59 ms·
IoT hacking and rickrolling my high school district
- octokatt 5y agoThis is awesome, and rock thee onwards. I wanted to make sure OP knows that “white hood” can mean something _very_ different, and “white hoodie hacker” might provide that distance.
- cghendrix 5y agoI thought I was cool being able to modify the ready message on printers across the school network. This is really impressive.
- person22 5y agoI wrote an infinite loop in postscript and sent it to all the printers. This was when postscript printers cost a fortune so there were not many of them. Fun days were those.
- drusepth 5y agoIn middle school I used Javascript to change Google's button text from "I'm feeling lucky!" to "Andrew is the best!" (javascript:getElementById('').text='blah') I showed some other students who were so freaked out that I had "hacked Google" that I got the attention of the librarian, who promptly banned me from the library computers for the rest of the year, even after I refreshed the page to show them it wasn't "real". Oof.
- cghendrix 5y agoHaha when I was searching for printers across the district network the librarian was looking at my screen. She called me out across the room asking why I was looking at printers at a different school. Oof.
- buzzert 5y agoHopefully everyone here has seen the movie Hackers, where a similar, but slightly more destructive prank involving the school's sprinkler system took place.
- pranavnt 5y agoThis is amazing!!
- Epitom3 5y agoI am glad everything went in a positive direction and the school didn't punish the students.
- BeFlatXIII 5y agoI remember being in elementary school and avoiding the net nanny by viewing one of the network drives that students (somehow) had access to but weren't told about. Eventually, someone in my class poked around enough to find BESS.exe and deleted it and we had unfiltered internet for a day.
- travelaminds221 5y agolooking for hscker for hire
- travelaminds221 5y agolooking for hacker for hire
- rejectfinite 5y ago30s crisis hurling at me when a high school senior is way better than me lmao. Amazing read!
- belval 5y agoThe fact that the administration didn't choose to sue them to oblivion is refreshing. I hope we'll see a trend in the future of educator being smart enough to admit that they made a mistake and to encourage the students to develop their talent. One can only hope.
- nielsbot 5y agoProbably helps that "We prepared complete documentation of everything we did, including recommendations to remediate the vulnerabilities we discovered. We went a comprehensive 26-page penetration test report to the D214 tech team and worked with them to help secure their network."
- IshKebab 5y agoThat hasn't helped in the past. Frankly I think they were naive to reveal themselves no matter what the authorities said. It hasn't gone nearly as well for other people.
- treesknees 5y agoThe students were extremely lucky. The advice given to me in high school (I was working on tech projects after school for several teachers and groups) was to not even try or explore poking around the IT networks it no matter how good my intentions were. All it takes is one grumpy school administrator to feel undermined or to misunderstand your report and you could be expelled. When you're in a position like a student, you're still working your way up and building credibility. No need to risk it all for an IT group that doesn't want your security advice and didn't ask for your help.
- adventured 5y agoIt's always fascinating how dramatically different schools can be. When I was in high school, in the late 1990s, nobody would have cared so much about something along these lines. At worst it would have resulted in a three day suspension from school and lecture from the principle.
- dmitrygr 5y agoMany here, I am sure, got in trouble in high school for exposing security issues in school IT. So I imagine we're all very happy to see a sane response from school administration for once!
- dvtrn 5y agoI got in trouble once in high school just for discovering and then using `net send` to send a message to my friend that said "Hi from lab 3". Computer lab access revoked for 6 weeks. Jokes on them, now I send socket messages to my friend that says "Hi from Chicago" and there's nothing they can do about it. My friend however keeps begging me to use this thing called 'email' because he claims he doesn't see the socket messages.
- uudecoded 5y agoSorry you got access revoked. I accidentally did a net send (via the GUI) to the whole district domain instead of my friend in AP CS that said "Time for break!" right before the snack break. In my next class, the teacher was talking about "Time for break" virus going around... :/ This was after the district IT wanted to suspend me for setting up a Windows 2000 domain for the yearbook lab, so I kept my mouth shut.
- flatiron 5y agoeveryone in my school net send bombed everyone all the time. Im not sure how they didn't figure out how to just turn it off. but i remember you had to do it from a library computer, because it said who it sent it from. so you had to do a little drive by walking net send as you walked out of the library to not get caught
- snerbles 5y agoIn our case it escalated to scripts with silent, random time delays. Launch it from a floppy, walk away and 87 minutes later everyone is wondering why a notice went out saying that a Toyota Corolla in the parking lot has its lights on.
- 5y ago
- castis 5y agoFree relatively harmless large-scale pen testing! Nice work.
- jcims 5y agoI’ve said this a bunch on here so please tell me to stuff it if it’s tiresome, but having been on the far side of a large scale bug bounty i am incredibly impressed with the skills that young folks are developing in infosec. Probably not particularly unique but the industry is still a bit of a combination of tradecraft and academic pursuit and can be confusing for people to find a way in. I think this is why i really appreciate those that just bear down and get after it.
- deleted 5y ago[deleted]
- ajford 5y agoGlad to see a cooperative and supportive academic administration, and I'm sure the thoroughness and planning that the team demonstrated made it easier on the administration. The sheer amount of testing and verifying no major impact to academic testing took place probably helped, and cleaning up after themselves and documenting their finding and reporting it to IT was a cherry on the top. I like that the administration even requested that the team brief the district IT on the "attack".
- securiTee 5y agoNeat story, and this is clearly harmless. But isn't the most basic, fundamental, number one rule of security/pen testing to try to break into a system (no matter how weak) if and only if you've been given clearance beforehand? Why doesn't that hold here?
