[13466] in Public-Access_Computer_Systems_Forum
Re: Library Computer Hacking
daemon@ATHENA.MIT.EDU (David J. Ives)
Mon Aug 7 20:20:13 2000
Date: Sat, 05 Aug 2000 07:09:46 -0500
From: "David J. Ives" <eldjives@SHOWME.MISSOURI.EDU>
To: PACS-L@LISTSERV.UH.EDU
Reply-to: Public-Access Computer Systems Forum <PACS-L@LISTSERV.UH.EDU>
Message-id: <398C040A.8F29BAD7@showme.missouri.edu>
MIME-version: 1.0
Content-type: text/plain; charset=us-ascii
Content-transfer-encoding: 7bit
I would agree, wholeheartedly, that library computers are just as much
targets for hackers as are any other computers.
I'm running the Black Ice Defender firewall on a webserver I maintain, and in
the last 90 days it has blocked 274 attacks it classifies as "suspicious" and
18 attacks it defines as "critical". My NT desktop machine is running dual
firewalls, is on a different subnet, and reports an equivalent number of
attacks. These attacks include: numerous port probes for the SubSeven
trojan, FTP port probes, SNMP discovery broadcasts, UDP port probes, TCP port
probes, DNS port probes, TCP OS fingerprint probes, and RPC port probes.
These attacks have come from numerous sources, domestic and 'foreign', from
dial-in machines and from machines based in other educational institutions.
In fact, I just sent e-mail to BYU informing them of a SubSeven trojan probe
from one of their computers against both of the MU Libraries' subnets.
In all cases, these attacks were blocked, but I doubt if I would have known
they were taking place (perhaps one of the sources for the thought that
"library machines aren't targets" -- if you have no detection h/w or s/w
installed, you detect nothing).
David Ives
Library Technology Services
U. of Missouri Libraries
"Dean M. Riley" wrote:
> After all these years, we are finally going to put our library catalog on
> the web. That will, of course, mean changes to some of routines --
> particularly in regard to network security. I suspect that some of my
> colleagues will not agree with my assessment but I believe that libraries
> are just as vulnerable to hacking as any other organization and should
> therefore be as vigorously protected as possible. I recall one discussion
> where one colleague just did not believe that libraries were regular
> targets of hackers. I only know of one incident personally but I would
> suspect that there are many more. With all the hacking stories we hear in
> hear from the media in today's environment, this seems like a silly
> question -- but would you all agree with that assessment?
>
> Thanks for your comments and opinions.
>
> Dean Riley
> -----------------------------------------------------------------
>
> Dean M. Riley Phone: 281-649-3000 x2304
> Systems Librarian FAX: 281-649-3489
> Houston Baptist University Email: driley@hbu.edu
> Moody Library
> 7502 Fondren
> Houston, TX 77074-3298
>
> "A fiery horse with the speed of light, a cloud of dust and a hearty
> 'Hi-yo, Silver.' The Lone Ranger."
>
> All expressed opinions are mine and do not necessarily reflect those of
> Houston Baptist University.