19 ms·
Youth expelled from Montreal college after finding security flaw
- denzil_correa 14y agoI beleive Skytech should hire this bloke for a "and they lived happily ever after" story. It's essentially a win-win for Skytech.
- mvzink 14y agoMaybe, but I hope Ahmed is more ambitious than to work for a company he condemned for "sloppy coding"...
- denzil_correa 14y agoAhmed could probably lead the charge to turn around "sloppiness". Besides, his career seems to be in doldrums currently. I don't think it would be a bad choice. FWIW, he might be able to use the same testing software on Skytech's products for which he has expelles at Dawson's. That would be a comeback of epic proportions! On a serious note, can't he appeal to any education monistry outside college?
- phaus 14y agoAfter the way this was handled, I'd live in a cardboard box before I worked for this company. You can't have a healthy working environment without trust. I'd give it a shot if they fired their president, but that's an unrealistic expectation.
- denzil_correa 14y agoDo you think there is a chance that the university over reacted without the company in loop?
- phaus 14y agoThe president of the company is the one who allegedly intimidated the student into signing a NDA by threatening to call the police and have him arrested. If that's how it happened, then it's irrelevant what the school did.
- denzil_correa 14y ago> The president of the company is the one who allegedly intimidated the student into signing a NDA Missed that part - now it makes me think back on my suggestion. Probably, he should just look around on HN. :-)
- deleted 14y ago[deleted]
- denzil_correa 14y agoApparently, he's been offerred a job from Skytech! http://news.ycombinator.com/item?id=5090108 http://news.ycombinator.com/item?id=5090108
- eigenvector 14y agoEven aside from the fact that he was acting in good faith and did not cause any damage to persons or property (as acknowledged by the software vendor), the procedure used to expel him is woefully lacking. I sat on the highest student discipline tribunal at my (Canadian) university and an expulsion for non-academic reasons - which had to receive final approval from both the President and the Governing Council - would only be recommended in cases involving egregious and likely criminal misconduct and only after the courts had found merit to the allegation. Furthermore, any student faced with potential expulsion would have been entitled to a series of quasi-judicial hearings and assistance in preparing their defence. To expel someone for non-academic reasons from a publicly-funded institution (which Dawson is) should not be taken lightly and surely never in a fashion where the accused is not permitted to present their case.
- gpcz 14y agoIt was also really crappy cover-up strategy on the school's part. By refusing due process to Al-Khabaz and expelling him with zeroes for his last semester grades, Al-Khabaz now had nothing to lose exposing both the security flaw and the injustice to the press. If they didn't play all their cards at the same time (like putting him on probation or something), he probably wouldn't have gone public.
- purephase 14y agoIn all honesty, it is all of these reasons that make me believe that we're not hearing the entire story.
- contingencies 14y agoShame on the faculty! Fire the faculty! I am sure this sort of thing wouldn't fly in France. Looks like Quebec is letting down the Fracophone team. Liberté, Égalité, Fraternité!
- deleted 14y ago[deleted]
- rtkwe 14y agoDo you mean the dean who ran the judicial hearing? If anyone were to have their heads roll so to speak for this it would be his. The faculty that voted were simply acting on the best information which was presented to them.
- contingencies 14y agoPeople who are supposed to be the shepherds of an environment that fosters free-thinking openness, curiosity, creativity and learning should not lend credence to witch-hunts. If they have a critical-thinking faculty to match their titles, then they should very well have realised that the process they rubber-stamped was one-sided and questionable.
- john_fushi 14y agoThis is superficial and I probably shouldn't answer to this but anyways : Dawson is, in fact, an english college.
- jbm 14y agoClearly the negative reputation Dawson CEGEP has should be applied to the administration, and not the students. What a clusterfuck. Since when do CEGEPs expel students for running security checks?
- kennywinker 14y agoThere really needs to be legal protection for acts of white-hat hacking like this. Both protection from prosecution, and protection from reprisal. This kind of stuff isn't going to stop happening unless the act of finding and reporting a security vulnerability becomes legally protected behaviour.
