Risk
10/7/2010
12:19 PM
50%
50%

Fannie Mae Insider Convicted For Planting Malware

Former Unix engineer inserted malicious script designed to destroy data at the financial services firm, finds federal jury.




Slideshow: Cloud Security Pros And Cons
(click for larger image and for full photo gallery)
The Federal Bureau of Investigation on Monday said that a federal jury has convicted Rajendrasinh Babubhai Makwana, a Maryland computer programmer, with "computer intrusion arising from the transmission of malicious script to Fannie Mae's computer servers." He faces a maximum prison sentence of 10 years.

According to the FBI, Makwana worked as a contract Unix engineer for Fanny Mae -- aka the Federal National Mortgage Association, a federally chartered corporation that purchases mortgages -- for three years, and had access to the organization's network of almost 5,000 servers.

Trial testimony detailed how Makwana was fired on October 24, 2008, and ordered to return all Fannie Mae-issued IT equipment, including his laptop. Five days later, however, "a Fannie Mae senior engineer discovered a malicious script embedded in a routine program," said the FBI.

"A subsequent analysis of the script, computer logs, Makwana's laptop, and other evidence revealed that Makwana had transmitted the malicious code on October 24, 2008, which was intended to execute on January 31, 2009," said the FBI. "The malicious code was designed to propagate throughout the Fannie Mae network of computers and destroy all data, including financial, securities, and mortgage information."

On that day, upon trying to log in to the Fannie Mae network, users would have received a message saying only "server graveyard."

The attack is a reminder of the danger of insider attacks, and highlights how, even though the erased data would likely have been restored, the incident would still have disrupted the organization's operations.

"Even though it would be likely that the firm would have off-site backups that would not have been hit by the malware attack, it would still have been enormously disruptive for the company, at a time when confidence in the financial industry was quite rocky anyway," said Graham Cluley, senior technology consultant at Sophos. "Indeed, the court heard evidence that it would take a week for the company to get its systems back up and running again."

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading Tech Digest, Dec. 19, 2014
Software-defined networking can be a net plus for security. The key: Work with the network team to implement gradually, test as you go, and take the opportunity to overhaul your security strategy.
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2011-1793
Published: 2014-12-25
rendering/svg/RenderSVGResourceFilter.cpp in WebCore in WebKit in Google Chrome before 11.0.696.65 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted SVG document that leads to a "stale pointer."

CVE-2011-1794
Published: 2014-12-25
Integer overflow in the FilterEffect::copyImageBytes function in platform/graphics/filters/FilterEffect.cpp in the SVG filter implementation in WebCore in WebKit in Google Chrome before 11.0.696.65 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified ...

CVE-2011-1795
Published: 2014-12-25
Integer underflow in the HTMLFormElement::removeFormElement function in html/HTMLFormElement.cpp in WebCore in WebKit in Google Chrome before 11.0.696.65 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted HTML document con...

CVE-2011-1796
Published: 2014-12-25
Use-after-free vulnerability in the FrameView::calculateScrollbarModesForLayout function in page/FrameView.cpp in WebCore in WebKit in Google Chrome before 11.0.696.65 allows remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via crafted JavaS...

CVE-2011-1798
Published: 2014-12-25
rendering/svg/RenderSVGText.cpp in WebCore in WebKit in Google Chrome before 11.0.696.65 does not properly perform a cast of an unspecified variable during an attempt to handle a block child, which allows remote attackers to cause a denial of service (application crash) or possibly have unknown othe...

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Join us Wednesday, Dec. 17 at 1 p.m. Eastern Time to hear what employers are really looking for in a chief information security officer -- it may not be what you think.