[13480] in Public-Access_Computer_Systems_Forum
Hacking Libraries
daemon@ATHENA.MIT.EDU (John Dooley)
Mon Aug 14 09:01:29 2000
Date: Sat, 12 Aug 2000 13:04:02 -0500
From: John Dooley <dooleyj@MEMPHIS.LIB.TN.US>
To: PACS-L@LISTSERV.UH.EDU
Reply-to: Public-Access Computer Systems Forum <PACS-L@LISTSERV.UH.EDU>
Message-id: <NDBBICLGOMOOBGALHDMLAEAKDCAA.dooleyj@memphis.lib.tn.us>
MIME-version: 1.0
Content-type: text/plain; charset="iso-8859-1"
Content-transfer-encoding: 7bit
Libraries can be attractive target sites for hackers
because they are assured a fairly large audience will
see the hackers mark.
The Memphis Shelby County Public Library was hacked twice
where the hacker replaced the library home page with
a graphic of the hackers screen name. We are not sure
how this was accomplished.
We currently do the following:
1. Installed a firewall
2. Made sure security patches are applied as released
3. Use and update anti-virus software
4. Frequently change passwords and do not use defaults
5. Limit access to sensitive applications
6. Maintain regular backups
7. Lock down public browser PC's with Fortress
8. Update filter software database and patches as released
9. System consoles in locked secure environment
Please post what your library is doing and relate your
experiences.
Sincerely
John Dooley
Computer Resources Librarian
Automated Services
Memphis Shelby County Public Library and Information Center
1850 Peabody Ave.
Memphis TN 38104
ph: 901-825-8817 x740
e: dooleyj@memphis.lib.tn.us
w: www.memphislibrary.org