12 ms·
My FBI file was for hacking into my school district's AS/400 that handled my school's attendance and grading system. Somehow using a public IP address with no
by torpid 5y ago
My FBI file was for hacking into my school district's AS/400 that handled my school's attendance and grading system. Somehow using a public IP address with no access restrictions allowed a clear telnet path in from home. Compounding username and passwords that were all the same for every employee. I didn't change a thing, just LOLed and told someone. Bad mistake.
This was the late 90s.
Oh well, 2 week suspension and kicked off the computers for less than a year. A nice conference with FBI, police, my parents, IT and school administration. Fun times.
I learned my lesson to not talk about such things because their egoes were too fragile.
When they decided to give students in their website design class ftp accounts on the district wide web/email server running an ancient version of Debian, they didn't disable the shell, just added a login script to a menu for pine, etc. for people who telnetted in, which I'm sure the sysadmin was proud of. However, a few fast CTRL-C's broke out of his script menu loop and got me a shell, and they didn't shadow protect their password files. Ran it through john the ripper and had half the district's e-mail passwords in a default dictionary file including the root pw in a few minutes. LOLed and never told anyone about that.
Good times, the 90s....
- namrog84 5y ago> I learned my lesson to not talk about such things I like how you shared how you learned lesson to not share mischievous activities with people in the same post you then go and share more things you haven't been caught for. This is going on your permanent school record! /s That's great. I know even as of recent of 2021 I've seen some places that had 0 security on things.
- JumpCrisscross 5y ago> I like how you shared how you learned lesson to not share mischievous activities with people in the same post you then go and share more things you haven't been caught for American public schools are quite adept at teaching distrust in authority, particularly in bureaucrats. That doesn't mean distrust in everybody.
- _-david-_ 5y agoThe American public school system likes to teach that they are an authority that should be trusted.
- littlestymaar 5y agoThat must be reverse psychology. /s
- anikan_vader 5y ago> American public schools are quite adept at teaching distrust in authority, particularly in bureaucrats. It's an important lesson to teach kids while they're young! Strange, though, how you never see it on the formal curriculum.
- pixiemaster 5y agoit’s a hidden lesson, only for privileged kids.
- 908B64B197 5y agoHow is that a lesson for privileged kids only?
- authoritawayu 5y agoBecause in the United States, unprivileged kids often get thrown into what we call the "school-to-prison pipeline" for inconveniencing authority figures. Unfortunately, they end up learning a different sort of hidden lesson.
- deleted 5y ago[deleted]
- Tr3nton 5y ago
- dylan604 5y agoanother thing probably learned is statute of limitations!
- cgriswald 5y agoI think this is especially prevalent in schools. You'll see things like this even for things that aren't related to computers. When I was a kid, drugs in your locker were your drugs, even though breaking into the lockers was trivial and stashing drugs in other people's lockers was the way business was done. I wouldn't have told the school of a theft I witnessed even if I knew there were cameras recording the entire thing. You're guilty unless you can prove someone else was more guilty and they're not really concerned about the truth of the matter so they're not trying to help you.
- dheera 5y ago> I didn't change a thing, just LOLed and told someone > Oh well, 2 week suspension God damn, these idiot school people have no fucking clue that someone who points out a security flaw to you without inflicting any harm is actually doing something good, and that behavior should be encouraged and rewarded.
- gojomo 5y agoBRB, preparing my YC S22 application: "BugBakeSale" "We're bug bounties for America's school districts: HackerOne for the K12 market. The product is free if you let our corporate partners, who also fund the bounties, recruit the winners."
- trulyme 5y agoThis is actually an awesome idea, because everyone wins. Well, except school districts who have more work. ;) I hope someone creates this.
- 77pt77 5y ago> and that behavior should be encouraged and rewarded He gave the reason why, fragile ego.
- lokimedes 5y agoI had sysadmin rights on my school’s Windows servers after some very simple social engineering (for a 10 year old). The real irony was that I was called to the principal’s office on multiple occasions because I seemed to be able to fix things on the network that the local “admin” (e.g. music teacher) couldn’t. Fun times indeed. It completely ruined my respect for authority figures. Which in retrospect has been the most valuable outcome from being the local “that kid from Wargames”
- RotaryTelephone 5y agoHad a similar problem with feeling betrayed by authority figures when I was called in to be questioned about a hacking incident while in middle school just because I was good at VB in programming glass. Can really ruin a kid's confidence for years to come in case anyone in such position is reading this now.