- jdmichal 5y agoThe author literally put in TWO disclaimers making that exact point...
- unethical_ban 5y agoI think the OP is asking "Why are we applauding them if they broke the rules?". The answer is "Sometimes, people break the rules".
- GavinMcG 5y agoThe rule does apply. Also, it was a senior prank, which by definition involves breaking the rules.
- ar_lan 5y agoTIL there is an Elk Grove that is not in California!
- SavantIdiot 5y agoUp until OP starts working out the frustrations of RTSP it was pretty much a yawner "scan for ports, http to them, see if sumthins there and unguarded". But the perseverance to make a prank work like that with a finicky protocol across a wide variety of different OEM hardware is really exceptional!
- bentcorner 5y agoUsing the school computer's webcam to test his exploit at night was genius. Very clean.
- particulars02 5y agoGreatest rickroll since S2E10 of Ted Lasso.
- hx2a 5y agoWhen I was in High School (early 90's) we got a new computer system that nobody was using yet. I discovered there was an email system of some kind and that every student had an email address that we were not told about. I also discovered Tetris installed in a directory on the server. I was able to play Tetris and I could show other students how to access it, but it was inconvenient to get to. Therefore I decided I would email Tetris to every student (I emailed the executable, not a link to Tetris), making it easier for everyone to play also. As soon as I did this the entire system got very slow...apparently the server had no quotas or partitioning and the hundreds of copies of Tetris filled up 100% of the hard drive space. It was a disaster. The computer "specialist" had no idea how to fix the system and she was teaching an adult education class that evening that required the system to work. She was furious and wanted me to get suspended. It didn't happen though because I spoke up about the problem right when I knew there was a problem and also some other teachers intervened on my behalf. The woman who was responsible for the computer system back then is now the superintendent of the school system. I wonder if she remembers me.
- codazoda 5y agoShe remembers you. I also graduated in the early 90's and my children recently graduated from my alma mater. When I went with them to teacher conferences some of the same teachers were still there. Teachers that I didn't even have classes with remember me.
- zengargoyle 5y agoIn like '89 when I was 19 and at university my work-study job was with the IT/ComputingResources department (old names). I worked as a graveyard shift NOC operator swapping tapes and handing out print-jobs, running system tests and stuff like that. We had several 24/7 computer labs full of Sun 3/50(60) workstations and things like that. But there was one lab that was closed from 10-5 overnight and I thought to myself "hey, there's a whole room of workstations not doing anything" so I wrote some scripts rsh/NFS and used that lab one night to run distributed ray-tracing jobs. The next day my account was disabled and I had to go talk to Security. They sorta laughed a bit then went like NO don't do that. I worked for the IT department for the next four years. Then I left for a decade. Then I came back and applied for a job. The interview lasted all of five minutes, I worked for a few months before being forcibly promoted up into the upper circle. My first task was to go around to the dozen others who had root and ask for advice and update the root-speech documentation. I got to Security.... tippity tappity "Oh, hello Mr. zengargoyle, let's see... '89 'misuse of computing resources'." LOL, still had root by the end of the day. So, this is just to say... that places like education where people may stick around for a long while in the system and such. They probably do remember a bunch of events from even a decade ago. It's the good places that have a sense of humor or appreciation for a worthy harmless infraction. They may even be secretly proud or have some admiration. Though I do sorta fear that I just happened to hit the tail end of old-school hackery where such things are such things are rewarded. Now get off my lawn.
- kervantas 5y agoThe s in IoT stands for security.
- thomasfromcdnjs 5y agoSo much attention to detail that I can't help but think that the kids parents were helping along the way.
- ajford 5y agoMaybe, maybe not. The author has graduated from High School, meaning they're about to enter college or the workforce. I wouldn't be surprised to see this level of detail from someone at that level academically. Delighted, yes. Would I expect if from everyone? Hell no. But surprised that a tech-enthusiast and eager learner might have put this much thought into this prank and it's potential consequences, not so much. Teenagers/young adults tend to have different stressors and other things to occupy their time than the average adult in the workforce, meaning the author likely gave this prank a fair amount of their free time, and that dedication showed through in the amount of planning done. Additionally it's likely, given they mentioned once or twice in the article they planned on posting a blog about the prank, that they might be hoping to use this on their resume or as a talking point in their career. If they're hoping to go into security or comp sci, this would be a decent feather in their cap and the amount of time spent is easily justified.
- giantg2 5y agoMy first thought when I read the headline was "another kid with a felony following them around for a prank that didn't harm anyone". Nice to see they weren't prosecuted.
- ianhawes 5y agoGiven the amount of press this is receiving and the fact that the message the administration sent to them seemed a bit suspect, I wouldn't be surprised if the kids did end up catching several charges.
- 0x000000001 5y agoNo kidding, I was threatened with legal action for significantly less shenanigans back in my day.
- sodality2 5y agoI told my district that I could change my race at-will via a hidden form on the profile page. I changed it to "Purple". Got a call back from some IT guy telling me I accessed their computer without authorization, and that if it happened again, they'd press charges. I asked to be put through to the IT administrator, and he laughed and told me don't worry about it... Sometimes, they can handle it well. Very glad they did for you as well :)
- qmarchi 5y agoI think the dilenation point comes in with whether they are an IT "person" or a school administrator. Regularly, I would end up in trouble in my High School for things like bypassing the root account (using ShellShock), or nullifying their executable restrictions (because I needed to run my own executables for a work/study program). If I got caught, the IT admin would sit down and we'd chat about what happened, how they could improve their security and such. An administrator caught on to one of my shenanigans, bypassing the content block because I wanted to read a "hacking" article, and threatened me with suspension. Supposedly, she reported the incident to IT, and IT told her to not bother me anymore.
