r/ShittySysadmin ShittyMod Crossposter 12d ago

Shitty Crosspost T-Mobile found a Chinese hacker inside its network. So its security team drove to a data center and literally cut the cable.

Post image
313 Upvotes

39 comments sorted by

141

u/ITRabbit ShittyMod Crossposter 12d ago

I mean they come with clips to disconnect? But also I guess if 1 cable takes their network offline not much backup/redundancy

64

u/ApprehensiveRest9696 11d ago

Probably behind an rj45 lock / secured rack and it’s just quicker to cut than fiddle

17

u/Jeff-IT 11d ago

Why not just disable the port?

27

u/ScreamingVoid14 11d ago

Quicker to cut the cable than VPN into the right management network, SSH into the switch, etc.

Also, cutting sends the universal "this was done for a reason" signal that just unplugging or sending a port down command wouldn't.

11

u/Salt_Ice_5321 11d ago

conf t

int fa0/16

shutdown

description CHINESE HACKERS, DO NOT TURN ON

do wr me

7

u/ForSquirel ShittyCoworkers 11d ago

Jokes on you, they're using netgear.

5

u/Ghostfriendd 11d ago

Jokes on him he didnt even write it in gig, still using fa smh

1

u/ForSquirel ShittyCoworkers 11d ago

Rookie mistake or what a double crosser would want you think

2

u/Jeff-IT 11d ago

I hate I understand this reference

14

u/Jeff-IT 11d ago

Idk much of their workflow and process, But I disagree. Physically going down (likely even remote employee had to go somewhere?) to find and cut the cable had to take longer than turning off the port. Even if it you had to get on a VPN.

Got to be something more to it than that

Edit: unless they were just already down there then I guess so yeah. But the post said they drove there

8

u/ApprehensiveRest9696 11d ago

Other comments in OOP suggested that it was standard practice to prevent another person plugging it back in.

3

u/Jeff-IT 10d ago

Huh interesting

7

u/krysisalcs Suggests the "Right Thing" to do. 11d ago

Makes sense if the cage was locked

27

u/[deleted] 11d ago edited 1d ago

[deleted]

5

u/northSideways 11d ago

But the haxor was already "inside the network"!!

1

u/Adventurous-Dingo720 10d ago

The ultimate firewall

38

u/dont_ama_73 11d ago

This is a fake story. It says Tmo sent 4 cybersecurity/IT people. Tmo in no way has that many IT people on staff

30

u/Main_Enthusiasm_7534 12d ago

Manual firewall.

15

u/CGCTV 12d ago

Manuel Firewall at your service!

71

u/themastermatt 12d ago

Sounds like something the outsourced MSP's AI coach told them to tell smarthands at the colo to do. Shutting down a port is hard.
I once had an outsourced service desk tell an end user in a 30k user org to go to Walmart and buy a wireless router to plug in at their hospital to get coverage in a dead spot.

17

u/Oompa_Loompa_SpecOps DO NOT GIVE THIS PERSON ADVICE 11d ago

Is this some elaborate meta joke because over here T-Mobile and it's sibling companies have a reputation for being great at hiring and retaining the nation's shitty sysadmins.

30

u/0xdeadbeef6 12d ago

Must of worked for NCIS previously.

17

u/Simple_Car8699 12d ago

Somewhere, an incident-response checklist just gained a new step: locate the data center, bring wire cutters, secure the evidence.

5

u/Intrepid_Ring4239 11d ago

Unplugging it also works.

1

u/Id10t_techsupport 5d ago

Unplugging what?

5

u/tonyboy101 11d ago

They did the needful

6

u/Sqooky 11d ago

because it's easier to find a pair of scissors in the data center than it is to do an en, conf t, int ge0/1/38, shut remotely.

3

u/wowsomuchempty 11d ago

This would go nicely with the 'sculpture' of the printer and the fire axe.

3

u/haZhat 11d ago

They really are slacking with their standard procedures. If we find a Chinese hacker we have to molotov the servers and bury the resultant ash under 10 metres of concrete.

1

u/Forsaken-Carrot9038 11d ago

You probably don’t even wait to get it out of the server room, gotta watch out those Chinese viruses are contagious!

7

u/Maleficent-Pop1031 11d ago

The “vigilant by design” slogan paired with a literal severed Ethernet cable is peak corporate security theater—and honestly, pretty effective messaging.

3

u/Forsaken-Carrot9038 11d ago

That’s my thought exactly. They probably remotely shut everything down, disabled ports, etc., and while they were there, one of the guys thought it would be cool so they sniffed the cable to bring back as “evidence“.
I can’t imagine a scenario in a collocated environment or anything that is properly managed to where you’d have access to just simply cut a cable.

5

u/Aristo_Cat 11d ago

You’re responding to a bot you walnut

1

u/Acme351 8d ago

Dont knock it, did work for a small elementary school that was worried after a porn filter failed (DNS filter back in the 2000's and it took me more than 5 minutes to login and fix. bought a red patch for the cord from the firewall to the network switch. Showed the 2 people I answered to and explained that if they felt the need to disconnect from the internet to unplug the red wire. never had problem again but the one let me know that she felt better knowing they could shut off the internet if they had to.

0

u/havpac2 11d ago

Hrmm was the cable fuzed? Couldn’t push the tab to pull the cable normally, just straight to cut the cable?

I have cut cables before when replacing an old switch and their patch cables but for a security event.

Sooo dramatic.

Anyways I’m switching to Verizon. T-Mobile has becomes super expensive for my family’s limited usage
Three lines and a smartwatch should cost us 200 a month with a total data usage of like 10gb accross three devices.

-21

u/Grumpy-Man19 12d ago

it's funny how it's always some country we are told to hate