- gilbetron 5y agoSame thing happened to my friend in high school, there was someone causing some mischief with some of the school computers, and just because he was into BBSs and computers, he was a big suspect, but he was a good talker and was able to avoid any punishment. He was a good friend because he kept silent about the fact that I was the one doing it ;)
- nefitty 5y agoI can point to several false accusations I suffered as an elementary school student that made me deeply skeptical and wary of authority. "Even if I color in the lines, or intentionally dabble in creative thinking, some adult might yell at me... Hm. I don't need their permissions. They obviously don't see how great I am so they are a dumb nuisance."
- 908B64B197 5y ago> It completely ruined my respect for authority figures. It sounds like they were right to trust you? Doesn't sound like you ever did anything bad with admin credentials. And you even used it to fix stuff.
- partiallypro 5y agoI had two friends that did similar in the early 2000s, except that while the school knew there was a breach, they never caught who did it. Had all student social security numbers, grades, attendance, etc pulled into a thumb drive on the school network. I imagine this happened a lot around various school districts, especially in that time when school networks were less secure.
- fnord77 5y agojust curious - has this ever shown up on employer background checks?
- torpid 5y agoNever been an issue for me. I was never charged with anything state or federal.
- 0xbadcafebee 5y agoI was punished three times for computer curiosity before I learned my lesson. No good deed goes unpunished, especially when it makes somebody powerful look bad.
- avgDev 5y agoThis reminds of a Costco bug I discovered, it appears that they fixed it lol. So, Costco runs AS/400 in stores, and their online store is in .Net MVC. I worked with both technologies and often have to communicate with AS/400 devs and they are close to their retirement so little fucks are given. Plus, working with DB2 is annoying in general, the .NET data provider from IBM is expensive and sucks. Now onto the bug, when you purchased items online at a discount, you were able to return to store at a full price as their systems were not communicating that a discount was applied. I returned several items, but did not realize until I bought a laptop that was $400 off and tried returning it. I ended up calling Costco and letting them know. Unfortunately, they didn't give me any lifetime membership or a good citizen award. If any Costco devs read this and know about this send me some love.
- windexh8er 5y agoCostco still has issues of resolving discounts on a return. I won't state the bug explicitly but I had a conversation with them about how they refunded me a significant amount I never paid on a large purchase and showed them the delta via receipts. Local management was appreciative but didn't seem to have an idea of how to proceed to make things right. Ultimately they said my account would be flagged as owing the difference so the next time I shopped I would be charged for the incorrect refund. The problem is that that didn't work either and I don't shop there often. I tried to do the right thing but ultimately it ends up being their responsibility to handle it when the customer is standing right in front of them showing their loss of revenue.
- giantg2 5y ago"I tried to do the right thing but ultimately it ends up being their responsibility to handle it when the customer is standing right in front of them showing their loss of revenue." I bought some lions mane mushrooms from a grocery store, which cost $10-12 per lbs. The cashier rang them up as "regular" (button) mushrooms at $2 per lbs. I pointed out the mistake and she tried to correct it but chose the button mushroom again. I brought it up a second time and she selected a different incorrect mushroom at a slight increase ($4/lb?). At that point, I gave up. She's the one ringing it up. I tried.
