Cybersecurity is a multifaceted discipline that requires functional knowledge of different technologies and many different skills. This includes computer networking, hardware, software, operating systems, social engineering, policy development, financial risk, and much more. This section contains demonstrations of both technical skills and understanding of how cybersecurity impacts society in various ways.
Colonial Pipeline Ransomware Attack
Zachary Weaver
Professor Arif
CS462
1 August 2025
Colonial Pipeline Ransomware Attack:
In May of 2021, the Colonial Pipeline was attacked and shut down by a ransomware attack that had been provided by a gang known as DarkSide. This pipeline delivered nearly half of the East Coast’s fuel at the time of the attack. Darkside is known for utilizing an affiliate-based model that loans ransomware attacks and infrastructure to their criminal clientele. In return, they receive a portion of the ransoms collected by the client. After the Colonial Pipeline attack, DarkSide released public statements claiming they are “apolitical” and “their goal is to make money, not create problems for society.” They went on to promise to moderate their clientele by researching the target company of the ransomware attack prior to loaning the required software and infrastructure to their partners (Newman, 2021).
The idea that a group of malicious actors would actively police their criminal clients is absurd. It makes for a self-aggrandizing statement to endear DarkSide to the sections of society desperate for a Robin Hood-type vigilante to protect them and redistribute wealth. The reality is that their statement only thinly veils their own greed. A criminal enterprise policing other criminals prior to assisting them with a crime is futile. DarkSide’s clients could easily lie about their intended target, and it seems highly unlikely that DarkSide would punish their clients when ransoms are paid. There have even been reports that DarkSide affiliates have not received their share of the ransom (Dudley, 2021).
There is no genuine incentive for ransomware groups to be so discerning with their targets outside of public sentiment. Considering they are criminal organizations, they are unlikely to generate substantial goodwill. In fact, it is more likely that they issued such a statement to reduce governmental urgency to act. Such a high-profile attack, causing the issuance of emergency declarations in several states, is more likely to spur governments to action more quickly. This reduces the likelihood of DarkSide being able to operate without capture for an extended period of time. The more governmental resources assigned to track down groups like DarkSide, the more likely it is that they will be caught and dismantled.
Newman’s article goes on to explain that the Federal Government had been ramping up its efforts to address ransomware attacks in the weeks leading up to the Colonial Pipeline attack (Newman, 2021). Many would argue that this effort was far too late, considering that the attack could have been prevented or resolved more quickly if the government had acted more proactively. The article also elaborates on the White House’s response to the attack. Statements were given discussing intense investigation and calls on foreign governments, specifically Russia, to stop harboring cybercriminals (Newman, 2021). Perhaps, if the government had taken a proactive and preventative approach, this attack could have been averted altogether. Even in the present day, it seems that governments worldwide are failing to generate genuine urgency to combat the ever-changing cybersecurity landscape.
Governments are not the only entities attempting to combat cyberthreats. Private sector companies are also developing techniques to provide robust defenses against cybercriminals. However, in the case of the Colonial Pipeline attack, one company was too overzealous with their defenses. On January 11, 2021, the antivirus company Bitdefender announced a breakthrough discovery of a flaw in DarkSide’s ransomware attack (Dudley, 2021). They offered the ability to download a free tool designed to utilize this flaw to neutralize DarkSide attacks. This announcement and release of the countermeasure alerted DarkSide to their weakness.
This gave the criminal enterprise the ability to repair the flaw in their attack and make it even more formidable. Specifically, the discovery involved DarkSide reusing the same keys to lock and unlock their victims’ encrypted data. DarkSide even went so far as to publicly thank Bitdefender for alerting them to this design flaw (Dudley, 2021). To make matters worse, two other researchers, Fabian Wosar and Michael Gillespie, had discovered the attack’s flaw prior to Bitdefender making the discovery. These two researchers had been discreetly providing help to DarkSide victims to avoid alerting the attackers. If Bitdefender had followed the same thought process, the Colonial Pipeline attack could have been stopped immediately and severe damage avoided.
As a result of the attack, there were many negatively affected parties. Colonial Pipeline was forced to pay $4.4 million in Bitcoin to unlock its files. The shutdown of the pipeline also led to a rapid increase in gasoline prices, panic buying of gasoline by consumers, and the closing of thousands of gas stations (Dudley, 2021). Dudley and Golden’s article discusses the likelihood that even discreet distribution of ransomware countermeasures will ultimately end up alerting the attackers. This is because payments from victims will diminish over time, leading to a reevaluation by the attackers of their programming and the recognition and resolution of flaws. It cannot be stated conclusively how much longer DarkSide’s attack flaw would have remained a secret to them. However, the timing does seem to indicate that Colonial’s shutdown could have been avoided with discretion on Bitdefender’s behalf.
The way this attack was carried out was well thought out. The attackers were able to acquire an exposed VPN password from a Colonial Pipeline employee. The investigation revealed the likelihood that the user had used the same password for a different location that was compromised as part of a separate data breach. This is a key detail because many organizations have a policy of not reusing previous passwords. While it is possible to create password rules preventing this, it is nearly impossible to avoid reuse from a separate system. The success of this initial system penetration provides a textbook illustration of why password reuse is so dangerous. Once inside the system, DarkSide was able to steal 100 gigabytes of data within a two-hour window. Following the theft, DarkSide then infected Colonial Pipeline’s system with ransomware. This causes the encryption of many system and company files. This included billing and accounting (Kerner, 2022). As the encryption began to spread, Colonial was forced to shut down the pipeline to prevent it from spreading any further. This led to payment by Colonial for the encryption key, bringing a swift end to the crisis.
This attack also created a shortage of jet fuel. Because of rising fears over gas shortages, communities rushed to gas pumps as quickly as they could. They formed long lines and overpurchased beyond their typical needs. This surplus buying led to the feared shortage and accelerated its arrival. One of the most dangerous activities was to put gasoline in plastic bags (Kerner, 2022). An easily spilled container filled with highly flammable liquid was a recipe for disaster. There was some optimism in the aftermath of the attack.
The Department of Justice was able to find the digital address for the wallet used by the attackers. They were then able to get a court order to seize the bitcoin. They were able to recover sixty-four out of seventy-five bitcoins. This was the majority of the ransom, but still a large loss (Kerner, 2022). It was clear that this attack, which only lasted eight days, had caused massive damage that far exceeded the recovered sixty-four bitcoins. This attack made it clear that the United States was not ready to resolve major cyberattacks with any speed or decisiveness. These facts made it clear that the U.S. would have to upgrade its cyber-readiness significantly. In May 2021, the Biden Administration issued an executive order to direct government agencies to bolster their defenses as quickly as possible.
The Colonial Pipeline is a cautionary tale on several fronts. It starts with one of the simplest security measures: avoid password reuse. Then, it demonstrates the speed with which these attacks can take place. The data stolen acted as ransom insurance, as the system data in place was encrypted. The stolen data could be used as leverage if leaked publicly, while the encryption required the decryption key to be removed. If one vector was fixed, they still could ask for ransom, knowing solutions to both issues were unlikely. It demonstrated an almost naïve faith in a criminal organization to keep its word. The CEO of Colonial believed the decryption key would be returned if he complied quickly. While DarkSide proved him right in this instance, it was also likely that an attacker wouldn’t provide the key regardless of whether the ransom was met or not. Finally, it demonstrated how a single resource can quickly cripple large sections of the United States. This is an essential issue to recognize the gravity of. DarkSide’s attack did so much to demonstrate how effective severing a commercial artery can be at destabilizing a region. While it spurred action in the government to vastly improve cybersecurity, there is a lingering sentiment that we are still behind the curve. That is because cyberthreats grow more complex with every passing day, and the US was too slow to react in the beginning. This has put them squarely behind the curve, barring a massive surge in threat mitigation.
Companies and government agencies have a responsibility to place high priority and investment into more robust cybersecurity systems. It is a common sight to find headlines about yet another data breach in a major company. These companies are trusted with sensitive data of all kinds. Careless mistakes can lead to crippled critical systems and resources. Only through diligence and a tolerance for inconvenience can this cyberthreat begin to be adequately defended against. The more secure a system is, the more tedious it is to navigate. So, cybersecurity experts are tasked with finding the balance between security and convenience. This can lead to gray areas in security that may be too easily exploited. Hence, cyberspace is in a constant tug of war between malicious and defensive forces attempting to attack and defend the world’s most valuable asset, information.
References:
I will be using MLA9 citation format and parenthetical citation for my references.
Dudley, Renee, and Daniel Golden. “The Colonial Pipeline Ransomware Hackers Had a Secret Weapon: Self-Promoting Cybersecurity Firms.” Nextgov.Com, ProPublica, 10 July 2023, www.nextgov.com/cybersecurity/2021/05/colonial-pipeline-ransomware-hackers-had-secret-weapon-self-promoting-cybersecurity-firms/174253/.
Easterly, Jen. “The Attack on Colonial Pipeline: What We’ve Learned & What We’ve Done over the Past Two Years.” Cybersecurity and Infrastructure Security Agency, 23 Aug. 2024, www.cisa.gov/news-events/news/attack-colonial-pipeline-what-weve-learned-what-weve-done-over-past-two-years.
Kerner, Sean Michael. “Colonial Pipeline Hack Explained: Everything You Need to Know.” TechTarget, 26 Apr. 2022, www.techtarget.com/whatis/feature/Colonial-Pipeline-hack-explained-Everything-you-need-to-know.
Newman, Lily Hay. “Darkside Ransomware Hit Colonial Pipeline and Created an Unholy Mess.” Wired, 11 May 2021, www.wired.com/story/darkside-ransomware-colonial-pipeline-response/.
Ethernet Network Design Project
This project required me to research the necessary equipment to establish a Local Area Network for a multi-story school. Each section lists the necessary equipment with hyperlinks guiding you to the products I identified as being suitable for the parameters of the assignment.
Disclaimer: Prices as of Spring 2025. Prices may have changed when viewing this page at a later time.
For this project, I would need:
1 Router/Firewall to establish an ISP connection and provide network security.
Cost: $400
4 total managed switches, 1 for each telecommunications closet and the equipment room. These switches have 48 ports each, which will provide more than enough coverage for the number of rooms on each floor.
Cost: $400 per switch for a total of $1600.
8 patch panels with 24 ports each (2 per floor): These panels will be used to establish connections from the switches in the equipment room and the telecommunications closets to each room on each floor.
Cost: $40 per patch panel for a total of $320
Punch down tool for cabling:
Cost: $10
RJ45 Connectors (100 pack) x3: I would order a surplus of connectors to ensure I have enough for now and future needs.
Cost: $14 per 100 for a total of $42.
Cable crimper:
Cost: $50
Wire loom: 90 spools 50ft long each.
Cost: $24 per 50ft for a total of $2160.
15 ft Cat 6 Patch cables for individual room connections, 2 packs of 50 cables.
Cost: $133 for a pack of 50 for a total of $266.
Approximately 10km or 33,000 ft of Cat6 cable. I calculated this by subtracting the furthest connection of 98.17 m from the shortest connection of 11.32 m and taking the average distance between each room on each floor, with adjustments for the number of rooms per floor, and adding all of the distances together then doubling that to account for two cables per room. I also added a 10% buffer, allowing for cabling going between the equipment room and the telecoms closets and other potential cabling needs. This cable is rated for plenum space, such as ceilings.
Cost: $110 per 1000 ft of cable for a total of $3700 for Cat 6 cabling.