- eru 14y agoPerhaps the existing whistleblower protection could be used here?
- jahewson 14y agoThe problem is the that would provide a legitimate cover story for black hats. "Oh I was just doing a white hat scan".
- freehunter 14y agoHere's the thing: black hats are always scanning you. Where I work, a fairly low-key place, we're currently being scanned on some of our ~100 Internet-facing IP addresses with a frequency of 15 requests per second. This is nothing uncommon. We get people on our guest network scanning us from the "inside" as well (they think they're inside, at least. They have a 10.x.x.x number, they're inside, right?) Point being, if you can't hold up to a white hat scan, you're likely already hacked. Security is how you enforce your policy. But it's only white hat until data is compromised, and that's where the prosecution comes in.
- rwallace 14y agoThat's not a justification for punishing white hats. In the meantime, until we can make this understood, we need to make the workaround understood: if you find a security flaw in a system you don't own, and you haven't been formally hired for the specific purpose of finding that flaw, ignore it and get on with your life; it's not your problem. Going out of your way to help people in normal circumstances is noble. Going out of your way to help people who will reward you with a knife in the back is a mistake. Don't make that mistake.
- kirillzubovsky 14y agoI love the part of the story where the guy naively assumed that it would take his school less than two days to fix the vulnerability. In reality, would probably take them months. How long did it take sony to fix their issues? Oh, right, it took someone to explose it publicly. Heh. It's unfortunate how broken some IT organizations are and that they would rather kill the messenger than fix things.
- chii 14y agoits apathy. The people "responsible" for the service don't actually care, and perhaps probably won't be punished for teh failure of the service. Hence, the vulnerability (and the publicity) only makes more work for them - therefore, they shoot the messenger as a form of blame/revenge.
- LatvjuAvs 14y agoIt involves more or less humongous amounts of pre-meetings, meetings, post-meeting, legal documents, reviews of meeting, implementation strategy, review of implementation, certificating/accepting, post-... You got the picture. In big companies it might take some time. Essentially is is very broken system that destroys itself. It is like you need a manager to watch over a manager that watches over a manager. It is funny to work at such companies, I got fired from one when I said everything I think about them.
- dade_ 14y agoAnd meanwhile, the student data is at risk on the Internet. Every org needs a better plan then that, especially when change management takes weeks/months and this requires immediate action.
- jrockway 14y agoI found something like this at my school. The administration reacted similarly. But fortunately, I was taking djb's Unix Security Holes at the time, and a harshly-worded note from djb to the Computer Center folks ended up getting me a thank you. Next semester, though, I refused to sign the new AUP (which included a clause allowing the computer center staff to seize any computer I was using, even at my off-campus home), and they kicked me out of school. (Actually what happened was they locked my course registration account, and wouldn't reinstate it until I signed the policy in their presence. I refused.) (Sadly, I can't find the full-disclosure thread for this bug. I guess I posted it to my blog, which I deleted after being threatened by school administrators. Oh well. That was 9 years ago!)
- tptacek 14y agoDid you pass that course?
- jrockway 14y agoI got a B. The homework was to find and write an exploit for 10 security holes in deployed software, but I only found 2. (3 including the one above, which I must have found the week or so after exams. The holes I found were in nasm and in some amateur open-source smtpd.) FWIW, the exams are quite thought-provoking nearly 10 years later, here's a link to them: http://cr.yp.to/2004-494.html http://cr.yp.to/2004-494.html
- bhickey 14y agoThe CS faculty at Dawson (less one) should be embarrassed. This happened to me twice in college, minus the expulsion part. In the less interesting case the University sent around a form to be used in nominating student speakers for commencement. It included a drop down that was keyed off of student id. Student ids were regarded as private. The school required everyone to either buy health insurance from them, or provide proof of insurance. They had a webapp where you could report this data. The login required your student id, name, and birth date (thanks Facebook). If you visited the app after using it, the form auto-populated with your health insurance information. I brought it to the attention of the University and they took down their nomination app in a matter of minutes. In the more exciting incident, someone at Sungard called my university and asked them to have the campus police arrest me. (Edit: Quite boring, really http://seclists.org/bugtraq/2008/Jan/409 http://seclists.org/bugtraq/2008/Jan/409)
- linuxhansl 14y ago"The CS faculty at Dawson (less one) should be embarrassed." Now they are.
