FBI probes hacking incident at Indiana clinic
Database changes made by intruder slowed system
February 10, 2006 12:00 PM ETComputerworld -
A Fort Wayne, Ind.-based orthopedics clinic with more than a dozen facilities in the state has called in the FBI to investigate a hacking incident that highlights the dangers companies can face from the placement of hidden back doors in their software.
The case involves Orthopaedics Northeast, which last month suddenly began experiencing serious performance slowdowns with Webchart, a clinical document management system supplied to the clinic by Medical Informatics Engineering Inc., a health care software developer that's also based in Fort Wayne.
MIE, which no longer supports the clinic's Webchart installation, last week confirmed that it is part of the FBI's investigation. But it denied that it was involved in the hacking activities at the clinic, which is known informally as ONE.
The performance problems, which on one occasion caused the Webchart software to become totally inaccessible for several days, were eventually traced to deliberate changes made in the system's underlying MySQL database, according to Todd Plesko, CEO of triPractix LLC, a medical systems integrator that now manages the clinic's IT services.
The database changes were made by someone who illegally accessed the system nine times over a period of two weeks, initially via a back door using a hard-coded username and password, said Plesko, whose company is based in Fort Wayne as well.
Uncovering the intrusion led to the discovery of "a backdoor realm called MIE Private with a username of MIE that would completely bypass all of Webchart's front-end authentication," he explained.
Plesko said that in one instance, two 1's were appended to the end of a database query to make it crash. In another case, a print-server directory was deleted from the system.
Hospital Hack
The hacker subsequently appears to have used the backdoor access to set up or modify user accounts to also allow conventional access to Webchart, said Benjamin Kessler, a senior network consultant at Midwest Network Services Group LLC, a network infrastructure and security consulting firm in Fort Wayne that helped the clinic investigate the incident.
According to Kessler, an analysis of system and firewall logs showed that the person accessing the Webchart system came in via a proxy server at a local hospital. The systems at ONE were connected to the hospital's network via a virtual private network.
The hospital's logs showed that the proxy server had been accessed from a Windows Server 2003 system at another clinic, Kessler said. That system, in turn, appeared to have been accessed from within MIE's network, he added. Tracing the alleged route taken by the
Security
Additional Resources



Learn the important issues you must consider before starting your next mobility initiative. Get your mobility white paper from IDC now, compliments of Sybase.
White Papers & Webcasts
Share our Strength
Download Now
Lower the Cost and Complexity of a Mobile Workforce through Automation
Download This Resource Now!
Top 10 Things to Know about Data Protection
Download Now
Managing Mobility: Improve Data Security, Compliance and Manageability
Download This Resource Now!
Managing Secure File Transfer to Save Time, Money and IT Resources
Learn how companies are using innovative technology to overcome these challenges and improve user productivity by offloading e-mail attachments and replacing FTP with...
Ponemon Study: The Business Risk of a Lost Laptop
Download Now
Security Convergence Equals Network Security Cost Savings
Listen to IBM Internet Security Systems' take on network security convergence.
Airport Insecurity: The Case of Lost Laptops
Download Now
Disaster Recovery 2008: Reduced Costs and Improved Performance
How long can your Enterprise afford to be without your data? With an accelerated disaster recovery program, you never have to answer this...