- Zenst 5y ago> I learned my lesson to not talk about such things because their egoes were too fragile. Yip, ego's and people talk are the downfall of many an innocent `self-education` in the area of IT security. Post 80's and laws started to change, prior, in the UK it was theft of electricity being the only way to nail some people. Crazy fun times. Though I do miss the old phone system per-say, outdials, wardialing, things like that, was common with many and just seemed more mysterious as you could only learn thru word of mouth or self-education as no books or internets and BBS's were not as cheap in the UK or common as we never had the official free local calls aspect as you fine folks had in the US. Do recall a chap getting kicked out of college for doing something I'd done previously, just that he had a bigger ego and not as delicate with the power to steal the admin password. Which involved an ICL George 3 OS mainframe in the times of very large disc platters and admin console journaling that had no encryption. so they rotated discs without adding extra wear of zeroing the previous content, only the file table so you could end up with a user disc platter that had formally been used as a admin console jounal reposatory and could create files without zeroing and dump the previous contents of the disc of that way...which eventually got you the admin password. Do recall few instances of work related cases in which I needed to do things so, kinda hacked what I needed (resourcefulness) like upon a DPS7 Honeywell mini computer in which needed the admin password to do something and nobody had it at hand at that time of night and the passowrds were kept in a file that was encrypted so I worked out the encryption key by looking at the file as was poor encryption and text files have lots of spaces so saw a pattern with the word OPERA in and tried and tada, got what I needed. The spooked admin next day wondered how I did it so I told him fully, he then went and redid the encryption and challenged me to see if that was secure, I looked at the encrypted file and kinda worked out by the patterning that it had been encrypted twice....yes with the same password OPERA only encrypted with that and then encrypted again with the same. Educational for all back then. Today, not as easy to do that, but still a great story of times of old. My ego prevents anything else and was an ethical hacker and the 90's was an era in which, we white hats would and was the internet security, bringing down pedo's and bad actors like that that frequented some platforms with ease (looking at you AOL). So whilst illegal per-say, was case of no real official policing of such things as we do today. But darn, some things learned and worked out, well zero day exploits back then were not as financially economical as they are today and heck, and some never really appreciated how long they would stay obscured from the wild. I also liked hardware back then, was also fun and many a hidden switch to get a feature you would normally pay silly money for some engineer to `install` though was just some hidden switch was not that uncommon. Heck even today you get kit that is same inside with a model up just adding some small thing and example would be some Fluke multimeters that you effectively pay hundred for a small capacitor and another digit on the outer shell, is a good example current today. Fun times indeed, but darn, goalposts always moving.
- loup-vaillant 5y agoSeriously, they would have deserved that the school mysteriously becomes littered with printed (or typed) sheets of paper explaining how to access the system and change everyone’s grade. If it were me, for the second time I would have considered adding a file to everyone’s FTP account (including the admins & professors themselves) explaining how they too can escalate to root.
- twox2 5y agoGood times indeed. I got into similar mischief, but my school didn't really mind. I got a slap on the wrist, because they were to prestigious to court negative attention. Then I got into similar shit in college. I reported it and got lucky again. The guy in charge of their cybersecurity program invited me to take his class which was all master's students and phd candidates as a freshman. I would have bombed as it was all over my head cryptography/math, but at the time I did some extracurricular research that got me a passing grade.
- IggleSniggle 5y agoI’ve been on the other end of this dynamic. It’s really incredible what you can accomplish by providing someone with a passing grade.
- empressplay 5y agoLate 80s and my junior high school computerized attendance reporting (and some grades) through shared documents on a 'teacher' Appletalk share I had access to (because I set it up!) Well now... ;) Honestly though I never did any of that sort of thing for profit, I managed to satisfy my needs selling disks with games on them and then turning a blind eye when people were playing them during class hours (I was basically used as a free labour resource by the school so I don't feel bad about that in the slightest.) Ah, the things we did when we were teenagers...
- technothrasher 5y ago> I learned my lesson to not talk about such things because their egoes were too fragile. At my university in the early 90s I went the white hat route and had tons of fun. I managed to convince the computing center folks to give me a student job in the Unix group, and then spent the next three years hacking their systems and getting a pat on the back when I did it.
