it allowed me to. Being the curious sort, I then typed ls -la and saw a list of recognisable company names. Picking one at random, I was able to access not only their directory but also their data.
This was in the mid-90s when "hacking" was Very Naughty. I spoke to my boss who was in the same quandary as me - report it as a security risk or potentially get arrested? His decision was to keep quiet about it.
Re: Marketing Company
Possibly the best approach might have been to have your boss go apeshit at the third party marketing* company for their lack of security as your own data was as much at risk from anyone else with FTP access as theirs was from you!
* Ah, a marketing company - well, that probably explains their lack of security. Their server was probably set up by the marketing boss's teenage son whose knowledge was based on his experience with AmigaDOS.
Re: Marketing Company
At the end of the nineties I had a similar issue with an FTP server managed by one of our suppliers. In that case I knew the guy who managed IT there, gave him a quick call and he sorted it out. Had I not known that guy I would have also mentioned it to my boss, with the remark that “if we can see their data, they can probably see ours”…
/etc/shutdown ?
Binaries in the config dir? Was that really common in those days?
Yes. /etc used to contain the so-called "dangerous" system binaries that are now normally found in /sbin (and possibly in other places, depending on the system).
In the 90's I was working on a system fro a Police research department based in a Home Office building in London - we were based at the IT centre in Liverpool. At a meeting with the moron of a Chief Inspector in charge of the department (obviously deployed there to get him out of the way) he basically accused us all of being IRA sympathisers - "You've even got an Irish name!" I was told. After biting my tongue and assuring him that we were all sevcurity cleared, he went on about how sensitive the info was, and how access to it must be strictly controlled!
A week or two later I visited the office to see how the bobbies using the system were getting along and noticed a sticky label on a function key that said "Login". Using my supreme detective skills I asked the bobby what that was for - he said "we can't be arsed typing in user names and passwords, so we found out how to program it into the function key. One press and we're in!". Oh how I laughed!
Never underestimate the ability of Plod to bend IT to make things "easier"
Around 1986 I put together a "screensaver" for Sun gear that made the screen look like it had a couple of bullet holes in it. I occasionally deployed it on workstations where the user (engineer) had walked away, leaving himself logged in. Quite realistic on the colo(u)r Trinitrons of the day ... realistic enough to draw many a scream of "What the FUCK‽‽‽‽" from people who should know better.
At employer -1 one if you left your PC unlocked then they'd install and run the Sysinternals BSoD screensaver and then when you asked for help you'd get the bollocking...
We would type a resignation email and leave it unsent as a warning of why you locked your machine.
Nobody told me I wasn't allowed to do it.
While not a defence in law, this is precisely the approach that is often needed in IT.
The best tester I ever worked would come up to us and say, "When I do [THIS], then [THIS], then [THIS], it goes kaboom". We would ask, "Why would you even try to do that combination", to which he would reasonably answer, "Because it allowed me to". We would then either make it impossible to so do, unless it was a safe combination and should have worked in which case we would fix it.
Thank you Gordon, you truly were Entropy's Little Buddy.
An unguarded prompt is the same opportunity (or temptation). What can I do with this? What could possibly go wrong?