- rajamaka 5y agoThis is spot on. I Used to work as a sysadmin for a large private school and always enjoyed the red/blue dynamic of tech team vs the smarter students trying to poke through the restrictions of their laptops and network. It was always disappointing when they took it too far and were directly caught by teachers or administration before I could tell them they were being a bit too blatantly malicious.
- sodality2 5y agoThat's definitely true, my elementary school principal once got upset at me for unplugging and replugging the ethernet to fix the internet... I'm pretty sure the IT guys would have done the same :P
- dyingkneepad 5y agoI feel so dumb when I read kids doing these things. Back in High School all I knew was how I could run arbitrary executable files by renaming them to calc.exe. We also did the classic "take a screenshot of the desktop, set it as the wallpaper, then remove all icons and the start menu" thing.
- alistairSH 5y agoAll this. Plus TI-86 king fu. Though this was 1991-1995, IoT didn’t exist and email and web access was mostly through AOL or Prodigy.
- rmorey 5y agoAnother good one on that level was using the Windows keyboard shortcut ctrl-alt-down to rotate the display upside down - totally harmless, but absolutely maddening if you don’t know how to undo it
- rocqua 5y agoEven better if you combined it with an upside down screenshot of the desktop. So it looked like only the mouse was upside down and all buttons didn't work.
- gpt5 5y agoUnfortunately, this feature was discontinued by most graphics drivers.
- lysurgic 5y agoThis is still a common prank at work on win10 pc’s
- nyanpasu64 5y agoI think it's a good thing that Ctrl+Alt+Arrow is no longer intercepted by graphics drivers, since IMO shortcuts not containing Win should be handled by apps and not the system.
- 5y ago
- jackson1442 5y agoAbout two years ago, I was in high school and decided to, as a joke, “hack” the computer. By logging in as admn:password. I was incredibly surprised when it actually ended up working as a domain admin account. After checking this, I immediately signed out. When my CS teacher filed a ticket asking “who has the user account ‘admin’ and why is the password ‘password?’” IT wanted to revoke my network login and probably put me in ISS for a few days. Fortunately, my CS teacher didn’t reveal who I was. Very glad IT at this person’s school took it in stride, unfortunately this was just the MO of IT in my district.
- don-code 5y agoI'm impressed with how much foresight this high schooler had in preparing for the prank. My impression is that most high school age kids would out themselves within the first few weeks of planning due to wanting to boast, here they instead took to testing covertly, overnight.
- mmaunder 5y agoSomeone I know did something similar, was arrested in their college dorm, and at the sentencing hearing in federal court was fined and sentenced to 5 years probation, and now has a criminal record. This kid is very very lucky. Obviously they violated the CFAA which carries severe criminal penalties. They engaged in actual hacking without any permission or defined scope. And they exploited the system without any responsible disclosure process. Anyone in the field will tell you that this is an absolute disaster of a post because it sends the signal to other young aspiring cybersecurity professionals that this is OK, and the school will laugh it off, and you'll be seen as an adorable Matthew Broderick type Wargames character. I can't overemphasize how far this is from the truth in 2021. Absolutely do not access systems you are not allowed to. If you do want to do penetration testing, you need permission from the systems owner and a clearly defined scope. And when you do find issues, you don't exploit them, you responsibly disclose them within a clearly defined framework. If you want to end up with a criminal record that will profoundly effect the rest of your life, including your career prospects and ability to travel internationally, then by all means, do what this guy did. I wish it wasn't so. It never used to be. But this is how it is now. Overzealous prosecutors have been given a huge amount of power, and all you need is one embarrassed systems administrator, school board or management team to trigger a disastrous outcome in stories like this.
- baybal2 5y agoThis is ridiculous
- jjoonathan 5y agoGross but true. The administration has every incentive and opportunity to spin this into a self-serving story about taking down evil sinister hackers -- and maybe scapegoat a few unrelated problems while they are at it. I am delighted that these admins had the character to resist the perverse incentives of the system.
- jdkee 5y agoThis post is 100% spot on. While the local school district may treat it as a prank, in the U.S. the federal authorities may not. To see how seriously the government takes this act, look at the penalties section of the relevant U.S. code. https://www.law.cornell.edu/uscode/text/18/1030 https://www.law.cornell.edu/uscode/text/18/1030
- donatj 5y agoWhen I was in elementary school in the early 90's, I discovered you could use AppleTalk to print to just about any printer in the district. I would print pages and pages of "I AM THE MASS PAPER WASTER!!!" to random printers in other buildings. I'm genuinely curious if it actually worked.
- guynamedloren 5y agoFun story! Such incredible attention to detail and thoughtfulness, all the way up to automatically sending a pen test report to the district's technical supervisors, and sharing a presentation after graduation. This kid was one step ahead all along. Great work, Minh.
- duped 5y agoDo prosecutors need consent from victims to file charges in cases like this? Also if you're going to commit a crime and brag about it, don't say "hey well they would point the finger at me anyway and I'm not going to name my partners." You've just told them there are coconspirators, and you don't have a right not to incriminate others.
- paxys 5y agoThey don't legally need it, but such cases are pretty much dead in court without the victim's cooperation so the prosecution will almost always drop it.
- EvanAnderson 5y agoThe Aaron Swartz prosecution continued, even after MIT and JSTOR said they didn't want to press charges, because of a zealous prosecutor.
