Search /
Docfinder:
Advanced search  |  Help  |  Site map
RESEARCH CENTERS
SITE RESOURCES
Click for Layer 8! No, really, click NOW!
Networking for Small Business
TODAY'S NEWS
FBI warns of holiday cyber scams
U.S. Open used Web filtering to prevent online gambling
Google Earth used by terrorists in India attacks
Mumbai terrorist attacks don't deter technology companies
Google layoffs: 10,000 jobs being cut, report claims
Experts to Feds: Sign the DNS root ASAP
Cisco shutting down between holidays
Sprint completes Clearwire WiMAX deal
Mobile sales to beat economic gloom, forecasts Ovum
Start-ups starting to feel economic pain
Spam levels fluctuate as crooks try to revive botnets
Mozilla eyes extra beta for Firefox 3.1
Grim forecast for holiday e-commerce sales
Talking Web, memory assistants and solar-powered cell phones headed mainstream, IBM says
Massive botnet returns from the dead, starts spamming
Security /

Ghost accounts: An open door to network sabotage

Today's breaking news
Send to a friendFeedback

Advertisement:


It's a scary indicator of a spiraling economy that through the first six months of this year nearly 1.1 million workers were laid off, according to the U.S Department of Labor.

Even scarier is the question of how many of those workers still have active accounts on the networks of their former employers.

So-called ghost accounts, those not closed when workers leave, can include access to mainframes, databases, file servers, intranets and e-mail. There are also remote access holes with VPN passwords and dial-in accounts. All open "back doors" into a network.


Internal net saboteurs being brought to justice
Network World, 08/27/01.

A recent series of high-profile network sabotage cases show that vengeful employees can wreak high-tech havoc.

"Disgruntled employees are a significant threat," says Larry Rogers, senior member of the technical staff at Computer Emergency Response Team Coordination Center. Security experts recommend a combination of procedures, policies and automation to combat the threat.

"We have an application that notifies all departments when an employee leaves, puts the user's passwords in a deny-access mode and quarantines their files," says one network administrator for a global distribution company who requested anonymity. "Part of the process is manual, and we are evaluating ways to automate that."

Automation is key and is being made available in a class of products known as provisioning software, which can automatically activate and deactivate user accounts.

"If you are a CIO and are currently using a manual process, fundamentally you have no way to know the process [of deprovisioning] worked. With provisioning software that is the opposite. You know that the process was completed," says Mike Neuenschwander, an analyst with The Burton Group.

Just last week Access360, Novell and Waveset Technologies announced provisioning products. Business Layers also has a product called eProvision Day One.

Access 360 released Version 4.0 of its EnRole provisioning software, which is now integrated with corporate directories to centralize user account information. Novell released its Employee Provisioning System, which is intended to create a single user identity across a corporate network. Waveset Technologies is offering for free its Inactive Account Scanner, which ferrets out dormant accounts.

However, the process must include social engineering, Rogers says. That means teaching employees not to share passwords and administrators not to reactivate closed accounts.

Rogers recalls one case where a former Coast Guard employee was able to hack into a database using a password given to her by an unsuspecting co-worker.

The result: A bill of $40,000 and 1,800 staff hours to repair the damage.

RELATED LINKS


NWFusion offers more than 40 FREE technology-specific email newsletters in key network technology areas such as NSM, VPNs, Convergence, Security and more.
Click here to sign up!
New Event - WANs: Optimizing Your Network Now.
Hear from the experts about the innovations that are already starting to shake up the WAN world. Free Network World Technology Tour and Expo in Dallas, San Francisco, Washington DC, and New York.
Attend FREE
Your FREE Network World subscription will also include breaking news and information on wireless, storage, infrastructure, carriers and SPs, enterprise applications, videoconferencing, plus product reviews, technology insiders, management surveys and technology updates - GET IT NOW.
* HOME    * RESEARCH CENTERS     * NEWS     * EVENTS

Contact us | Terms of Service/Privacy | How to Advertise
Reprints and links | Partnerships | Subscribe to NW
About Network World, Inc.

Copyright, 1994-2006 Network World, Inc. All rights reserved.