- mossplix 14y agoNo good deed goes unpunished
- mikeleeorg 14y agoI hope someone offers him an internship or job. It sounds like he may have a lot of raw talent.
- eru 14y agoOr at least attitude. Which transforms into talent anyway in the long run.
- phaus 14y agoSo why exactly did Tazo (The incompetent president of the company responsible for the security breach) mention "police" and "legal consequences" in his conversation if he wasn't making a threat. If you are going to be a lying asshole and deny something, do yourself a favor and deny it outright. Don't try to imply that you were just having a friendly conversation about "legal consequences" right before you solicit someone to sign a non-disclosure agreement. No one in the world will believe you weren't trying to intimidate this poor kid into compliance.
- herlifeinpixels 14y agoWhat's upsetting is the 14/15 professors who voted him to be expelled. Do computer science professors not understand the concept of white-hat hacking? Shame on them. What message does this send to other students at Dawson? Don't be curious; don't go out of your way to do a favour for the safety of your peers; keep your mouth shut and we'll hand you your degree. Someone give him a scholarship to a legit university!
- droithomme 14y ago> Do computer science professors not understand the concept of white-hat hacking? Unfortunately, if they were at all competent they wouldn't be teaching at a place like that. CS programs at minor universities are notoriously poor and staffed by whoever they could get, and it's not going to be anyone that can make decent pay working on current technology.
- herethis 14y agoDawson isn't a university. Its a CEGEP. In Quebec high school only goes until grade 11, after which most students do 2 years at a CEGEP before going on to university. It replaces Grade 12 and first year of university. http://en.wikipedia.org/wiki/CEGEP http://en.wikipedia.org/wiki/CEGEP
- doktrin 14y agoPerhaps CS is an exception, but I was under the impression that jobs in academia (in general) were in woefully short supply. While I'm sure they wouldn't get the cream of the crop, there's reportedly an excess of under-employed & under-paid PhD's and post-docs in a number of STEM fields (again, specifically in academia).
- barry-cotter 14y agoCEGEPs are kind of a combination community college/last year of high school/first year of university. They are teaching institutions, not research ones. US community colleges can demand Master's degrees but not Ph.D.s to teach. Mostly people with Ph.D.s who can't get real academic jobs exit that market, not go CC. Anyone who is actually teach a CS course at a CC or a CEGEP and who is doing it as a full time job is doing it for non-pecuniary reasons, inclusive of being incompetent but having attained a qualification sufficient to teach.
- janisjanis 14y agoHe's too good for college. He should just start his own IT security company.
- rdtsc 14y agoI've said this before -- don't bother being a "white hat". The industry and the legal system doesn't have a pigeon hole for that. You'll be labeled as "hacker" (and not in a positive sense of it). Either disclose the vulnerability immediately to get recognition, hoping it is public enough they'll be ashamed of going after you, or or sell and profit from it. You are already treated as a criminal by these large institutions, so if you go in that direction might as well make some money.
- guard-of-terra 14y agoYou can also pastebin it. That's what you should do.
- eru 14y agoPerhaps from a tor connection?
- Tichy 14y agoHow do new pastebins get discovered? I've never used the service - was assuming someone should post the link to the pastebin on Reddit?
- guard-of-terra 14y agoYes, someone should. You can imagine some fun ways of doing so.
- jlgreco 14y agoYeah, Tor->Reddit should work. Alternatively you could fire off some emails to a couple high-ish profile twitter accounts of people/groups that would be interested in taking credit for it.
- gpcz 14y agoDuring undergrad I discovered the university's blackboard-like site sent plaintext passwords over http, and the majority of its use was over wireless. I went to the IT office responsible for the site, told them about it, and refused to give my name when they asked. After reading some of the horror stories on this page, I feel really lucky that the IT department didn't go further to figure out who I was and get me in trouble. End result was that quickly afterward their site forced https on you...