- duped 5y agoWhat happens when the suspect publicly admits to doing it and providing detailed information on the motive and means
- earksiinni 5y agoSerious question. What, if any, instruction do kids these days receive regarding what's allowed on computer systems? I remember in high school poking around a network drive until I found an executable with the name "SEND" in the name. I had a sense that it would send some kind of message somewhere, but I honestly didn't know where or to how many people. I was quite surprised when all the screens in our computer lab froze and, five seconds later, my message appeared on all of them. (I later learned that my message appeared on every desktop screen in the school!) I'm not sure exactly how they found me out, but I was called into the IT admin's office a couple of days later. She was furious with me. I told her the truth. I didn't know what exactly would happen when I ran that command, but she didn't buy it. Fortunately, nothing ended up happening after that. I've wondered to this day what exactly they could have done to me if they decided to press whatever legal authority they might have had to its fullest extent. I was never told "don't go to Z:\" or "don't run any program other than those on this list." Even after I was found out, I wasn't ever explicitly told that my actions constituted unauthorized access. It was a different, perhaps more innocent (or ignorant) time back then. How much have things changed now?
- jovial_cavalier 5y agoI graduated high school in 2015. I remember similarly poking around a network drive until I found a file in plaintext which contained everyone's student ID and whether or not they had a nut allergy (protected by HIPAA), for the bus system. I didn't think much of it, but some other students caught wind. Before I knew it, the superintendent threatened to have the police involved and press legal action for "hacking confidential student data." It's CYA all the way, usually at the expense of the person in the chain least equipped to cover their ass (the student).
- earksiinni 5y agoWow. That's terrifying. And you didn't even run anything! I'm guessing that they never told you "don't browse this network drive"?
- Buttons840 5y ago
- Justsignedup 5y agoMy time in highschool was wasted. Kudos to these amazing kids.
- 908B64B197 5y agoI just hope the author, at least, applied to MIT. He would fit right in. http://hacks.mit.edu/ http://hacks.mit.edu/.
- joezydeco 5y agoI live near this kid and I'd offer them an internship on the spot if they came forward...but I fear they'd just be bored.
- datavirtue 5y agoQuick! Hire them before they can use their powers for the forces of good.
- bfirsh 5y agoReminds of me my school leaving prank. I rewrote the whole internet on my school's computers. Google's logo became "Leavers '08", Facebook became "Hatebook" and was red, YouTube only played videos of cats, amongst other things. These were the days when nothing had SSL, so you could just intercept and rewrite traffic! My only requirement was: do no actual damage It was implemented as a Debian live CD that you could drop into any school computer. It would boot up, then Ettercap would MITM the whole network by spoofing the router. It routed all HTTP traffic via Squid and a custom ICAP server that did the actual rewriting. If you removed the live CDs, the network just went back to normal within a couple of minutes. Routing the whole school's network through one old Pentium machine wouldn't work though, so I figured out a way of doing distributed load balancing: it would do the ARP spoofing slowly and randomly. So, as you added more machines, it would just magically balance between them. It worked great for about an hour then whole network mysteriously stopped working for the rest of the day. I left all the live CDs in the computers as a calling card. Sorry, school network admins.
- bluedays 5y agoI don't think this happened.
- samschooler 5y agoHypothetically it could happen and even if it isn’t true, I feel it adds something to the conversation. Besides, you cited as many sources as they did.
- bluedays 5y agoSounds way overly complex for a high schooler to pull off. At least the OP sounded legitimate, the details didn't sound over the top.
- anyfoo 5y agoI think you're underestimating motivated high schoolers. When I was in high school I was a huge Linux fan and had a side job as a network administrator for small companies in my town. I don't know if I would have gotten the "random ARP load balancing" idea, but overall it seems well within the knowledge admins of the days had about TCP/IP. When I was between 15 and 17 or so, I wrote small HTTP, DNS servers etc. in C++ for fun (straightforward implementations and not better in any way, so in the end just learning exercises), and I definitely had friends who did similar things.
