Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Security > Hacking News

January 30th, 2009, 09:18 GMT · By

Rogue IT Admin Close to Shutting Down Mortgage Giant

SHARE:

Adjust text size:


Former IT admin planned to halt operations at Fannie Mae
Enlarge picture
A former IT admin, who used to work for Fannie Mae at their Urbana Technology Center in Maryland, has been indicted by a grand jury for planting a malicious script to destroy data on all of the company's servers. The computer time bomb was designed to go off on the 31st of January, 2009 at 9:00 am.

The Federal National Mortgage Association, also known as Fannie Mae, is a financial enterprise sponsored by the government, and founded during the Great Depression in 1938. Given its main activities of buying and guaranteeing mortgages, the company is particularly vital in these difficult times of world crisis.

According to the indictment, Rajendrasinh Babubhai Makwana, 35, who is an Indian citizen, worked for three years as a computer engineer at Fannie Mae, until October 24, 2008, when his contract was terminated. During this time Makwana had root access to all of the main systems, credentials which the company failed to revoke until the evening of the day of his layoff.

Finding out that he was being let go, the software engineer, in a true BOFH style taken to extreme, came up with a viciously evil plan to bring all the operations of the enterprise down. His intention was nothing short of replacing the entire financial data, including the backups, from all of the company's production servers, with zeroes.

Profiting from the fact that his credentials were not yet revoked, the admin appended malicious code to a legitimate script, leaving a page-worth of blank lines between the two in order to avoid detection. This code was to be executed three months later, making it more difficult for the investigators to trace the incident back to him.

"When the program ascertained it was January 31, 2009, it would copy the rest of the files from the '.soti' file from the dsysadm01 server and run the .y.sh script. The .y.sh script would place a blocker on the monitoring system disabling any engineers from receiving a monitoring alert for any problems on any machines in the entire environment for 61 minutes," FBI Agent Jessica Nye, explained in a sworn statement.

The script was set to greet the administrators trying to log in with a message that read "Server Graveyard," which might have really been the case if another senior engineer hadn't discovered the code a few days after Makwana was fired. “Had this malicious script executed, engineers expect it would have caused millions of dollars of damage and reduced if not shutdown operations at Fannie Mae for at least one week. The total damage would include cleaning out and restoring all 4,000 servers, restoring and securing the automation of mortgages, and restoring all data that was erased,” said the FBI agent.

The investigators were able to determine that Makwana was responsible, because the script upload was made from the IP assigned to his company-issued laptop. In addition, a message sent from his Fannie Mae e-mail address to his family, who were in India at the time, instructed them not to return to the U.S. The rogue administrator, who was living in Glen Allen, Virginia, has been arrested on January 7 and is facing a maximum sentence of 10 years behind bars.

“Obviously this case is ongoing, and charges have not been proven against Makwana. But imagine what the impact could have been if an attack like this were not intercepted, and had successfully struck a financial institution. With economies so rocky at the moment anyway and confidence in the financial system amongst the general public badly shaken in recent months, it would be very bad news indeed for any institution to be hit in this way,” commented Graham Cluley, senior technology consultant for Sophos.

Given the current sensitive financial situation around the world, a lot of people are bound to lose their jobs, while many already have. Companies have to be more vigilant than ever when it comes to revoking the accounts of ex-employees, otherwise they might face serious data breaches or system downtimes. Former workers have wrecked havoc on the networks of their past employers many times before, but now more of them might be tempted to do it, being angered because they are left without a job in such difficult times, with few prospects of new employment.

TELL US WHAT YOU THINK:

5,007 hits · 2 comments · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Potentially Racist SMS Sent to Thousands of Students

Former State Department Employee Admits Snooping Private Records

Terminated Employee Hacks His Way Back In

Former Network Admin Turns Full-Time Criminal

Disgruntled Ex-Employee Turns Company Server into Spam Relay

READER COMMENTS:


Comment #1 by: hackerIwas on 06 Oct 2009, 22:08 UTC reply to this comment

Wow, well, sometimes it takes that to let a client know that you were not treated well, especially if they think that any punk kid can take care of their network mess. I have retaliated in the past and I was NOT caught. It takes a little planning, and you have to see the writing on the wall first. Let's just say that I am good at creating back doors and having spare keys.
If you think about it carefully, NO SYSTEM is TOTALLY secure. Especially if the keymaster is the Administrator.


Comment #2 by: elaxi on 02 Dec 2009, 10:06 UTC reply to this comment

i am the younger sister of rajendra.my brother is innocent.some body is trying to entrap rajendra in a big conspiracy.what he will get by doing all this rubbish.he has his family he has 2 little kids and old parents and he is the only son of his parents.rajendra is very trustful ,sincere and honest person.i am proud that he is my brother,and my brother cant do any shameless offence like entering any malicious script to destroy data of Fannie Mae for which he was working since from last 3 years.what he will get by doing this ? Better FBI should go to the right way to search a original offender and do inquiry of all the employee those who were working that day on the server as rajendre was not the only person who was woking on server.and as my brother didnot work on last day as it was his last day so he spend his time to meet his employee staff and other people.i think somebody is playing with my brother and framing a big conspiracy on name of rajendra.god is always with rajendra.dont worry rajendra every thing will be ok and a real person who has done all this offence and mischief with you will come out soon he cant hide himself from the eye of god. god bless u.

Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM