3 ms·
Some friends and I hacked Blackboard last year. We exploited it by smuggling null bytes (0x00) via. their WebDAV protocol. This made it possible to hijack othe
by michaelmcmillan 7y ago
Some friends and I hacked Blackboard last year. We exploited it by smuggling null bytes (0x00) via. their WebDAV protocol.
This made it possible to hijack other accounts, including our professors'. So we hacked our own grades and then reported it. Luckily we didn't suffer the same fate as Demirkapi.
Blog post here: https://bustbyte.no/blog/how-we-hacked-blackboard-and-changed-our-grades https://bustbyte.no/blog/how-we-hacked-blackboard-and-change...
- anaphor 7y agoI remember finding XSS and XSRF bugs in one of their things like 9 years ago. I'm not surprised it still sucks. I posted it on the full disclosure mailing list, and IIRC they ignored it as far as I could tell. This was back in 2010. (And before I get flak for not notifying them before disclosing it, I was a teenager and I wouldn't do it that way now)
- Rychard 7y agoI reported a vulnerability in blackboard when I was in college (around the same time period as you). I don't recall any sort of disclosure mailing list, and the only contact link I found seemingly went through my college's IT department. Whether my university had applied some customization, or whether it was just me being a young college student, I'm not sure. Anyways, a few days after I had reported the vulnerability, I was summoned to a meeting where I found myself sitting at a table opposite my academic advisor, as well as the Department Chair of the CS department, where they began to speak to me about "academic integrity". I'm glad the story mostly ends there, as during this meeting I realized what had actually happened; someone in the IT department had misinterpreted my report as some sort of hacking threat, and they had "tracked me down on the university network", which makes no sense because I had reported the vulnerability via email directly from my .edu address. While I wasn't exactly well-liked among the professors in the CS department, the department chair at least recognized that it was a big misunderstanding, that I wasn't doing anything nefarious, and had been acting in good faith. After that meeting, I had approximately zero interest in disclosing vulnerabilities of any sort, for fear of being on the hook if/when they were ever exploited.
- tastroder 7y ago> I don't recall any sort of disclosure mailing list, fyi, your parent post referred to [1] here. Glad nothing too bad came of your disclosure. [1] https://seclists.org/fulldisclosure/ https://seclists.org/fulldisclosure/
- droithomme 7y ago> After that meeting, I had approximately zero interest in disclosing vulnerabilities of any sort Sales to a private broker is one alternative.
- hermitdev 7y agoBack on the windows 9x kernel, one could render a file/folder by including a NIL character (0xFF) in the name. The NIL wouldn't render at all in explorer, but explorer was also incapable of accessing the file or folder. I forget the exact error message, but it was something along the lines of the path not existing. Had to hop out to a command prompt to temporarily rename it to make it accessible, then rename it back. Had to enter the code by using ALT+0+2+5+5. Sadly, doesnt work on the NT based kernel. Was fun hiding in plain sight in the 90s.
- pixl97 7y agoThings like this were fun if you could use Linux to access windows via a samba share with write access. You could make all kinds of directories that explorer wouldn't handle correctly. Also reminds me of a bug that was common in Adobe Reader that would create a very deep recursion of adobe folders in the users directory. You could not delete said files because the path was far too long. Had to use SUBST to map it to a shorter path then delete your way up.