Wall plates for Cat 6 Ethernet connections: 74 plates, one for each room.
Cost: $8 per plate for a total of $592.
Equipment Rack Enclosures: One for each closet and the equipment room. The one I have selected allows for room to grow with the needs of the school.
Cost: $150 per rack for a total of $600.
1 Server to manage the network and establish different server needs for the school, including mail, DHCP, DNS, etc. This will also be used to manage the Software Defined Networking aspects of the router and managed switches by the system administrator.
Cost: $2800
Based on the equipment I have identified as necessary for this project, I have established a cost of approximately $12,500.
The assignment below demonstrates my understanding of Subnetting when establishing and managing an IT network.
Networking Basics – Subnetting
Fill in the following tables for Network, broadcast, first IP, last IP, and maximum hosts in the
network.
The column for IP address should be in Decimal format for each, except number of hosts.
| Category | IP Address | Binary Format |
| Address | 192.168.100.4 | 11000000.10101000.01100100.00000100 |
| Netmask | 28 | 11111111.11111111.11111111.11110000 |
| Network Address | 192.168.100.0 | 11000000.10101000.01100100.00000000 |
| Broadcast Address | 192.168.100.255 | 11000000.10101000.01100100.11111111 |
| First IP | 192.168.100.1 | 11000000.10101000.01100100.00000001 |
| Last IP | 192.168.100.14 | 11000000.10101000.01100100.00001110 |
| Maximum Host in the Network | 14 |
| Category | IP Address | Binary Format |
| Address | 170.1.0.0 | 10101010.00000001.00000000.00000000 |
| Netmask | 26 | 11111111.11111111.11111111.11000000 |
| Network Address | 170.1.0.0 | 10101010.00000001.00000000.00000000 |
| Broadcast Address | 170.1.0.127 | 10101010.00000001.00000000.01111111 |
| First IP | 170.1.0.1 | 10101010.00000001.00000000.00000001 |
| Last IP | 170.1.0.126 | 10101010.00000001.00000000.01111110 |
| Maximum Host in the Network | 62 |
Working in Linux
Task A: Practice with the Basic Linux Commands
Step 1:

Above is the network configuration of the Kali Linux Cyber Range VM. I used the command “ifconfig” to check this configuration and it returned an IP address of “10.1.172.184”.
Step 2 through 6:

Tasks 2-6 are reflected above. I used the “pwd” command to print the current working directory which is “/home/student”. Then I used the “echo” command to print my name, “Zachary Weaver” to the console. Next, I used the “echo” command with the flag “-e” to enable escape characters and the “\n” escape character. I placed the escape character between my first and last name to place each name on a unique line. Next, I used the “cd” command, which, without any modifiers will change the directory to the “/home” directory for the current user, which in this instance is “/home/student”. Next, I used the “touch” command to create the file “forzweav004.txt”. I then used the “ls” command with the “-l” flag to display the long list of the current directory and can see that the “zweav004.txt” file has been created. This file is zero bits in size at this time.
Steps 7 and 8:

The above screenshots show steps 7 and 8. I used the “mkdir” command to create a new directory named “zweav004”. I then used the “ls” command with the “-l” flag to display the long list of the contents of the current directory. The new directory “zweav004” is present and is 4096 bits in size. It is known that this is a directory because it is blue in color. I used the “cp” command to copy the “/etc/passwd” file to the “/home/student” directory and renamed the file within the same command by inputting “passwd_zweav004” at the end of the command. I then used the “head” command with the “-n” flag followed by a “6” to show the first six lines of the file “passwd_zweav004”. The “head command shows the beginning lines of a file, the “-n” flag indicates that the user wants to see a specific number of lines instead of the default first ten lines that the “head” command generates. The number “6” in the command input indicates that the first six lines of the file will be output to the terminal. Finally, I used the “grep” command to search for “www” in the “passwd_zweav004” file.