- mdip 5y agoThis is excellent; reminds me of (very much smaller and far less cleverly executed) grief that I caused the administration at my HS back in the day[0]. There's a few comments about the risks along with a little surprise/at least applause for the administration choosing not to waste the courts/various other parts of the justice system with this prank. I completely agree -- I don't know if I'm terribly surprised they chose that route (whether or not they were truly upset in the first place). I applaud the students for executing this so carefully/well and if my kids pulled something like this off with this level of care -- well, they'd at least be getting a dinner out of their choosing -- probably a trip to a nearby theme park. I suspect the kids involved were also certain that their approach, attention paid to keep from disrupting class and (thankfully thorough) testing that helped avoid a harmless prank turning into expensive litigation/really pissed off parents. But I'll bet there was a lot of fear around that, anyway! Had something gone awry -- and that's always where the risk is -- I'm guessing the outcome would have been more severe for these kids. They really played the social engineering/covering their hind-quarters side of this prank very well. A large amount of effort was put toward making sure class was not interrupted[1], things worked and were tested and they provided detailed information to the administration on how to secure their systems -- that last piece allowing them to say "Without our minimally invasive prank and report you'd have never known these issues existed. We're not that special; a more malicious student could have discovered these flaws, opted for a porn broadcast and made it difficult/impossible to find them to punish." They probably understand their own school's administration and took an educated guess as to how they might handle something like that, too. At least for the scope of anything I did, I knew I wouldn't hear from the Vice Principal or Principal -- I'd solved various computer problems for them by then that the worst I'd get would be "that was cool, but please don't do that again." I didn't get in trouble because the pranks worked similarly -- I tested/avoided disruption (most of the time), did no permanent damage and anything was resolved by a reboot (DOS and no fixed disk) and our harm was necessarily limited since there are only so many computers you can covertly pop a floppy disk in -- there was no network. The biggest factor, though, was that our programming teacher sometimes got involved, himself. He was the head of the math department, not your traditional "computer geek" and I was doing things that he wasn't teaching, so he encouraged it. The guy was amazing (passed away in the mid-00s). So, kids, if you do try this at home, make sure it all works, provably, very very well and don't do anything that will give them other reasons to throw the book at you. And if your administration has more than the typical "Zero Tolerance[2]" stance on things, it's just a bad idea regardless. I'm sure there were a few among the ranks that became furious but cooler heads prevailed. The report at the end was a nice touch. [0] Mostly contained in the computer lab, which was non-networked, but when we discovered the three-letter-acronym TSR (DOS's Terminate and Stay Ready) and realized it was rare that another student would reboot an already booted machine (it took forever counting to the 512KB or so RAM installed). Incredibly, I graduated in the late 90s -- my Senior year, the lab that taught (Turbo, then Borland) Pascal was 15 years behind what most people had at home... these diskless all-in-one bastards wouldn't break. [1] I'm sure it took the kids a little longer to get to their classes after that all happened -- that's a minor, completely expected, situation here and at least a small reward for the efforts involved. [2] The school ten miles north of us was in a rural district and had a parking lot full of trucks with hunting rifles attached sitting in the parking lot every day (well after all of the schools installed additional locks and added security theater to make parents feel better post-Columbine)...that wasn't forbidden at least as far back as the early 00s and I wouldn't be surprised if a blind eye is mostly turned, today in some parts of that district.
- nudgeee 5y agoI got in trouble and subsequently suspended from school back in the ‘90s for causing BSOD’s on classmates computers using WinNuke [0]. They classed it as vandalism even though the payload causes no permanent damage (apart from losing unsaved work). I found more severe vulnerabilities including being able to lift home addresses of students by querying an unprotected endpoint. Didn’t get in trouble for this one, and reported it promptly to the IT administrator. [0] https://en.m.wikipedia.org/wiki/WinNuke https://en.m.wikipedia.org/wiki/WinNuke
- azinman2 5y agoReminds me lightly of when I was in high school, email was fairly new -- especially at a school. My friend at a fancy private school had a Linux machine to access, and she really wanted to know what someone else had said about her. I managed to script kiddy my way in leveraging her existing shell login, got root, and read the email. What I didn't realize was that my .history file contained everything I had done. Eventually the sysadmin wrote me an email saying he knew what was going on and wanted to meet up, stating 'he wouldn't cuff me' and that he was 'a chill dude'. I was obviously scared, deleted everything, and tried to pretend nothing ever had happened. Luckily no one got in trouble (meaning me or my friend). Not so sure this would happen in 2021.
- midwestemo 5y agoHey I know someone who goes to that school, interesting. He was telling me about this incident before
- themantra514 5y agoThis is the way.
- hnwd 5y agoI'm interested to know how was he able to remote access to seemingly any machine in the network, from outside?
- WhiteHoodHacker 5y agoI had Chrome RDP access on a few machines setup earlier, since I could come in-person with my team for security competitions.
- hnwd 5y agoHey, thanks for the reply. Appreciate the writeup too, it was a fun read. Hope you don't mind but I have a few more questions. How were you able to get Chrome RDP access setup without admin privileges? I assume this is automatically blocked via group policy. Now that you have Chrome RDP setup, how were you able to access these machines from outside the network from home? "since I could come in-person with my team for security competitions" I'm really intrigued now. What were these security competitions about and were they part of a class you were in?
- lxe 5y agoIn 2001, in 7th grade at the beginning of my web dev "career", so to speak, I made a website that looked exactly like our school district's "snow day" school closure and delay page -- and I allowed anyone to edit the message. I told a few kids about this -- it was a pinnacle of my PHP prowess back then. Got called into an office -- a gifted program administration, not the regular school office. I think one of the teachers there caught wind of my cool little trick, and asked me to take it down right then and there. I was terrified, as I wasn't really someone to get into any sort of trouble. I was able to take it down through their machine's windows explorer's FTP access. Now I realize that this teacher probably saved me from a lot of trouble. I wish these sort of stories were the norm -- where educators welcome the natural curiosity instead of throwing the law at kids who dare to think outside the box.
- rsp1984 5y agoIn case anyone else is wondering how the heck the kid got access to the district's network, the key sentence is hidden in the middle of the post: Since freshman year, I had complete access to the IPTV system. I only messed around with it a few times and had plans for a senior prank, but it moved to the back of my mind and eventually went forgotten. Not sure why they don't go into more detail about how exactly "complete access" was obtained, since that is obviously the hardest part of hacking any system. Not trying to downplay the achievement here, just think that this would have deserved a bit more detail.
- ajcp 5y agoHe explains it quite clearly that him and his friends were port scanning the schools network for funsies. "From the results, we found various devices exposed on the district network. These included printers, IP phones... and even security cameras without any password authentication!"
- kevinsundar 5y agoIt seems like he just was on the school network and the IPTV devices were also on the same network with no authentication.
