Help, my IT team has no admin access to their own systems
- Reference: 1648197013
- News link: https://www.theregister.co.uk/2022/03/25/on_call/
- Source link:
Today's story, from a reader Regomised as "Dan", takes us back to the end of the first decade of the 21st century. Dan was gainfully employed at a London-based MSP and frequently called upon to deal with the vagaries of Mirosoft's finest. As such, a frantic call from a well-known financial institution demanding immediate assistance was not the rarity it might have been.
What was unusual, however, was how cagey the customer was being about what was actually wrong on this occasion. Just that they needed help. And they needed it NOW .
[2]
"Our sales people at the time saw an opportunity to make some money and took it," recalled Dan, "sending me in on a massive day rate, but blind, without a real clue what I was there to do."
[3]
[4]
"When I arrived on site I was taken into a quiet room and told through hushed voices that the IT team had lost admin access to their own systems and needed someone to help them regain access …"
Oh dear. It transpired that during the financial crisis of 2007 and 2008 the company had elected to save costs by slicing staffing. The cutbacks included the then-head of IT, his deputy and the whole of the service desk. Heck – we've no doubt the words "outsource" and "offshoring" were heard in the offices of the beancounters.
[5]
Loyalty still being a thing, the IT boss's team had followed him out of the door and gone to work elsewhere, which left our well-known financial institution in a bit of a bind.
"The net result was a fairly junior team all being promoted to positions with lofty titles, but none of them having full administrative privileges to the entire network."
Well, this was awkward. The newly titled staff did not want to confess to their bosses that they were out of their depth and inadvertently reveal hitherto hidden levels of incompetence. They had therefore found the funds to get someone on site to sort their access. Hence the call.
[6]
Dan was talked through the complexities of the network topology. He was given a long list of accounts for which credentials were needed. He was then marched to the server room before being wished good luck. The door was closed and Dan was left alone with racks and racks of headless hardware.
What to do? At least everything was running on physical kit, but that was pretty much all that could be said for it.
Dan walked to the first server and connected up a monitor, keyboard and mouse. Just to see what he was dealing with.
The mouse was jiggled and the monitor burst into life. A Windows Server 2003 desktop appeared: a logged in desktop … for the Active Directory box. With full admin rights.
It transpired that the departing IT staff had either left things in a state where their replacements could pick things up easily, or simply didn't bother with such fripperies as time-outs, auto-logouts or password-protected screensavers. Dan could scarcely believe his luck.
"I was able to easily reset the master Admin account to Active Directory in under a minute," he recalled, as well as remembering the look of undisguised relief on the faces of client as they beheld his genius. Sure, he could have simply said the server hadn't been locked, but where was the fun in that?
"They still regard me as some form of super hacker to this day because I never told them how I really managed it so quickly," he confided.
"I think my company charged a sweet £1,000 for my time!"
That's around £1,500 ($1,980) in today's money. Not bad for a few seconds' work.
We know the lifestyle trappings of consultancy bosses don't pay for themselves, but have you ever found yourself the hero of the hour even if the effort expended came to zero? Or is it all down to a special jiggle of the mouse? Tell us the simple solution to your call out for which your client still calls you a magician with an email to [7]On Call . ®
Get our [8]Tech Resources
[1] https://www.theregister.com/Tag/on-call
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/systems&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Yj2g3tvHwf0ImyOJBqEtjQAAAJE&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/systems&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Yj2g3tvHwf0ImyOJBqEtjQAAAJE&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/systems&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Yj2g3tvHwf0ImyOJBqEtjQAAAJE&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/systems&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Yj2g3tvHwf0ImyOJBqEtjQAAAJE&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_onprem/systems&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Yj2g3tvHwf0ImyOJBqEtjQAAAJE&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[7] mailto:oncall@theregister.com
[8] https://whitepapers.theregister.com/
I used to be the IT Manager for my company many years ago. I insisted that all admin passwords had to be printed off, placed in a sealed envelope and securely stored. Got taken out for a beer a couple of years afterwards by my successor - that strategy had saved his bacon when someone responsible for managing a critical system left the company without doing a proper hand-over.
Always a sound strategy, but sadly screwed up these days by IT forcing everyone, even admin accounts, to change passwords every month or two.
Miracle workers
It is like giving a book to a future tablet user. There are no buttons and you actually need to turn the page manually. I'd gladly take £1000 for turning the page once without them seeing the trick.
