Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | [ISN] How a guy's gizmo spread fear at Fed |
|---|---|
| Date: | Mon, 15 Nov 2004 04:47:54 -0600 (CST) |
Forwarded from: William Knowles <wk@c4i.org> http://www.nydailynews.com/front/story/251774p-215484c.html BY THOMAS ZAMBITO DAILY NEWS STAFF WRITER November 11, 2004 It nearly sparked a financial catastrophe. An electrician's homemade gadget wreaked havoc on the Federal Reserve Bank of New York, causing computer convulsions at a facility that houses the world's biggest cash vault, the Daily News has learned. The foulup short-circuited the career of journeyman electrician John Cravetts, who was fired though he insists he meant no harm. But it could have been much worse, according to papers filed in Manhattan Federal Court. "The results could have been catastrophic," said Barry Schindler, an attorney for the New York Fed. Fed officials say they might have had to shut down computers that process some $2.5 trillion in funds and securities payments and $4 billion in checks every day. Fortunately, backup systems kicked in after the Nov. 17, 2002, incident. The heavily guarded facility in East Rutherford, N.J., is also home to a vault that handles more than $1 billion in currency, coins and food coupons. Cravetts, 62, was canned two weeks after the incident. A surveillance tape caught him using the crude device - two red wires strung between an ordinary household switch and plug. He later filed an age discrimination suit and also charged his firing was retaliation for reporting an electrocution hazard at the facility where he'd worked for almost 10 years. Manhattan Federal judge Harold Baer tossed out Cravetts' claim this week. "I had an unblemished record," Cravetts told The News yesterday. "What I did was in good faith. I did not do anything malicious," added the licensed electrician, who has since found a new job. "What do they think I'm going to do, sabotage it?" Although Fed attorneys presented a near-doomsday scenario in court filings, Fed spokesman Peter Bakstansky downplayed the incident yesterday. "There was no point at which the operations of the Fed were in danger," Bakstansky said. "We stopped him. ... We have a lot of redundancy." Cravetts had been asked to locate circuit breakers on the Fed computers that had not been properly labeled. He used his gizmo to conduct the search, plugging it in and tripping breakers, knocking out power as he went along. Cravetts told The News his superiors knew he used the device. He had made four of them at work. Fed attorneys say he should have used a device that sends a harmless tone back to the breaker and doesn't cause disruptions. Cravetts said that for more than a year, he had asked his bosses to order the manufactured device needed for the job, but they never did. *==============================================================* "Communications without intelligence is noise; Intelligence without communications is irrelevant." Gen Alfred. M. Gray, USMC ---------------------------------------------------------------- C4I.org - Computer Security, & Intelligence - http://www.c4i.org *==============================================================* _________________________________________ Open Source Vulnerability Database (OSVDB) Everything is Vulnerable - http://www.osvdb.org/
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | [ISN] NSA honors security efforts, InfoSec News |
|---|---|
| Next by Date: | [ISN] Japanese Government Bans Security Researcher's Speech, InfoSec News |
| Previous by Thread: | [ISN] NSA honors security efforts, InfoSec News |
| Next by Thread: | [ISN] Japanese Government Bans Security Researcher's Speech, InfoSec News |
| Indexes: | [Date] [Thread] [Top] [All Lists] |