top o' the mornin'®
- earendel
- Posts: 13857
- Joined: Tue Oct 09, 2007 5:25 am
- Location: mired in the bureaucracy
top o' the mornin'®
An unusual start to the morning - I got off the elevator and headed for my office, only to find someone standing outside waiting to get in (I'm usually the first to arrive). It was our network administrator and he looked troubled. As I opened the door he asked me if I knew which employee used a computer with a particular barcode number. I logged onto my computer and checked my inventory and found it. While doing so I asked him why. He said that last night he had received an alert that that computer was "performing suspicious activity", by which, he said, was meant that it was either accessing or being accessed without anyone present, possible signs of a worm or virus. This automatically triggers a protocol for handling an potential intrusion. He had to take the computer off the network, and eventually a team will come get the CPU and run a series of diagnostics on it to find out what was causing the "suspicious activity". The network administrator said it could take from several hours to several days to deal with the problem, and that the user would probably lose at least some, if not all, of the data stored on the computer. Needless to say when the user arrived she was not happy at all. By then the network administrator had left, so I was the target of her confusion and anger. She is NOT a happy camper.
"Elen sila lumenn omentielvo...A star shines on the hour of our meeting."
- MarleysGh0st
- Posts: 27966
- Joined: Mon Oct 08, 2007 10:55 am
- Location: Elsewhere
Re: top o' the mornin'®
Understandably, but it's good to know the protocol for detecting and stopping this activity is working!earendel wrote: She is NOT a happy camper.
Let us know what the results of the scan is, if that information's not classified.
- ulysses5019
- Purveyor of Avatars
- Posts: 19442
- Joined: Mon Oct 08, 2007 10:52 am
- Location: Los Angeles, CA
- peacock2121
- Posts: 18451
- Joined: Mon Oct 08, 2007 10:58 am
- PlacentiaSoccerMom
- Posts: 8134
- Joined: Mon Oct 08, 2007 10:47 am
- Location: Placentia, CA
- Contact:
- MarleysGh0st
- Posts: 27966
- Joined: Mon Oct 08, 2007 10:55 am
- Location: Elsewhere
- MarleysGh0st
- Posts: 27966
- Joined: Mon Oct 08, 2007 10:55 am
- Location: Elsewhere
The more likely concern would be that her PC has become infected with a trojan. That might be trying to steal government secrets from her computer or just trying to turn it into your run-of-the-mill spambot zombie.PlacentiaSoccerMom wrote:Do you think that she is a spy?
Either way, that's a big no-no!
- earendel
- Posts: 13857
- Joined: Tue Oct 09, 2007 5:25 am
- Location: mired in the bureaucracy
Most likely the latter - we don't deal in government secrets in this office, although I suppose it might be possible to get to the Pentagon through the .army.mil domain that we use. What's more of a mystery is how it happened in the first place, since all of our computers are supposed to be protected with anti-spyware software, as are the servers. Heck, most of the time I can't even get a Word document sent to me because the e-mail filters catch and quarantine them as "suspicious".MarleysGh0st wrote:The more likely concern would be that her PC has become infected with a trojan. That might be trying to steal government secrets from her computer or just trying to turn it into your run-of-the-mill spambot zombie.PlacentiaSoccerMom wrote:Do you think that she is a spy?
Either way, that's a big no-no!
"Elen sila lumenn omentielvo...A star shines on the hour of our meeting."
- ulysses5019
- Purveyor of Avatars
- Posts: 19442
- Joined: Mon Oct 08, 2007 10:52 am
- Location: Los Angeles, CA
- MarleysGh0st
- Posts: 27966
- Joined: Mon Oct 08, 2007 10:55 am
- Location: Elsewhere
- gsabc
- Posts: 6489
- Joined: Tue Oct 09, 2007 8:03 am
- Location: Federal Bureaucracy City
- Contact:
- ulysses5019
- Purveyor of Avatars
- Posts: 19442
- Joined: Mon Oct 08, 2007 10:52 am
- Location: Los Angeles, CA
- earendel
- Posts: 13857
- Joined: Tue Oct 09, 2007 5:25 am
- Location: mired in the bureaucracy
Re: top o' the mornin'®
The network administrator just stopped by my cubicle to give me an update. After an exhaustive series of diagnostics, it was discovered that the user's computer had a trojan on it, as well as two infected files, which were traced back to a Web site (he didn't indicate what site that was). Whatever the site was, it was also visited by a computer in one of our field offices. Chances are it was an innocent site with some malicious add-on probably unknown to the site's operator. It must have been a fairly sophisticated trojan to get past the anti-virus software we have installed; it's updated on a regular basis.MarleysGh0st wrote:Understandably, but it's good to know the protocol for detecting and stopping this activity is working!earendel wrote: She is NOT a happy camper.
Let us know what the results of the scan is, if that information's not classified.
"Elen sila lumenn omentielvo...A star shines on the hour of our meeting."
- MarleysGh0st
- Posts: 27966
- Joined: Mon Oct 08, 2007 10:55 am
- Location: Elsewhere