Re: Miracle workers
Books?! We should never have given up scrolls!
https://www.youtube.com/watch?v=pQHX-SjgQvQ
This article is briiliant! :D
What I want to know is did the bloke state he "fixed" it as soon as he did so, or wait a few hours? Was he even getting paid an hourly rate?
All just under an hour. I'm guessing the briefing was at least 45 minutes, walking to the server room took 10 minutes and the fix was 1 minute.
There is long established precedent in the industry for this. I was convinced that the two-day very expensive performance uplift to ICL 2900 series mainframes was 1 3/4 days of the white-coated technician eating his sarnies, half an hour taking the side panel off, 10 seconds with the tin snips to cut the wire to the performance-slugging circuit, 10 minutes to put the panel back on and half an hour to do the paperwork.
If there was a quality management system in place swap the eating sandwiches and doing paperwork times.
I once worked for a medium sized IT services company. One of the sales people was a solid gold twat who just happened to be a director’s son. Eager to wring extra money out of a poor and unsuspecting customer, he sold them a ‘mandatory’ pbx upgrade. With on-site engineer services, ‘hardware’, licenses etc the total came out at about £15k.
The ‘work’ consisted of a guy walking in with cardboard boxes, turning the phones off and eating his sandwiches in the comms room. After a few hours of snoozing and YouTube he turned the phones on, put a different plastic cover on the pbx, then went home. Disgraceful.
That sales guy was such a prick, I very much doubt this was the only time it happened.
A dangerous game, as I'm pretty sure that's actually fraud. Had one of his customers / victims caught on, both he and the company could have landed in some very hot water.
snips, we don't need no snips
That story was factually incorrect. The work would have been performed by a level 2 engineer who would have loaded a new CPU micro program from tape. There would also have been a requirement to check the microcode levels of all the associated disk and tape controllers to ensure they were at the same level as the new CPU microcode. It may also have been necessary to run the ATS (Ashton Test Suite, named after the factory) to confirm that the system was functioning correctly. I imagine that this would would have been scheduled over a weekend and would have allowed at lead a couple of hours in a local hostelry , probably while ATS was running.I never once saw an engineer with sandwiches, they lived entirely on liquid diets.
What about other systems? I doubt everything was AD integrated and that it was all left unlocked ready to go.
"...
I used to be the IT Manager for my company many years ago. I insisted that all admin passwords had to be printed off, placed in a sealed envelope and securely stored. Got taken out for a beer a couple of years afterwards by my successor - that strategy had saved his bacon when someone responsible for managing a critical system left the company without doing a proper hand-over..."
There should always be at least one break glass account per system where the accounts are stored offline, in a secure place (fire safe, for example, or some equivalent even if it's digital).
When tech support manager I always insisted on this. Imagine my embarrassment when after having had to retrieve the password for a mainframe system to heck up on dome config info, when my sysadmin was away for 2 weeks I left it in a shirt pocket and it was then washed. I had a very nervous 10 days hoping that there was no need for admin access to the system. All credit to him that there was no need for any system privilege access for the whole period. No Disks filled, nothing expired we didn't even need to create any new users while he was away.
Shades of The Lone Jedi...
For those of us of a certain age!
Does your CMDB extend to password stores & credit cards?
Similar thing at "an/other" financial organisation, where Azure was setup with a credit card. A personal one. Something got productionised, and then the card holder left the company. Some payment reminders presumably went to an inbox which was no longer serviced (or more likely in existence).
Not long after, an Azure subscription magically vanished. Which was nice.
Password storage (actually secure) *was* a thing. Checking how it was funded, less so....
don't spoil the magic
Well, that was very badly managed. You NEVER do a two minute job in two minutes! You MUST stretch it out to at least an hour or the customer won't believe they're getting value for money. You are the expert with years of experience, training, knowledge and wisdom. Don't ruin the illusion.
Re: don't spoil the magic
As Scotty taught us…
https://youtu.be/8xRqXYsksFg
Re: don't spoil the magic
That depends on whether you want a reputation as a hero or magician.
Re: don't spoil the magic
I'd settle for God status.
Re: don't spoil the magic
..whether you want a reputation as a hero or magician.
Which pays more?
Re: don't spoil the magic
I think after several days being stuck with an unsolvable problem, the customer would pay handsomely for one of your farts if it looked like it fixed things, regardless of how short a time it took.