- dmatthewson 14y agoLike most developers, I've stumbled into lots of security problems over the years. The first few times I attempted responsible disclosure, but that resulted in enough close calls that I simply don't report them anymore. I document them. Sometimes I might mention them to others who have an interest. I would now never report a security flaw without a iron clad set of laws in place to protect the rights of white-hats, whether we are licensed and approved security researchers or not.
- codewright 14y agoI nearly got expelled from High School and pegged with a felony my Senior year for noticing a vulnerability.
- zobzu 14y agoHappened to me in 2000 in France. Same sort of stuff. Didn't kill my career. Just went elsewhere. I guess the French education system at least had this that it couldn't ban me nationwide :)
- securitywiz 14y agoshall we all assume it was an sql injection? does anyone know what the actual vulnerability was?
- tantalor 14y agoAlmost certainly a query parameter, since he was reverse engineering their API it would be obvious. For it to be a SQL injection, he'd have to have been looking for vulnerabilities.
- nwh 14y agoWhile it's probable he found some issue with permissions in the queries, stumbling on SQL injection is easier than you'd think. For a very short period I used a completely random (any ASCII character) password generator for websites, but I quickly realised that the ' and " characters were breaking the vast majority of sites I logged in to. Plaintext passwords in a database without escaping; about the worst password storage you can get.
- namank 14y agoWho knows but I'm bound to look the way of GET URLs given that they discovered it trying to make an app around an existing system. API not validating correctly. If this is true, it will take a long time to fix.
- hn-miw-i 14y agoIt's likely to be an application logic authorization bug; the application doesn't check the context to see if it should return that info. Being web it's something silly like the student-id stored in the user cookie is used to to build the (parameterized) SQL statement. It's not arbitrary injection per say.
- tantalor 14y ago> The agreement prevented Mr. Al-Kabaz from discussing... No, it didn't, because he was blackmailed into the NDA. It's completely unenforceable. It was signed under duress and only benefited one party.
- wpietri 14y agoYou misunderstand the purpose of an agreement like that. It's not like it magically binds your tongue. It just makes it easier to sue you if you violate it. The fact that the student could win in a suit is irrelevant. He couldn't afford the time and money to fight. Before he signed the NDA, they would have had a harder time suing him. Perhaps he could have spent merely $10k and gotten it quickly dismissed. After, the company could make it arbitrarily expensive for him to fight it. If he could have eventually proved coercion (which I'm honestly skeptical of) then he would have been off the hook -- after years of stress and massive lawyer bills.
- tantalor 14y agoYou're absolutely correct, I hadn't considered that.
- mathrawka 14y agoBack in 1999 when I was a freshman in university, my school had a server for students to host their websites on and use Pine for email. The server did not give shell access... but then there was a security hole in Pine that would allow you to run chsh. So I did that, and got shell access. I think the worst thing I did (other than running ls in a few directories) was use it to connect to IRC. Since I wasn't really trying to hide anything, so one of the IT guys must have seen me with shell access and reported me. My punishment was having my ethernet turned off in my dorm room (even though the incident occurred in a computer lab while the dorm's ethernet was turned not ready for use yet). I appealed the decision and met with the Dean, and she said I was considered a threat to the school so I should be happy that my punishment wasn't worse. Anyways, the rest of the year in the dorm was spent playing a cat and mouse game. I used my computer on my roommate's LAN port, so they ended up shutting off his ethernet as well.. I felt bad about that, especially since they refused to give him internet access for the rest of the year. So I ended up making a 50 foot ethernet cable and running it through the bathroom into another person's room (Two 2-person dorm rooms were connected by a common bathroom). That got shut off, so I bought a new LAN card (to get a new MAC address) and connected to another ethernet drop. I was able to get online for the rest of the year, but that sure left a sour taste in my mouth for my school. Edit: I remember one close call... over a break (I was one of the few people in the dorm), water came out of the shower drain and flooded our rooms. I came back from spending the day out to see the Dean going into our room to inspect the damage, and I quickly had to hide my 50 foot cable that went through the bathroom.