- ubermonkey 5y agoThree things are remarkable about this, and make it a happy story. First, that the pranksters were so egregiously responsible in the way they went about it. They avoided disrupting any actual educational activities; it was meant to be harmless fun, not vandalism. No harm came to anything here. Second, that they documented their findings to the administration as part of the action, including recommendations for improvements. Third, the administration took this as exactly that: a harmless prank by smart, ethical kids who ALSO did them a favor by pointing out the vulnerabilities. If the admin had a panicked fit about this, they could have made it an ugly situation. My educational experience was populated far more by "freak out and yell" types than this school district, which was a shame.
- nutwit 5y agoThe school district itself was relatively chill, however the individual deans freaked out. Because the penetration report was sent to the tech team and not the deans, the deans were intent on finding out exactly who did the hack to find something to report to their bosses (and according to them concern about the grade book system being exposed?? Not sure how you’re supposed to rick roll a grade book but if anyone has an idea i’d love to know). As the earliest poster of footage of this event, I actually got tracked down (despite the fact that the only information they had to go off of was my youtube channel which had no references to my actual name whatsoever) and interrogated about what I knew of the event by the dean. The penetration report had been sent a while prior to this (which I knew about, as being a sibling of the original blog poster can have many benefits) which made the entire thing so much funnier. I was thankful that masks were a requirement for in person students at the time, as my mouth was literally twitching the entire time during the interrogation.
- saltminer 5y ago>and according to them concern about the grade book system being exposed?? Junior year in high school, I got suspended for "hacking." The tl;dr is that I was using a proxy to fetch assignments for class (because the county decided "yeah, this state run Moodle instance is obviously not appropriate for education" and one of my classes used Moodle) and got caught with the proxy configuration screen open. I wish I was joking. Anyway, when I was sitting in the guidance counselor's office as the teacher was talking up how "dangerous" I was, I noticed a sticky note with a username and password written on it. Turns out it was an admin account for the gradebook, though I think it was just intended for scheduling. I never did anything bad with those credentials, but that really tanked what little respect I still had for the administrators there. On a lighter note, when stack exchange & co got blocked the next year, I was good friends with the librarians since I helped out a fair amount fixing up their laptop carts (and doing other things the sysadmins were too busy to take care of), and they were able to get them unblocked. It taught me a lot about office politics: people are willing to return favors, so you should always make those connections.
- mister_c_dub 5y agoWhat a legend.
- gjsman-1000 5y agoI was at my own community college 2 years ago, and they had those Smart TVs showing news and weather everywhere, as well as custom images uploaded by the clubs on campus. It was supposed to be that a club could log into them, make, and submit a graphic to display on the TVs, but the school would have to review them before they would be displayed. However, I would later find out, a software update had messed up the roles system and so that club username/password which was in a public document actually had the ability to post things immediately on the TVs, without review. I found this out when I made a Math Club poster, hit the button, and it was immediately live without a check. I just reported it and it was fixed the next day. My instructor said that could have been really really bad considering some more unscrupulous college kids who would have (not naming names) probably gotten a kick out of throwing pr0n on them...
- RubberShoes 5y agoI went to Buffalo Grove High School in this same district and graduated many years ago. At the time no IPTV systems or EPIC bell systems were in place. However, as soon as I walked in my freshman year I noticed the 'teacher' WiFi was only using MAC Address Filtering. One minute scan and a spoof later I was poking around to discover a whole lot was visible from this privileged network. “...From the results, we found various devices exposed on the district network. These included printers, IP phones... and even security cameras without any password authentication!” It was even worse back then. It was all exposed on wide open WiFi! My senior prank was going to revolve around the printers. We were shocked to discover every printer not just in BG but across the entire district was accessible with no authentication of any kind. We cooked up ideas and were planning to print either porn or I has cheezburger/lolcat memes via telnet (I'm dating myself.) Ultimately I got into other trouble before we could execute and figured this wasn’t worth not graduating over. I moved on and so happy to see a much better prank on this same network happen so many years later with almost no repercussions. Congratulations and great prank!
- driverdan 5y agoIn middle school all classrooms had their own printer. They were also shared on the entire school network with no security. We had a lot of fun printing stuff to other classes and never got caught.
- joshuamoes 5y agoPreface this by saying this was a smaller school, and the students had limited access to wifi. For example a teacher would create a set of radius credentials that would only be active for 1 hour. Since data was also expensive that was not an easy work around. In my grade 11 electronics class, one project we were assigned was to create a digital clock with notifications for one of the teachers. Me and a friend set up a raspberry pi with magic mirror installed on it, and modified some available plugins at the time to allow a google calendar for test dates embedded on the display. The teacher was quite pleased with this, but we convinced him to hard wire it to the network for "stability". In the background we had installed a vpn connection to one of my vps that I used to host my website, and created a new set of sudo enabled credentials naming it magic-mirror or something. The teacher then reviewed the project and changed the normal user credentials etc. Then right before it was installed in the ceiling, we attached a wifi adapter to the pi. A week or so later we remoted in through the tunnel and enabled a wireless hotspot from the pi. This provided us with internet while we were close to the classroom for the next year. People also over time learned that you could extend the range by hot spotting additional jumps using laptops.
- bowmessage 5y agoNice! I used to carry around a wireless router in my backpack for the same reason, and made sure to surreptitiously plug it in at the back of every class. Similarly, the school had very restricted WiFi, but no restrictions on the wired network. Fun times.
- joshuamoes 5y agoFor sure lots of fun, we also very quickly found the staff wifi password, and just cloned mac addresses of allowed devices to bypass the filtering.
