iTnews
  • Home
  • News
  • Technology
  • Security

Network admin pwn caught on server room cams

By Staff Writers
Mar 5 2012 1:04PM
Follow google news

Attackers break voting system, capture moment admins find out.

University of Michigan researchers have used webcams in a data centre to capture the moment administrators of an internet voting system learned they had been pwned.

Network admin pwn caught on server room cams

The researchers participated in a sanctioned attack on the voting system developed by the Washington DC Board of Elections and Ethics [pdf].

The system was designed to allow military and overseas voters registered in cast electronic ballots in a local election.

However, prior to general use, it was subjected to a "mock election" process where "anyone" was invited to probe its security.

The University researchers found a shell-injection vulnerability on the mock server after several hours examining the application source code.

"We exploited the shell injection vulnerability to carry out several attacks that illustrate the devastating effects attackers could have during a real election if they gained a similar level of access," the researchers said.

Their attack attempts went unnoticed by the intrusion detection system (IDS) device deployed in front of the web server, because it "was not configured to intercept and monitor the contents of the encrypted HTTPS connections that carried" the attacks.

The researchers retrieved the public key used to encrypt ballots on the system. The key was used to change past and future votes lodged in the system.

Although the researchers took steps to cover their tracks, they left a "calling card" in the form of a video that appeared on a modified "Thank You" page.

In addition to attacks on the system, the researchers also severely compromised the physical network infrastructure on which the system operated.

The researchers used a publicly-available network topology diagram for initial clues as to the underlying architecture.

They were able to locate a terminal server, install a JavaScript rootkit to conceal their presence and eventually crack administrator passwords for various network boxes.

Acting as admins

The researchers said they helped repudiate an SSH attack from Iran on behalf of the actual network administrators.

A review of the terminal server logs showed attempts to guess SSH login passwords.

"We realised that one of the default logins to the terminal server (user: admin, password: admin) would likely be guessed by the attacker in a short period of time, and therefore decided to protect the device from further compromise that might interfere with the voting system test," the researchers said.

"We used iptables to block the offending IP addresses and changed the admin password to something much more difficult to guess.

"We later blocked similar attacks from IP addresses in New Jersey, India, and China."

Later, the researchers were able to gain broader access to other switches on the electoral network and change usernames and passwords - "effectively locking the administrators out of their own network".

Webcam access

On the same network, the researchers found a pair of publicly-accessible webcams showing the server room that housed the pilot network.

The cameras were pointed at the entrance to the room and at the rack of server and network hardware.

Malicious users could have watched the footage to determine the types of servers used or to "learn the pattern of security patrols" in the room.

The researchers had a different purpose. "We used them to gauge whether the network administrators had discovered our attacks," the researchers said.

"When they did, their body language became noticeably more agitated."

The University said it took election officials about 36 hours to notice the attacks. The tip-off appeared to come from posts to a mailing list joking about the calling card video.

Researchers said that while election officials deserved praise for opening their system to public tests, the successful attack highlighted the challenges in putting together a robust electronic voting system.

Add iTnews as your trusted source

Add iTnews As Your Trusted Source Add iTnews As Your Trusted Source
Got a news tip for our journalists? Share it with us anonymously here.
Copyright © iTnews.com.au . All rights reserved.
Tags:
researcherssecurityuniversity

Related Articles

  • Apple bumps up security in fresh operating system releases Apple bumps up security in fresh operating system releases
  • Meta accuses NSO Group of violating court order by WhatsApp spear phishing Meta accuses NSO Group of violating court order by WhatsApp spear phishing
  • Researchers build self-replicating AI worm with BYO LLM Researchers build self-replicating AI worm with BYO LLM
  • Anthropic opens Claude Mythos Preview AI program to Australia Anthropic opens Claude Mythos Preview AI program to Australia
Join our WhatsApp Channel

Partner Content

Agile isn’t the problem: why projects still fail, and what’s missing
Partner Content Agile isn’t the problem: why projects still fail, and what’s missing
Thomas Peer Solutions unveils data cloud platform and executive leadership forum for 2026
Partner Content Thomas Peer Solutions unveils data cloud platform and executive leadership forum for 2026
Why resilient communications are becoming critical infrastructure for modern enterprise IT
Promoted Content Why resilient communications are becoming critical infrastructure for modern enterprise IT
The hidden economics of AI: Why token usage matters more than you think
Partner Content The hidden economics of AI: Why token usage matters more than you think

Sponsored Whitepapers

Agile in the AI Era: why projects still fail
Agile in the AI Era: why projects still fail
When Technology Becomes the Blocker: Unlocking Real Outcomes from AI and Cloud
When Technology Becomes the Blocker: Unlocking Real Outcomes from AI and Cloud
High-volume data sources for AI-driven security analytics
High-volume data sources for AI-driven security analytics
How healthcare organisations can get more value from cloud
How healthcare organisations can get more value from cloud
1 in 3 companies lose SaaS data. Here’s how to prevent it
1 in 3 companies lose SaaS data. Here’s how to prevent it

Events

  • iTnews State of Security Breakfast iTnews State of Security Breakfast
  • iTnews State of Data & AI Breakfast iTnews State of Data & AI Breakfast
  • The 2026 iAwards The 2026 iAwards
  • Integrate 2026 Integrate 2026
  • Security Exhibition & Conference Security Exhibition & Conference
Share on Facebook Share on LinkedIn Share on Whatsapp Email A Friend

Most Read Articles

Anthropic opens Claude Mythos Preview AI program to Australia

Anthropic opens Claude Mythos Preview AI program to Australia

Defence says Palantir is "sandboxed" in its environment

Defence says Palantir is "sandboxed" in its environment

Services Australia describes fraud, debt-related machine learning use cases

Services Australia describes fraud, debt-related machine learning use cases

Microsoft backs down on legal threats against 0day disclosing researchers

Microsoft backs down on legal threats against 0day disclosing researchers

techpartner.news logo
Sydney-based AI-cloud waste startup raises $3m
Sydney-based AI-cloud waste startup raises $3m
Brennan uses NiCE to modernise its contact centre
Brennan uses NiCE to modernise its contact centre
Impact Awards: Tecala slashes customer response times for fintech IQumulate
Impact Awards: Tecala slashes customer response times for fintech IQumulate
Interactive introduces private cloud platform
Interactive introduces private cloud platform
Digital61 expands cybersecurity portfolio
Digital61 expands cybersecurity portfolio
All rights reserved. This material may not be published, broadcast, rewritten or redistributed in any form without prior authorisation.
Your use of this website constitutes acceptance of nextmedia's Privacy Policy and Terms & Conditions.