[13472] in Public-Access_Computer_Systems_Forum
Re: Library Computer Hacking
daemon@ATHENA.MIT.EDU (Stephen Westman)
Tue Aug 8 20:11:06 2000
Date: Tue, 08 Aug 2000 09:29:04 -0400
From: Stephen Westman <westman.2@OSU.EDU>
In-reply-to: <4.3.2.7.0.20000804075309.00b47740@mail.hbu.edu>
To: PACS-L@LISTSERV.UH.EDU
Reply-to: Public-Access Computer Systems Forum <PACS-L@LISTSERV.UH.EDU>
Message-id: <4.2.0.58.20000808085639.00bd89e0@pop.service.ohio-state.edu>
MIME-version: 1.0
Content-type: text/plain; charset="us-ascii"; format=flowed
IMNSHO, it is both dangerous and naive to think that libraries are somehow
immune to this kind of attack. The bad news is that we aren't! Our servers
are
no different than any other servers out there on the Internet.
Indeed, libraries are as vulnerable to attacks as any other system on the
net and
quite often fall victim to a wide variety of attacks. For example, on the
day I was
on campus to interview for a position, it was discovered that the library
had had
both of their Unix servers compromised by hackers the previous weekend. It
took
a significant amount of time to get the situation resolved and to
re-establish some
security on those servers.
In addition to that situation, at least one of the library's Unix servers
(a Sun SPARC20) at my previous position had been compromised less
than three months before. While the problem was solved due to early
detection and securing of the system, other servers on campus which had
been compromised in the same way took hundreds of person-hours and
tens of thousands of dollars to be made secure again.
There are several things that should be kept in mind.
First of all, it is very easy to succumb to the notion that hacking a library
computer is like tripping a little old lady - only a cad would do it. However,
the realities are much different. This is especially true, given some of the
things that libraries sometimes do (like charging overdue or lost book fines)
can cause nascent hackers to target library servers. Even though we may
think of ourselves as the "good guys", hackers don't make any distinctions
between us and any other service provider.
Beyond that, there are many reasons that hackers might go after a box.
Besides the "I've got a grudge against the library" rationale, "script
kiddies"
often don't know which IS and ISN'T a library box (and even if they did, it's
hard to believe that they would actually CARE). Many times all they are doing
is to launch a probe of all IP addresses available on a particular network
without
knowing who owns a particular server. If they find that a certain box has
vulnerabilities that they can identify and exploit, they will then use that
information
to gain illicit entry. Once such entry has been gained, they have all sorts of
possibilities open to them.
Another motivation is, if a computer has a lot of power (which a number of
the boxes
that libraries are using for online catalogs and for web servers DO), they
can be very
attractive to hackers who are looking for "free bandwidth" - a computer
with which
they can do all sorts of CPU-intensive things without having to pay for those
large-capacity servers themselves. Example tasks include breaking password
files
and cracking encryption schemes (particularly interesting for hackers
trying to
gather credit card numbers off of the net).
Also, even the lowliest of systems can be used as a screen behind which
hackers can hide where they are REALLY coming from. By hacking into another
system from a "borrowed" server, it is much harder to track down the person
responsible - particularly if the hacker is hiding behind three, four, five
or even more
boxes. Such server can also be used to "sniff" passwords on more powerful
machines
(including campus information systems and bill payment servers).
More recently, "Distributed Denial of Service Attacks" have become
increasingly
popular. This type of attack is similar to that which was launched against
amazon.com and a number of other online vendors a few months ago. The way
these programs work is that they hackers attack a large number of boxes (often
numbering into the hundreds, if not thousands) and install automated robots
controlled from a central server(s). This/these server(s) can then use
these hundreds,
even thousands, of these compromised servers to target individual hosts.
Because
of the large numbers of computers involved, only a small amount of bandwidth
(sometimes less than one CPU cycle per minute) is required from each
compromised
machine to bring a target server to its knees.
The thing that should cause librarians (and administrators of library
boxes) some concern
is that there are questions as to the extent to which systems
administrators whose equipment
has been used to hack other servers can he held legally liable for what has
been done
under the auspices of their machines.. While it may be questionable as to
whether such
claims could stand up in court, I have seen at least one institution which
threatened sysadmins
by stating that, were their boxes to be used in an attack that brought a
lawsuit against said
institution, the sysadmins could be held personally liable for the
situation with their being some
question as to the amount of support those sysadmins could expect from the
institution.
The good news is that a reasonably informed and equipped systems
administrator can do a lot
to make his/her system secure and to discourage would-be hackers from
having a field day.
While one can never make one's system 100% secure (yes, even NT boxes are
vulnerable to
Denial of Service attacks along with a multitude of other possible system
compromises), it is not
hard to make it difficult enough to discourage the casual hacker and to
encourage them to go
elsewhere. Towards that end, there is a large (and growing) number of open
source, shareware,
freeware, and other tools that one can easily install on a site to make
things more secure. In
addition, by subscribing to certain listserves (such as SANS and CERT), one
can keep up on
"breaking news" (no pun intended) in the area and to find out how to
protect themselves.
To paraphrase Philip Greenspun, we "need to be afraid, be very afraid".
Unless we take all
possible steps we can to make sure our system are secure, we will be
constantly (and
increasingly) vulnerable to the vagaries and whims of hackers who have more
time and
expertise than they do sense and consideration.
At 08:02 AM 8/4/00 -0500, Dean M. Riley wrote:
>After all these years, we are finally going to put our library catalog on
>the web. That will, of course, mean changes to some of routines --
>particularly in regard to network security. I suspect that some of my
>colleagues will not agree with my assessment but I believe that libraries
>are just as vulnerable to hacking as any other organization and should
>therefore be as vigorously protected as possible. I recall one discussion
>where one colleague just did not believe that libraries were regular
>targets of hackers. I only know of one incident personally but I would
>suspect that there are many more. With all the hacking stories we hear in
>hear from the media in today's environment, this seems like a silly
>question -- but would you all agree with that assessment?
>
>Thanks for your comments and opinions.
>
>Dean Riley
>-----------------------------------------------------------------
>
>Dean M. Riley Phone: 281-649-3000 x2304
>Systems Librarian FAX: 281-649-3489
>Houston Baptist University Email: driley@hbu.edu
>Moody Library
>7502 Fondren
>Houston, TX 77074-3298
>
>"A fiery horse with the speed of light, a cloud of dust and a hearty
>'Hi-yo, Silver.' The Lone Ranger."
>
>All expressed opinions are mine and do not necessarily reflect those of
>Houston Baptist University.
Stephen R. Westman
Digital Resources Systems Administrator
Ohio State University Libraries
1858 Neil Avenue Mall
Columbus, Ohio 43210
(614) 688-0142
westman.2@osu.edu