- jimt1234 5y agoWorking in IT/tech for school district is the worst. My experience from many years ago - around 2002, I think: 1. First day on the job, email to boss: "Hey, the computer lab at Springfield High has a ton of known security flaws that are begging to be exploited." 2. Reply, 1 week later: "Sorry, we don't have any money for that. Just keep everything up-and-running." 3. 3 weeks later the computer lab at Springfield High got "hacked". All the computers displayed a popup window that said, "Miss Krabappel is a dyke!" (sorry for the offensive language) 4. Next day, email from boss: "The computer lab at Springfield High was hacked! Figure out how to fix this and make sure it doesn't happen again!" 5. A few days later Miss Krabappel filed to sue the school district. The local newspaper picked up the story. 6. Email from boss, in full panic mode: "I need you to figure out who hacked the computer lab at Springfield High so we can report him to the police!" 7. A week later an independent consulting firm was brought in to help identify the person behind the "hack". I heard they were paid $50K and found nothing. However, the kid got ratted out when he told all his friends. (It wasn't Bart Simpson! ;) ) 8. Several weeks later: meeting to discuss working with a consulting firm that's gonna fix all the security issues because the current staff (me and my team) lacks the skills. 9. About 6 months later, I quit.
- snerbles 5y ago> All the computers displayed a popup window When I engaged in `net send` shenanigans at the local community college, at least the IT staff was smart enough to know where to scramble a runner whenever those dialog boxes popped up across campus. "ALL YOUR BASE ARE BELONG TO US" was quite the meme then, but apparently they thought it was some form of cyber-terrorism.
- koboll 5y agoA good buddy of mine did the same, but with the message "DOOM!" His punishment was community service, and the service was having to be basically an intern for the school IT guy. Smart administration, really.
- saltyfamiliar 5y ago
- ilaksh 5y agoIt's not hacking if you have ssh access. I missed the part that explained how they got that.
- 1024core 5y ago> In fact, he thanked us for our findings and wanted us to present a debrief to the tech team! This is the only acceptable response.
- sneak 5y ago> With that said, what we did was very illegal, and other administrations may have pressed charges. We are grateful that the D214 administration was so understanding. Note well that the victim of a crime does not get any say in whether or not a prosecutor prosecutes a crime. "Pressing charges" is a myth. The prosecutor decides. Period.
- novok 5y agoThe probability of a prosecutor filing charges decreases significantly if the victim does not want a case to go forward, and even more if they actively do not want to cooperate with the court case.
- sharmin123 5y agoFacebook Safety Tips: Take Steps Now and Avoid Hacking: https://www.hackerslist.co/facebook-safety-tips-take-steps-now-and-avoid-hacking/ https://www.hackerslist.co/facebook-safety-tips-take-steps-n...
- jerrysievert 5y agowhen I was in high school, we had been battling on the pdp11 (running rsts), and when they finally upgraded to vax/vms they just gave up and gave us a small vax system to ourselves to battle on. it was much less disruptive than the hijinks we had previously been up to. of course, this was in the days when pad-pad was a thing out in the real world, so false logins on vt100/vt220 terminals was all too easy to fake. I am still thankful that they decided to set that up (we even had physical machine access) - such a better solution than just letting us go wild on the local network.
- alexbrower 5y agoHope there was still time to amend the college applications with a link to this post.
- theshrike79 5y agoWe figured out that our computer class had a few computers infected by the Ambulance virus[0]. So of course we intentionally infected all the computers with it =) On the other hand me and a few of my friends were the only computer literate people in the school and were tasked with removing it in the end. But still, it was fun seeing a whole class of computers have an ambulance run at the bottom of the screen with the poor beeper emulating the siren. [0] https://en.wikipedia.org/wiki/Ambulance_(computer_virus) https://en.wikipedia.org/wiki/Ambulance_(computer_virus)
- dfox 5y agoEarlier versions of Intel Management Engine used ARC core. It is somewhat funny to see Intel licensing third-party CPU IP core to use in their CPUs of all the things…
- gareiner 5y agoI do really wished that my school wasn't strict and I'm allowed to tinker with my ideas in my school.
- ElFitz 5y agoFellow high school students just loved me when, after giving up on ophcrack, I found out that on Windows XP, a limited account could simply escalate privileges by scheduling a command. First installed some open source FPS on all computers. They got found and removed, and we all got moved to guest accounts. I then found something called DreampackPL. Just pop in the CD, boot on it, replace the pinball game with their executable, reboot. And voilà, access to everything. Just remember to put the pinball back afterwards. That’s when the BIOS got password protected. My next step? Opening the machines up to move a jumper. Do everything all over again, but this time on a hidden windows account. The IT admin was a student’s parent. Just spent years making the poor guy run in circles before the school administration finally gave up.
- lyian 5y agoI remember in my school days we all used Windows, but the teacher/admin administration software, the school bought was pretty cheap. The administration tool allowed teachers to stop students from using for example the mouse or keyboard, was written in Java and was installed on all computers as a service. My favorite part was, that the installation setup of the whole setup was laying around on a random network drive. Being naught little script kiddos we started to dump the code an voilà no authentication or checks who is actually sending the commands. This resulted practically us, locking the teachers and even the admins out. Aaaah, good times...
- pkpioneer 5y agoLG is acquiring automotive cybersecurity startup Cybellum in a $240M deal: https://pkpioneer.blogspot.com/2021/09/lg-is-acquiring-automotive.html https://pkpioneer.blogspot.com/2021/09/lg-is-acquiring-autom...
- Timpy 5y ago> I used a loop of the DVD bouncing logo to test stream quality. This is a beautiful touch, if somebody happened across his testing in the middle of the night they wouldn't suspect anything was amiss.
