[13487] in Public-Access_Computer_Systems_Forum

home help back first fref pref prev next nref lref last post

Re: Hacking Libraries

daemon@ATHENA.MIT.EDU (Dean M. Riley)
Tue Aug 15 20:13:57 2000

Date: Mon, 14 Aug 2000 16:52:32 -0500
From: "Dean M. Riley" <driley@HBU.EDU>
In-Reply-To: <NDBBICLGOMOOBGALHDMLAEAKDCAA.dooleyj@memphis.lib.tn.us>
To: PACS-L@LISTSERV.UH.EDU
Reply-To: Public-Access Computer Systems Forum <PACS-L@LISTSERV.UH.EDU>
Message-Id: <4.3.2.7.0.20000814161800.00b4e780@mail.hbu.edu>
Mime-Version: 1.0
Content-Type: text/plain; charset="us-ascii"; format=flowed

John,

We are definitely a work-in-progress. We were surprised that our
administration moved on our proposal. We thank them for that! In our
environment, I must view the total situation as: 1) what can I control, 2)
what do others control.

Of what I can control --

1. Developing system policies (changing passwords, etc.)
2. Updating with latest patches and virus protection.
3. Re-writing backup job scripts to include new functionality after we get
up and running.

What I cannot control (but I am working on trying to get more input!) --

1. New routers. IS is getting new routers with better firewall protection
for the campus. The campus does have a proxy server and routers with heavy
protection.

2. Security software for my database. Right now, the main database is about
to be opened to the campus intranet.  Hopefully,  I can add a security
package to better protect the catalog database before opening up to the
Internet. However,  the problem is that we'll be migrating from the current
HP3000 platform to an NT platform within two or three years. The
administration and IS want to see how the new routers will do before
committing to purchasing it. Also, I believe they want to wait and utilize
NT security more after we convert. I assume their argument is -- "Why spend
the money on HP protection if we are going to convert in two+ years?" I
feel like responding with the line from the car transmission commercial  --
"You can pay me now or pay me later."

3. IS has had to reduce security in the labs because various faculty have
software they want to use in conjunction with their classes but the former
tight security policies had to be relaxed to allow for more software
functionality. Policies were so tight that much of the software would not
function. We used to have Fortres until IS moved to system policies and NT
policies. The campus is going more and more to NT. We are on the same
network as the labs so we invariably have less security as well. The
Windows 95/98 system policies are fairly weak.

I am personally uncomfortable with the current situation of the things I
cannot control. I would rather protect the library's database than have
students knocking on my door asking why the library catalog has been down a
week when they have papers due. I do understand the administration's
concerns -- everyone has a job to do. I realize there are budget restraints
but I think some things should take a higher priority. I will probably get
more aggressive on this stance as we move forward. I think that is the most
difficult part of our work -- knowing what we need but not being able to
get it due to budgets or other reasons.

I'm going to think positive for now and hope to have good news to share
with you in the next several months. I hope I've answered your question.

Dean

At 01:04 PM 8/12/00 -0500, you wrote:
>Libraries can be attractive target sites for hackers
>because they are assured a fairly large audience will
>see the hackers mark.
>
>The Memphis Shelby County Public Library was hacked twice
>where the hacker replaced the library home page with
>a graphic of the hackers screen name.  We are not sure
>how this was accomplished.
>
>We currently do the following:
>
>1. Installed a firewall
>2. Made sure security patches are applied as released
>3. Use and update anti-virus software
>4. Frequently change passwords and do not use defaults
>5. Limit access to sensitive applications
>6. Maintain regular backups
>7. Lock down public browser PC's with Fortress
>8. Update filter software database and patches as released
>9. System consoles in locked secure environment
>
>Please post what your library is doing and relate your
>experiences.
>
>Sincerely
>John Dooley
>Computer Resources Librarian
>Automated Services
>Memphis Shelby County Public Library and Information Center
>1850 Peabody Ave.
>Memphis TN 38104
>ph: 901-825-8817 x740
>e:  dooleyj@memphis.lib.tn.us
>w:  www.memphislibrary.org

home help back first fref pref prev next nref lref last post