- eru 14y agoWas MAC spoofing not doable in 1999?
- sliverstorm 14y agoEntirely believable. I don't have a timeline for you, but I do know that even only a few years ago it was not ubiquitously supported.
- jacquesm 14y agoSome guy told me that it depended on the card that you used, some cards apparently had eeproms that you could reprogram without too much trouble.
- dbbolton 14y agoThe title is misleading. He wasn't actually expelled for finding the flaw; he was expelled because, after reporting the flaw, he ran an exploit program on the school's server without permission, allegedly to see if it had been fixed. Had he only reported it, he would not have been subject to any disciplinary action.
- Gigablah 14y agoSo the fact that the submission title is misleading makes the university's heavy-handedness easier to swallow?
- aquadrop 14y agoIt just means that whole article can contain more misleadings and be one-sided. Journalists... you know.
- Zr40 14y agoThe article could contain that regardless of whether the title is misleading.
- dbbolton 14y agoI didn't say anything about whether the decision was justified. I only elaborated on the reason behind it.
- vertis 14y agoStupid, but hardly deserving of expulsion. Especially given prior evidence of his character in reporting the flaw.
- Dylan16807 14y agoHe ran an exploit FINDER. He did not put exploit programs on the server.
- plouvre 14y ago
- antsam 14y agoFound a bug like this at my school and reported it a few months ago. The guy who responded to me said he'd fix it but it's still live :(
- throwaway125 14y agoI've had similar encounters with privately disclosed vulnerabilities that are still live years after the fact. What is the right course of action here? If you just wait out and the vulnerability eventually gets exploited they could blame whoever reported it "because he was the only one who knew". You can't really anonymously disclose it after privately reporting it either, because they'll quickly link it to who reported it before.
- deleted 14y ago[deleted]
- sudhirj 14y agoAhmed, if you're reading this, sorry about your college acting like idiots. If finishing college is important to you, I'm sorry they've made it so difficult. That said, please don't think this is going to end your career. There are a lot of companies and startups that would love to have you for your kind of initiative. Not having a degree that you don't seem to need anyway will not be a sticking point with them. And the option of starting your own consultancy is a possibility - you already have some publicity that can help with initial gigs. If you'd like to try your hand at a job, do check out ThoughtWorks (www.thoughtworks.com). We don't usually stand on ceremony or make a fuss about qualifications.
- vertis 14y agoI have to second this. Start sending your resume out and include a link to the story. We're a little far away (Australia), but otherwise you'd get in the door for an interview at the very least.
- chm 14y agoHe's technically still in Québec's equivalent of a US high-school 12th grade. Since he's 20, he can wait a year and be accepted to a University.
- aroberge 14y agoNo, cegep has either 2 or 3 year programs. Year 1 is equivalent to US high-school 12th grade. Year 2 of 2-year programs is equivalent to 1st year university for B.A. or B.Sc. 3-year programs tend to be terminal degree of a more "technical" nature.
- chm 14y agoJe suis au courant. Je croyais qu'il était en première année de CEGEP.
- eduardogonzalo 14y agoMy name is Eduardo Gonzalo Agurto Catalan, I am an entrepreneur in the field of IT security and a digital rights activist. i would like tohave Ahmed Al-Khabaz's e-mail or other contact information in order to contact him and discuss how I and a few fellow experts could help him. We believe it is a great injstice and that the business community cannot stay passive towards this situation which we perceive as a kind of bullying. You can contact me : eduardogonzalo@hotmail.fr
- Xcelerate 14y agoThis sort of thing scares me. One time I found a security vulnerability in a popular forum I frequented. I emailed the site owner, and he thanked me and fixed it. Later someone else discovered another weakness and used it to post spam; the site owner emailed me asking about it. My initial thought was that he suspected I was the one doing it, but it turned out he was just trying to see if I could help him. That scared the crap out of me though and I realized this was a VERY bad idea. Something as harmless as trying to help someone make their website more secure can get you more jail time than robbing a bank. I also, completely accidentally, logged into another student's account at my university (a big university too). The school gives you an ID number. Your initial password is the same as this ID, and you're supposed to change it later. I didn't remember my ID correctly, swapped two numbers in it, and ended up in someone else's account. Home address, phone number -- all sorts of information staring me in the face. Will I report this issue? Heck no! It's weird how many of these I discover by accident. My school also had a hackathon hosted by eBay and PayPal. In fact, one of the programmers from PayPal was there. During the hackathon, I stumbled upon a way to get account information without authentication (security tokens were being seriously misused). The PayPal guy was shocked and asked me to send him all the information on what I had found. Never did get any sort of reward out of that... (and I lost the hackathon too).
