GovernSmyrna.

Committee of the Whole Meeting - A. MAX BACON CITY HALL, HR TRAINING ROOM — Minutes

Open official source ↗ · Source page 2

SHA-256 bb19a7fe96358194ef3cd947daa25a6ff5a47931cc637e054475ab6c68e87dfd · Captured source extract

 
February 27, 2025 
6:00 PM 
 
City of Smyrna 
Mayor and Council Meeting 
2800 King Street SE 
Human Resources Training Room 
 
Page 2 of 10 
 
• Operational Disruption: Ransomware, loss of data integrity or availability, or 
other threats that stop service delivery or back office functionality 
• Regulatory and Compliance: Impact to compliance status, Service Level 
Agreements (SLA), interconnection agreements, regulatory fines, litigation, or law 
enforcement matters 
• Information Disclosure: Loss of Intellectual Property (IP), City of Smyrna 
operational information, personnel, customer, financial, or other sensitive 
information 
 
Penetration Testing Process 
What is penetration testing?  
• Enumeration and Vulnerability Scanning of Internet-facing and internal networks 
• Network attacks to capture credentials, data, or configurations as they cross the 
network 
• Targeted hacking attempts against applications and services 
• Post-compromise credential harvesting, privilege elevation to Domain Admin 
• Documentation of findings into Penetration Test Report 
 
Penetration Test Results  
• Library Software Programmatic Flaws – The Library Corporation (TLC) software 
noted to expose API and user credentials to internet due to lack of security in 
programming 
• Overall Strong Encryption in Use – Other internet exposed services for 
administration and monitoring are noted to have strong SSL/TLS configurations 
and be free of exploitable flaws 
• Security Defaults Compromise Devices – Weak or default passwords, SNMP 
configurations, telnet, FTP, or other insecure services present resulted in 
compromise of non-PC devices like printers, UPS devices, HVAC controller 
• Insecure Configurations Compromise Active Directory – Credential theft from 
unsigned SMB traffic, extraction from a printer, improper certificate issuance result 
in 3 administrative compromises of the Smyrna local domain 
 
Notable Exploitation  
• HELO Plus AJA Video System – An audio-video conferencing system 
compromised, allowing an attacker to monitor or change video content displayed 
by the system 
• Data Center Uninterruptible Power Supply – A battery backup system used to 
maintain power in the City Data Center was compromised, allowing as attacker to 
shutdown power or change configurations 
• TLC Library Database – The TLC data was compromised, allowing an attacker 
the ability to login as any user, update PIN values, and extract PII from the 
application 
• Police Station Uninterruptible Power Supply – A battery backup system used to 
maintain power in the City Police Department was compromised, allowing an 
attacker to shutdown power or change configurations 
• Weak User Passwords – 103 unique user accounts were observed to have weak 
passwords decrypted through brute force password attacks 
• Usage of Netwrix Account to Compromise Active Directory – A harvested 
Credential for a network software tool is used to compromise Active Directory for 
the Smyrna.local domain 
 
Improvement Recommendations  
• Security Hardening – Configuration of security controls pre-production