- remix2000 5y agoI once wrote a script that would pluck the entire student’s computer and rat them out hard in case they tried to exploit some vulnerability. Alas, no one got owned, at least not until I graduated.
- godtoldmetodoit 5y agoReminds me of when I attended my districts technical career center for 2 years. We had ~3 hours of various IT learning every morning with kids from high schools all over the county before we all went back to our normal schools. We'd of course run out of stuff to do and start messing around with our newly honed skills. Learning about net send wasn't too bad, we just sent dumb messages to each other. But learning vbscript combined with net send... you could DoS the other machines with a for loop. One morning I was playing around with the net send script, but accidentally plugged into the schoolwide LAN instead of our local network... every computer in the building got locked down with some idiotic message my 17 year old brain had come up with. IT took a educated guess and came down to our class and I fessed up, thankfully they let me off with a stern talking to and promises to never do it again.
- treszkai 5y agoThese devices were unsecured for a reason: there wasn't money to hire competent people who would make all services secure. Finding a vulnerability in the grade tracking system is much different than in IPTV: the first can have real-life implications, the latter only gives the attacker bragging rights. Only students would benefit from hacking IPTV (for funsies), but patching it requires funds nonetheless, and then further effort from staff when the default user/pass doesn't work. And then we complain about the hidden costs of low-trust societies. If the guy had written to the admins about it, they probably would've replied "yeah we know about it, please don't do it". "But I want to because I can and you're too lazy and incompetent to fix it." "Okay then here's 50 bucks, please fix it for us, we don't have time for this nonsense." "F off", and then proceeds to rick roll because that can get him to HN front page.
- pgcm1 5y agoThis article was great. If you want to understand the IoT better, I can recommend this article: https://girlsplaining.substack.com/p/internet-of-things-and-smart-cities https://girlsplaining.substack.com/p/internet-of-things-and-...
- CountDrewku 5y agoUgh. I worked school IT in the past. You're not as smart as you think you are. These vulnerabilities are typically known but there's not enough time, money, or the devices themselves can't really be locked down or hacker proofed anymore than they already. IF you do something like this at least consider that someone else is going to be cleaning your mess up. School kids are the worst users you can ask for. Unlike a normal business where they'd be punished or removed for something like this the kids will deliberately try to destroy the school network.
- mingusreedus 5y agomy old school used this old as hell system using two solaris servers that we would connect to via thin clients. i got root creds to everything in our school district and on my very last day at that school i decided i'd do everyone a favour and at least update the system from firefox 3 to firefox 12. well, shortly after installing the package everyones clients stopped responding and that's the day i learned about dependencies. everyone kind of knew it had to be me that screwed everything, but nobody said anything and they were grateful to have gotten rid of that horrible old system. Unfortunately they decided to replace it with windows now, but my little brother is doing a great job keeping the people managing that new system on their toes ;)
- mwcampbell 5y agoI wonder how they managed to achieve perfect synchronization across the whole district, or even between IPTV players in one school. Sure, maybe that ability is built into the IPTV system, but I wonder how it's done. Did the players all sync their clocks from a central server, pre-buffer the stream, then start playing when the local clock hit a certain time?
- sleepybrett 5y ago'white hood hacker' ... that has .. klan connotations.
- begueradj 5y agoseriously scary stuff, than you for sharing
- elymar 5y agoPool on the roof must have a leak.
- charcircuit 5y agoI had a teacher say that if I knew the root password to the machine students tested programs they made on that I didn't have to take the final. Little did he know the kernel was old and had a privilege escalation vulnerability. I ended up leaving a note about it on the back of my final exam.
- unwind 5y agoCool, I guess, but "scary" and as always a bit obnoxious to read about for me. Anyway, it was fun to learn about the "obscure ARC architecture" used by the IoT devices in question. Unpacked to "Argonaut RISC Core", that made me curious enough to look it up since I hadn't heard of it. And sure enough, it was related to Argonaut as in "the UK game developers founded by Jez San" [1]. That's a really interesting development! :) [1] https://en.wikipedia.org/wiki/Synopsys#ARC_International https://en.wikipedia.org/wiki/Synopsys#ARC_International
- michaelmior 5y agoMuch less exciting, but when I was in high school I discovered an unsecured messaging service that could be accessed via a Web interface. This included the ability to send messages to any user logged in to any machine. And also the ability to broadcast messages to all machines in the school. I was never bold enough to test this feature but word got around after I showed a few friends and eventually someone decided to broadcast a rather crude message about our principal. One thing this student didn't realize is that all messages are logged and the sender was easily found and disciplined. It could have been a lot of fun if schools in the early 2000s were as well-connected as they seem to be now. We were still working with overhead projectors at the time.
- nedt 5y agoWhen I was in school we were trying to improve the IT, but as we "knew too much" and prefered Linux over Netware we weren't trusted. Also everything was run by the teachers, we didn't help either. Each summer they "improved" security and in less then a week we again had all of the important passwords. Even the one of the top sysadmin - which really was the one he told some students when he was trunk (everyone thought he was joking). We didn't prank, but instead installed Duke Nukem on the Netware login drive or enabled internet access when the teachers weren't around or didn't want to give us access.
- hills3523 5y agoHi Viewers, I am a computer wizard and INTERNET hacker. Get your Blank ATM card that works in all ATM machines all over the world.. We have specially programmed ATM cards that can be used to hack ATM machines you can withdraw $5000 daily without been caught.. we are also specialize in hacking and upgrades of course contact for more info smoothhackers006@gmail.com Whatsap +16572677149