Live data from Hacker News

Fannie Mae Unix Engineer Gets 41 Months for Planting Logic Bomb

thenewnewinternet.com

1–10 of 54 posts

Re: Fannie Mae Unix Engineer Gets 41 Months for Planting Logic Bomb

#6
post #4

"the malware was designed to spread throughout the Fannie Mae network of computers and destroy all data, including financial, securities and mortgage information" Not really malware though, that sounds like a good thing.

"the malware was designed to spread throughout the Fannie Mae network of computers and destroy all data, including financial, securities and mortgage information"

Sounds like a prototype for the toxic mortgage derivatives spreading throughout the banking system.

Re: Fannie Mae Unix Engineer Gets 41 Months for Planting Logic Bomb

#7
5000 Servers. A "Senior Engineer" discovered this script. Probably it was a cron job or something which they review regularly?

Would be useful to know how exactly they got to that one script. Must have real good review practices , audits and logging in place if they were able to find it before it did the damage and then collect evidence to trace it back to the perpetrator.

Re: Fannie Mae Unix Engineer Gets 41 Months for Planting Logic Bomb

#8
Does anyone know what the actual "logic bomb" consisted of?

My money is on a crontab that executed a simple set of ssh command attacks on the specified date.

As per the article, to destroy "all data, including financial, securities and mortgage information," it would be as simple as an "rm -rf" across multiple servers. Except for one critical item, he would have to have root access on all those servers.

Either the scope of his potential damage was very small, or Fannie Mae had some terrible security and change management policies in place.

I cannot decide which to pick.

Post reply on HN