From pen-test to penitentiary: Infosec duo cuffed after physically breaking into courthouse during IT security assessment
Two men hired to assess a court record system's computer security were arrested Wednesday – after they were caught physically sneaking into a courthouse.
According to the Des Moines Register today, the duo were cuffed by deputies in Iowa, USA, after they tripped an intruder alarm at a Dallas County courthouse.
The two men, who now face burglary charges, said they were attempting the break-in as part of a penetration test the county court had paid their employer, security biz Coalfire, to perform against the court's electronic records system.
In other words, the ethical hacker duo were pen-testers just trying to get physical access to computers managing or storing court records as part of a planned security probe.
Here's where things jump the tracks. The Dallas County court officials fully acknowledged they hired the two experts to test the security of their IT system. The bureaucrats were, however, unaware the tests could also involve physical break-ins, it is claimed.
"The two men arrested work for a company hired by [the state court administration, or SCA] to test the security of the court’s electronic records," Iowa's judicial branch said in a statement on the matter.
"The company was asked to attempt unauthorized access to court records through various means to learn of any potential vulnerabilities. SCA did not intend, or anticipate, those efforts to include the forced entry into a building."
Those familiar with pen-testing procedures were quick to point out just what a colossal failure had to occur to create these sort of circumstances.
Industry: Cyber Security
- Contract (outside) Cyber Incident manager – current SC clearance ESSENTIAL
- United Kingdom
Contract (outside) Cyber Incident manager – current SC clearance ESSENTIAL Outside IR35 Client facing (Remote UK) with occasional site visit. Must have current Cyber incident response / management experience. Both proactive planning, escalation, coordination and coordinating response. Stakeholder engagement both technical and non technical teams. Prior experience with Technical incident / digital forensics / crisis management. Immediate role.
- Tenable Vulnerability Analyst - CONTRACT outside IR35. SC cleared.
- United Kingdom
6 month rolling contract Outside IR35- immediate start. Threat and Vulnerability Analyst. Tenable.sc experience needed. The ability to deploy agent, configure environments, run active and passive scans, produce reports and prioritise remediation activities based on output Current and ACTIVE SC clearance is required
- ForgeRock Consultant
- £600 per day
ForgeRock Consultant required for 6 Month Contract (with potential to extend) Outside IR35, Must be willing to work Europe hours (GMT+1) This is a remote position, Looking for a lead ForgeRock Technical Consultant with strong experience of ForgeRock to lead the next phase of deployment. Good understanding of ForgeRock Directory Services. · Responsible for the design and implementation of ForgeRock stack · Install and configure ForgeRock stack to meet customer authentication and authorization requirements, · Design and implement OAuth2 protocol using ForgeRock OpenAM, · Design and develop OpenAM custom authentication modules, · Configure ForgeRock stack to protect RESTful API, · Troubleshoot and support ForgeRock IAM stack. · Designed and developed Restful APIs, This is a great project with an expanding ForgeRock Partner, where you will get to work on some high level deployment projects We are looking for someone with the above experience, who is comfortable hitting the ground running and taking on the reins mid project
- Network Security Engineer
- €550 a day
German- based contract opportunity This is an onsite based position, we would need the Network Security engineer to be able to work on the client site 5 days a week Seeking an experienced Network Security Engineer for a leading technology company. Strong expertise in firewall/IPS solutions, proxy solutions, and certificate management is required. Good hands-on experience in networking and web-related technologies necessary. Strong problem-solving skills and the ability to work under pressure are essential. we are looking for a Network Security Engineer with the following experience: · Expertise in Administration, Management & Troubleshooting of Firewall / IPS solutions / Proxy solutions/Certificate Management Solutions · Good Hands-on Experience on security devices (PaloAlto/ /McAfee Proxy/CISCO ISE/Certificate Management) · Good Hands-on Experience in Networking with skills of switching, routing & wireless Technologies · Familiarity with web related technologies (Web applications, Web Services, Service Oriented Architectures) and of network/web related protocol · Configuration of NAT / PAT, firewall policies, profiling, objects, AD-Integration, backup – restore · Knowledge of Subnetting TCP/IP Communication, VLSM Configuration of VLAN VTP · Configuration of Routing Protocols e.g. RIPv1 & v2, OSPF, EIGRP, BGP Knowledge of standard and extended ACL 12 month contract