- hermitdev 5y agoI was in junior high early 90s when I got into trouble with my school's networks. Setup was Novell Netware, DOS 6.x. I was never a Netware expert by any means, but by that time I'd been using DOS at home for quite a number of years and knew my way around pretty well. Anyways, the network crashed. I got accused of causing the crash because a teacher had seen me with "a black screen open", aka a DOS prompt. Our Netware setup didn't allow for direct DOS access; we had a limited set of DOS apps from a menu we could run. Well, among those apps was WordPerfect for DOS. There was some function key combo that'd suspend WordPerfect and dump you at a DOS command prompt (I forget the key combo, but we all had those keyboard templates at the time that listed out the various commands helpfully, right in front of you, at school, even!). Well, being at a DOS prompt was enough circumstantial evidence for me to get suspended for a week (no FBI record, AFAIK). My parents, despite being strict, were also fair and asked me point blank, "Did you have anything to do with what you're being accused of?". Told them no, I was just at a DOS prompt (probably to play either nibbles or gorillas - those classic BASIC games). To their credit, their opinion was if I was going to serve the time, I might as well know how to do the crime (know, not actually do). I had already been tagging along to continuing education computer classes my mom was attending, but my parents started buying me more and more computer books. It got me started down the programming path. I'd already been pretty friendly with our sysadmin at school and he knew I had nothing to do with what happened and hadn't accused me, but the school needed a scape goat, and I was it. He felt bad for me and choose to help me out with my learning, too, instead of continuing the punishment. He gave me a copy of the software he used for after hours remote access over direct dialup. Think it was called Carbon Copy? It was basically just telnet over dialup that allowed me direct access to his PC on the network after hours before I even knew what telnet was. So, I'd connect after dinner and play around for hours as network admin. It wasn't multiprocessed, so I had to be patient. Typically when I'd log in, he was running a nightly backup manually that he'd kick off before he left for the night. I just had to wait for it to complete, then I could do whatever I wanted. I had full access to the grading/attendance system. I could message teachers as other teachers, etc. I could have granted admin access to anyone, but I was smart enough to never touch my own account, instead, created fake admin users and used those, instead. I'd hide files in plain sight using the ALT+255 trick to embed a nonprintable character in file/directory names. You could see them, you just couldn't directly access them without renaming them for most programs. Fun times. I never did anything destructive, though I could have easily. Security in the 90s was a joke. They were good times, indeed :) I continued my shenanigans into college. College was my first encounter with Windows NT networks & l0phtcrack. I remember one night, walking into my dorm room with the SAM file from a lab PC on a floppy. I popped it into my own PC, started cracking the passwords, expecting it to run all night. As I got up from my PC to head down for dinner, I was surprised to see that I'd already cracked the administrator password. It was just a 5 character password that was the building code & room number for campus IT. I already knew better than to do anything from my own PC, only ever worked from different lab PCs in different buildings and under assumed accounts. Never reported anything, either, for fear of reprisal.
- andai 5y agoWhen I was 11 or 12 we had a bunch of old Windows (2000?) boxes with a shared network folder — all the students' files were in the same folder. I had just learned about basic batch file "programming" so I made one called Change Your Grades Click Here!!.bat which asked for your username and password (we had individual accounts on the Mac computers) and saved them to a hidden text file in the same folder. Most people didn't fall for it, but I got one girl's login that actually worked, which scared the shit out of me, and I deleted the program. (I really wanted to tell her that "emma" is not a good password, but I thought it wouldn't turn out well for me.) A few years later, I cracked the admin password (with a Ophcrack live USB) for a silly reason: they had the machines mostly locked down, and I wanted to change the desktop background hahah. I remember being quite disappointed in the sysadmins that the admin password for all the machines in school was a common dictionary word, cracked in 30 seconds. Oh, once I met a guy who identified as a "hacker" (in the sense of breaking into systems illegally) and he told me (then a young teen) to "have my fun" before I turned 18 and then to stop, which in retrospect was very good advice.
- vagrantJin 5y ago> I got one girl's login that actually worked, which scared the shit out of me, and I deleted the program. (I really wanted to tell her that "emma" is not a good password, but I thought it wouldn't turn out well for me. With all due respect for HN policy of nuanced, Intelligent debate. "Wimp"
- hutzlibu 5y agoDid you ever had the courage to tell, that you lacked courage, once?
- vagrantJin 5y agoAt least a few times a week. Wimping out is par for the course.
- rootsudo 5y agoAh yes, grabbing the SAM file. That's still a valid attack vector if local admin password rotation isn't in play.
- BLKNSLVR 5y ago> because their egoes were too fragile If anyone else reading can learn vicariously, this line is almost universally true and manifests itself in a multitude of ways.
- stank345 5y ago> they didn't shadow protect their password files Could you please explain what this means? Googling didn't reveal much.
