Committee of the Whole Meeting - A. MAX BACON CITY HALL, HR TRAINING ROOM — Minutes
Open official source ↗ · Source page 2
February 27, 2025 6:00 PM City of Smyrna Mayor and Council Meeting 2800 King Street SE Human Resources Training Room Page 2 of 10 • Operational Disruption: Ransomware, loss of data integrity or availability, or other threats that stop service delivery or back office functionality • Regulatory and Compliance: Impact to compliance status, Service Level Agreements (SLA), interconnection agreements, regulatory fines, litigation, or law enforcement matters • Information Disclosure: Loss of Intellectual Property (IP), City of Smyrna operational information, personnel, customer, financial, or other sensitive information Penetration Testing Process What is penetration testing? • Enumeration and Vulnerability Scanning of Internet-facing and internal networks • Network attacks to capture credentials, data, or configurations as they cross the network • Targeted hacking attempts against applications and services • Post-compromise credential harvesting, privilege elevation to Domain Admin • Documentation of findings into Penetration Test Report Penetration Test Results • Library Software Programmatic Flaws – The Library Corporation (TLC) software noted to expose API and user credentials to internet due to lack of security in programming • Overall Strong Encryption in Use – Other internet exposed services for administration and monitoring are noted to have strong SSL/TLS configurations and be free of exploitable flaws • Security Defaults Compromise Devices – Weak or default passwords, SNMP configurations, telnet, FTP, or other insecure services present resulted in compromise of non-PC devices like printers, UPS devices, HVAC controller • Insecure Configurations Compromise Active Directory – Credential theft from unsigned SMB traffic, extraction from a printer, improper certificate issuance result in 3 administrative compromises of the Smyrna local domain Notable Exploitation • HELO Plus AJA Video System – An audio-video conferencing system compromised, allowing an attacker to monitor or change video content displayed by the system • Data Center Uninterruptible Power Supply – A battery backup system used to maintain power in the City Data Center was compromised, allowing as attacker to shutdown power or change configurations • TLC Library Database – The TLC data was compromised, allowing an attacker the ability to login as any user, update PIN values, and extract PII from the application • Police Station Uninterruptible Power Supply – A battery backup system used to maintain power in the City Police Department was compromised, allowing an attacker to shutdown power or change configurations • Weak User Passwords – 103 unique user accounts were observed to have weak passwords decrypted through brute force password attacks • Usage of Netwrix Account to Compromise Active Directory – A harvested Credential for a network software tool is used to compromise Active Directory for the Smyrna.local domain Improvement Recommendations • Security Hardening – Configuration of security controls pre-production