News: 1710145871

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Intern with superuser access 'promoted' himself to CEO

(2024/03/11)


Who, Me? Aaah … Monday! That wonderful week-opening day that brings with it so many possibilities. Including, as Register readers know all too well, the chance to make errors that must then be discreetly buried – the subject of our Who, Me?, our weekly reader-contributed tale of career-threatening bullets you’ve managed to dodge.

This week meet a reader we’ll Regomize as “Niall”, who told us of his time as an intern at “a well-known massive semiconductor company.”

Niall’s team developed firmware and software; a role that saw it equipped with what he described as “a couple of *nix servers that were used for general development / testing/ continuous integration tasks.”

[1]

Everyone on the team, even lowly Niall, had a superuser account on those boxes.

[2]

[3]

“Being an intern, I spent a lot of time faffing about with things we didn't necessarily need and that nobody had asked for,” Niall admitted. One of those unnecessary things was a cron job that used the servers to send an email to other team members at 3:00PM sharp, to remind them it was time for a tea break.

Niall now thinks he was probably the only team member who thought that this was in any way cool or interesting.

[4]

But while he was setting up the automated email, he noticed something that was definitely interesting to his underoccupied mind: the email client he was using (mutt) allowed users to use any email address in the “From” field.

“Received emails would display in Outlook as if it really had come from that email address, complete with corporate profile photo etc,” Niall told Who, Me?

Like most interns, Niall was young. And like many young people, he didn’t always think things through very well.

[5]

So he set the From field to include the name of the massive semiconductor company’s CEO and sent an email to a colleague to advise him that he was fired, effective immediately.

“I thought it was hilarious,” Niall said.

Bu the recipient did not “and came over to tell me what a complete idiot I was.”

[6]If we plug this in without telling anyone, nobody will know we caused the outage

[7]'Crash test dummy' smashed VIP demo by offering a helping hand

[8]Health system network turned out to be a house of cards – Cisco cards, that is

[9]Developer's default setting created turbulence in the flight simulator

It didn’t help that Niall had pulled similarly lame pranks before – but identifying Niall as the likely source of the prank wasn’t the reason he was labelled a fool.

He earned that label because, as the recipient of the prank mail pointed out, replying to the message would have seen it arrive in the inbox of the actual CEO.

“If that happened, I probably would have been in a great deal of trouble,” Niall told Who, Me? That it did not happen, and he enjoyed a career in tech that continues to this day, was down to the kind toleration of a senior colleague.

Have you pulled a prank that rebounded badly? If so, [10]click here to send an email to Who, Me? . Our mailbag is a little threadbare so help us out by sharing a story.

You’ll never be identified, and no story is too silly to share. ®

Get our [11]Tech Resources



[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Ze7kRUHegN1th4caYXaJJQAAAUo&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Ze7kRUHegN1th4caYXaJJQAAAUo&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Ze7kRUHegN1th4caYXaJJQAAAUo&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Ze7kRUHegN1th4caYXaJJQAAAUo&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_software/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Ze7kRUHegN1th4caYXaJJQAAAUo&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[6] https://www.theregister.com/2024/02/26/who_me/

[7] https://www.theregister.com/2024/02/12/who_me/

[8] https://www.theregister.com/2024/03/04/who_me/

[9] https://www.theregister.com/2024/02/05/who_me/

[10] mailto:whome@theregister.com

[11] https://whitepapers.theregister.com/



Been there, done that

Anonymous Coward

The really prickly, self styled IT manager at the European head office of one company I worked for, sent out an email to the whole company to say that she had just enjoyed a wonderful 2 weeks in the US sun on a security course and now everything IT was setup tighter than a Gnats chuff.

Needless to say that it wasn't her that sent it!

Evil Auditor

That is indeed a difficult situation to resist. Ours was an internal *nix server that unnecessarily ran an unprotected mail server. So, we the CEO decided to send a rather sarcastic e-mail to the person responsible to inform them of the open mail server on their machine.

Pascal Monett

Same problem. Had the recipient decided to respond, the CEO would have gotten involved, and I'm not they are of a race who approve their name being used without their knowledge . . .

Evil Auditor

That thought did cross our minds, too. But given that it was the CEO of a major international financial institution, chances were dim for the recipient to not pick up the clue. And even had they replied, it probably would have been filtered out by a CEO's assistant.

"That it did not happen"

Pascal Monett

And he could count his blessings that day, because today there would have been a response, quickly, and then things would have escalated from there.

A massive semiconductor company, eh ? Not based in Taiwan, eh ? Sounds like Intel. Looks like Intel participated in the learning IT security paradigm.

You don't give interns superuser access to anything.

Now they know why.

Seems more common than I thought

TonyJ

About 22/23 years ago, I worked for a large manufacturer. They were a Lotus Domino/Notes shop as well as big users of Citrix (the latter being the reason I was there).

One of the young lads on the helpdesk was a bit of a prankster and often got himself into a spot of bother for acting before thinking.

This one particular day, he was called out to one of the HR managers' for some problem on her desktop.

Whilst he was fiddling around with her computer, she went to get a coffee, leaving our intrepid plank alone for a few minutes.

Did I mention his dad also worked for the company at the same site. Not in am IT role, as I recall, but he had email.

He also had a sense of humour, so when he received an email from the HR manager that read "You're fired you bald bastard!" he knew it was a joke. He also had a good idea (he'd been on the receiving end of his son's pranks before) who had sent it, so he did nothing with it.

Again, though, the genius that the kid was, he didn't delete it from sent items.]

Yeah...you guessed it. The HR manager found the email and lodged a formal complaint. Due to his other pranks it ended up being a final written warning.

It was quite funny, though.

This is where technology lets you down

Lurko

Back in the day of the hard copy office memo and internal post, with a bit of imagination and care, a PC, a photocopier, and an internal mail envelope (last addressed to another team) it was easily possible to pull off these sorts of capers without any provable link to the originator.

One particularly successful effort of mine resulted in a senior manager writing to a board director and a tranche of other senior managers to deny that his team was going into hibernation over the winter. Nobody was ever caught, or even accused, but I know that management mentally assigned the blame to the wrong person. Collateral damage, from my perspective.

HR Security

Sam not the Viking

When I worked for the UK subsidiary of a medium-sized international concern, HR (UK) wanted to introduce a system which would collate all personnel detail into a single program. This would include details such as bank-details, passport, as well as the usual personal information. She had set up some details to show how it all worked and organised a demonstration. Best of all this program was 'Free' and internet-based. "What could possibly go wrong?"

Being a 'Superuser' she had access to all and everything and demonstrated the frightening detail at her fingertips, including her personal bank details. It gets worse. Telling us her password was <> she confided that used her daughter's name for all her passwords. Anyone could now log in using her name and password and view everyone's details. On a 'free' online sysyem....

I refused point-blank to have any of my details applied to this system. I was threatened with disciplinary action if I did not comply. The projected system was quietly abandoned as was the HR lady.

The five rules of Socialism:
(1) Don't think.
(2) If you do think, don't speak.
(3) If you think and speak, don't write.
(4) If you think, speak and write, don't sign.
(5) If you think, speak, write and sign, don't be surprised.
-- being told in Poland, 1987