- pmw 5y agohttps://en.wikipedia.org/wiki/Passwd#Shadow_file https://en.wikipedia.org/wiki/Passwd#Shadow_file
- jll29 5y agoThe UNIX family of operating system (Unices) historically stored passwords in /etc/passwd, which was readable (but passwords were soon hashed, i.e. passed through a one-way function to obfuscate them). Eventually, shadow passwords were introduced to have the passwords themselves stored in another place with stricter access rights (readable only by the sysadmin or their group), so even the hashed versions were inaccessible to normal souls, whereas other information traditionally kept in /etc/passwd - e.g. the user's full name - could and can still be retrieved from that file by making it widely readable - just without the passwords, which were moved to the "shadows". See also https://en.wikipedia.org/wiki/Passwd https://en.wikipedia.org/wiki/Passwd, section "Shadow file" for more details.
- torpid 5y agoDebian even back then did protect the passwd files appropriately out of the box, but in this server's case, they did an import from an older system where it wasn't protected, and they couldn't figure out how/bothered to convert it to shadow.
- pbhjpbhj 5y agoI always thought the shadow was just a way to refer to a hash -- the shadow of a thing being less detailed/unique but still capable of being used for recognition. Maybe I read Plato around the same time as I heard of it and that biased my thinking.
- lr1970 5y ago> Could you please explain what this means? Googling didn't reveal much. An classic UNIX /etc/passwd file is readable by all local users and in the past used to contain the password hashes. One can download these hashes and crack the passwords offline. At some point the problem was recognized and password hashes were moved to special /etc/shadow file which is accessible only to root and members of shadow group making /etc/passwd useless for extracting passwords.
- deleted 5y ago[deleted]
- dfgjdfgjjdfg 5y agoWith all the shenanigans I was into as a turn of the century high school student, I'm incredibly lucky to have never had a (known) FBI run-in. At my first high school I was expelled for selling teachers a boot floppy that disabled the district's security software (Fortress) on their machine. At my second high school I was busted twice, once for selling CDs with a much anticipated unreleased movie, and the second time for finding (and copying) a network share that had every student's school photo from that year before they could even purchase it. Nevermind all the unsavory nonsense I did outside of school and was luckily never busted for.
- alana314 5y agoouch. I once tried to grab a password file remotely that made the whole computer network crash for some reason. They found out it was me and they said, "please don't do that again." I was really lucky.
- xyst 5y agosadly, security hasn’t changed much since then
- knodi123 5y agoI cracked all the passwords in my MS-DOS based computer programming class by modifying the boot floppy. It was pointless since the assignments were easy and I had perfect grades in that class, and the only thing this allowed me to do was steal other peoples' homework. But eh, boredom.... I also figured out how to auto-crawl the networks of all the schools in our district, which, as a self 15 year old whose only experience was non-networked DOS, is still a proud accomplishment. The only things I found were a bunch of printer management, some office form templates, and a cool video game that was like sim-moonbase. But then my teacher found the file in my home dir called passwords.txt, and I was busted. Oh well. Instead of an FBI file, I got a detention, and I had to teach him how to write-protect the boot floppies so no one else could do what I had. (he didn't need to know that you could reverse the write-protection with a piece of electrical tape)
- democra 5y ago>I learned my lesson to not talk about such things And yet here we are, talking about it.
- torpid 5y agoA quarter century later, statute of limitations expired, systems long gone and replaced with entirely different vendors/technology, nobody cares except you.
- xjlin0 5y ago> they didn't disable the shell, just added a login script to a menu for pine, etc. Very fancy, everyone was using elm and you got pine.
- sandos 5y agoOh yes. I remember the embarrassment / horror of having the admin just creepily poking my shoulder when at the computer and gently saying: "Hey, I promise I will NOT report you for antyhing, if you just tell me what the hell you just did with our network!" I had no idea what I had done, honestly, I just sent a large ping packet to some IRC-user. Turns out it killed some vital things in the network. Also the admin leaving anonymous FTP enabled with write access. That was one weekend with an extreme amount of illegal stuff apparently uploaded via the schools FTP, but that was my classmate which was involved in and not me. This was at the time when people had dial-up at home so the 256kBps connection at school was awesome.