4 ms·
Seeing as we're sharing our fun and games... When I was at college back in the 80's we had access as students to the college's VAX 11/750 (an 8750 Systime clon
by teh_klev 3y ago
Seeing as we're sharing our fun and games...
When I was at college back in the 80's we had access as students to the college's VAX 11/750 (an 8750 Systime clone) to work on our coding projects. The student terminals were on one half of a large divided room, the other half being used by the college IT folks. Often, if there wasn't a spare terminal on the IT admin half of the room, one or two of the IT folks would use two of the nearest terminals just over the divider.
One day, bored out of my mind waiting for my COBOL project to compile, I wondered if I could capture the sys admin's username and password. I wrote a script using the CLI to perfectly simulate the login prompt complete with beeps, messages and all. All it did was clear the screen, sit there waiting for user to enter their username and password, when they did the script would mail me said username and password, display a username/password error then logout to the real login process.
After trying the script out on a couple of unsuspecting classmates and having a bit of anonymous tomfoolery I decided it was time to try this out for real with the sysadmins. I logged into both terminals the IT folks normally used and left the script running. A few hours later I returned and to my surprise and mild anxiety I found out that I'd captured the SYSTEM login password :o. For about a month or so I'd full control of that machine, and would re-run the script occasionally whenever the SYSTEM password changed. I told no-one and on my last day at college logged in and deleted the script, just in case (this was around the time the law in the UK was getting a bit heavy with regards to unauthorised computer access).
Combined with access to the huge set of manuals for that machine I spent a heap of time exploring and learning about VMS and no-one had a clue.
- 0x6c6f6c 3y agoThis is great. Reminds me of the BASIC program I wrote on my Ti-83 to simulate the memory reset process for algebra tests because our teacher walked around and would run it himself. Big surprise now I program for a living.
- teh_klev 3y ago> Big surprise now I program for a living. Oddly, me too :)
- samch 3y agoFun fact: Login spoofing like this is why, from Windows NT on, users have had to first enter a security context with Ctrl+Alt+Del. https://en.wikipedia.org/wiki/Control-Alt-Delete https://en.wikipedia.org/wiki/Control-Alt-Delete
- gumby 3y agoan approach that goes back the the rainbow books, at least. There was some scheme to use the "break" key on the teletype for this (maybe in Multics, or OS/360 perhaps?) but I have no idea if it was ever implemented. For those who don't remember, "break" was not an ASCII character but a literal long unmaskable pause in transmission, and couldn't be generated in software or by reading the paper tape punch, nor could it be read on the host side into an input buffer as it wasn't a character.
- TimTheTinker 3y agoIn MS-DOS, Ctrl+Break could be simulated through ASCII character 0x03. Literally, hit Alt+3 and it would respond the same way. The sysadmin for my high school computer lab had written a text-mode DOS login screen that would start Windows 3.11 for workgroups after the user logged in. A few of us kids figured out we could just Ctrl+Break out of it and install/play DOOM, Descent 2, etc. He wised up and wrote a trap for the Ctrl+Break sequence, but I discovered the Alt+3 trick and we continued on our merry way. I don't think he ever figured out how we did it. (We also hid our games inside a directory named Alt+255, which appeared as a space. A single space was not allowed as a directory name, so it felt like magic to us.)
- chx 3y agoHa yes, name your TSR keylogger REMalt+255.COM , put it into AUTOEXEC.BAT , it looks like an innocent comment.
- eichin 3y agoThe magic words being "Secure Attention Key" (on multics in particular, it was specifically caught by the Front End Processor, so nothing in the OS could interfere by (for example) catching the signal and printing a fake login prompt, becauase it was literally a separate computer handling the request...)
- gonzus 3y agoThis seems like a rite of passage... I did the same thing with the VAX at my school, but decided to come clean and gave the sysadmin all the passwords I gathered after one day (including several with SYSTEM privileges). They gave me my first job :-). I also made sure to grant the necessary permissions to one or two obscure accounts, so that I could regain SYSTEM when it was revoked on my "official" accounts. Fun times, and innocent too -- I never used the privileges to cause havoc.
- intrasight 3y agoI recall a student at CMU getting in big trouble for doing that - around 1985.
- dormento 3y agoIts funny how writing a user login replacement seems kind of ubiquitous for all future hackers. Mine was in Visual Basic (5 iirc) for a Windows (Novell?) network. This was back in school. You could trivially change win.ini to set it up to run _before_ the real login screen. Mine would save the username and password to either a shared network drive or a local file, then display a "password error" and exit to the real login prompt. What got me in the end was that a "friend" used the same trick and started copying peoples files from their network account to his own. My suspicion is that when he eventually maxed his quota, the system must've warned the network admin... a cursory look would later reveal he copied some teacher's thesis files, and that was a big no no. Eventually this incident would land me my first computer related job as a junior tech support/network admin.