A former employer allowed their drawing office to source new CAD systems without consulting IT (me!) Fine, they were NT-4 boxes but this was prior to AD so it didn't really make a lot of difference. My only involvement was dragging the delivery van out of the mud after they'd decided to drive up to a window and pass the boxes through that rather than take them 30 feet further through reception (I did have a Range Rover at the time - see the fuel bills!)
Several months after they'd decided they didn't need an IT manager and made me redundant I had a call, "Do you know the admin password for the CAD machines?"
I took great delight in pointing out that they hadn't involved IT in the purchase/installation and hadn't given us the passwords therefore I couldn't help. My suspicion is that the vendor had never actually told anyone what the passwords were but that wasn't my problem.
At my current employers there is an encrypted spreadsheet on a backed up server folder with two senior people having the key to decrypt it, just in case.
At my current employers there is an encrypted spreadsheet on a backed up server folder with two senior people having the key to decrypt it, just in case.
that is a great way of storing those passwords,
How often are those passwords rotated or even checked?
Does the encryption get redone when one of those seniors leaves?
Do the seniors know where they have stored their password and do they know how to retrieve in the event ion an issue, is that tested?
Not raining on your parade just wondering how far down that rabbit whole I'd need to go if I did the same.
To answer, for info,
Every few months or if something significant changes.
Hasn't happened yet but it will if/when one leaves and a substitute is appointed
I probably should audit them on it but they're both pretty reliable on these matters.
Well, sometimes knowing how to fix something in one minute is a results of 20 years experience. So, charging for one minute of your time should factor your experience too. That's why I won't feel that bad for overcharging customers.
As they say, it's $50 for the hammer, and $400 for knowing where to use it.
A magician!
Never reveals how his tricks work!! At least to the audience. I always found it best to share these experiences with my colleagues, we all like a good laugh!
I left a company once because the new management decided I was no longer needed
A couple of months later the manager tracked my down by phone at my new job, "err you wouldn't happen to know the admin password would you, we've lost it."
I did remember it, and I remembered where it was written on a post-it, but I let them squirm for a few days whilst I "tired to remember"
I did remember it
Without a consultancy fee?
Organic memory needs beer* vouchers to refresh.
* Chateauneuf du Pape vouchers if you are working in the city.
Top Dog
At one company I worked for, we had to use a production system run/supervised by a sister company who seemed to want to prove their superiority. (The system was hopelessly out of date but that's another story). The supervisor would visit, usually to sort out a 'technical glitch' that only he could resolve. It was a clear scam to get a day out at our expense. When we realised that this was going on, we quickly 'discovered' his login details and in doing so obtained much wider access than we anticipated..... We used this access carefully to maintain our rich data source; as well as prevent the 'glitches' recurring.
His password was 'Top Dog' and he used it for everything. He must have puzzled the persistent canine references in the surrounding chatter.
Re: Top Dog
Brilliant! I would not be able to resist mumbling ‘sausages’ in a doggy style voice, followed by light panting, as I walked past him…..
Me: “SROSSAJIESS!”
Him: “What was that?”
Me: “RNNUFFINK!”
That's around £1,500 ($1,980) in today's money
£1800....
£1900...
£2000....
Cost of living these days....
Admin access
In a previous job in the early 2000's, where I was IT Manager (and I was also 50% of the IT team), I was made redundant, partly enabled by underhand reassigning of roles. We had an internal meeting where the organisation chart was displayed. I pointed out that they had me down in the wrong role, but it was brushed over - I should have seen the signs...
Anyway, on the day they called me down to tell me I was redundant, they asked someone else to revoke my admin rights and changed the admin password. I was allowed to go back to my desk for the rest of the day to copy off my personal files from my computer. As I had been logged in the whole time, I still had full admin rights and could have done anything, but obviously didn't do any damage. I did copy off a few customer directories from a server so that I could make direct contact with them after the event and actually did some work for many of them.
A few months later, after the redundancy period was up, I received a call asking for the password for a specific system. I told them what my rates were for consultancy and they never bothered me again. They lost many knowledgeable developers due to the way those of us who were made redundant were treated and eventually went bust.
I worked in a small company that worked closely with other similar, local companies. We all had independent IT. One day I got an email from one of the other IT teams asking me to reset their admin password as they'd lost it. I replied saying I couldn't as I didn't have access to their system. It took a bit of persuading that I couldn't help. They then asked how they could reset the admin password. I told them it probably wouldn't be a quick and painless process (just as it shouldn't be)
The admin password they'd lost was the global admin account for their Office 365 tenancy.