- slapshot 14y ago> more jail time than robbing a bank This meme of "more jail time than robbing a bank" needs to end. The federal penalty for possessing a firearm while robbing a bank is a mandatory minimum of 5 years and a maximum of life in prison. The mandatory minimum means that a judge could not sentence an armed bank robber for less than 5 years for each bank robbed while holding a gun (you don't even need to show it; just having it is enough). To make it worse, each 5-year gun sentence must run _consecutive_ with each other sentence (ie., be added on after you serve the other sentences). [1] If you brandish the gun, it becomes a mandatory minimum of 7 years, and if you fire it you get a mandatory minimum of 10 years [1]. Contrast that to all of the hacking charges we've discussed recently where the mandatory minimum is zero (a judge could sentence a convicted defendant to no penalty, or to probation). To go further, the US Sentencing Guidelines [2], which are all-but-mandatory for federal judges (there's a constitutional out, but in effect most defendants are sentenced according to the Guidelines) gives "wire fraud" a base offense level of 7 (of 42+), which gives a sentencing range of either 0-6 months or 4-10 months, depending on how much economic harm is caused. Compare that to robbing a bank, which is a base offense level of 22, brandishing a firearm adds +5 for an offense level of 27, and if you actually make off with any cash add another +2 for an offense level of 29 (of 42+). The sentencing guidelines call for a sentence of 87-108 months (7-9 years) for a first-time bank robber, per bank, assuming that nobody gets hurt---plus the mandatory additional 5+ years for having a gun. Realistically, bank robbers face a lot more time than even malicious computer criminals. [1] See section (c) of 18 USC 924 http://www.law.cornell.edu/uscode/text/18/924 http://www.law.cornell.edu/uscode/text/18/924 [2] http://www.ussc.gov/guidelines/index.cfm http://www.ussc.gov/guidelines/index.cfm
- namank 14y agoTweet this link to Anonymous. I just did. https://twitter.com/naman_k/status/293252007878328320 https://twitter.com/naman_k/status/293252007878328320
- namank 14y agoWhile I was expecting downvotes for this comment, I was also looking forward to the discussion that should arguably accompany such downvotes. But that, of course, is a privilege exercised by the downvoter and rarely ever happens!
- Dylan16807 14y agoIf you know why you got downvoted then you don't need someone to explain it to you. There are less-irritating ways to start a conversation than trying to be 'loud and wrong'.
- namank 14y agoPerspectives matter. There isn't only one way of being wrong; or right for that matter.
- deleted 14y ago[deleted]
- cantos 14y agoI've only reported a security issue once and wouldn't do it again. In this case a vendor and IT has agreed to allow several security settings to be disabled temporarily, making all user passwords easily available in the process, but then had apparently forgotten and left things vulnerable for 6 months. IT had to brief some senior people who then started freaking out about hackers. I was lucky to just get off with a few people annoyed with me.
- ck2 14y agoMaybe the answer is if you find a problem like that don't keep a secret between you and the person in charge. Just go to the school paper or town paper and let them report it. He did great up to the point where he tried to pen-test after reporting it. I understand the intellectual curiosity to see if people are doing their jobs and it's too easy to armchair quarterback but if you bring attention to yourself by reporting a problem you can be sure they will watch you and not necessarily the problem.
- sebcat 14y agoWhile I do not agree with the way this student was being treated, running Acunetix on a system is quite invasive. Regardless of his intent, the consequences might have been data loss and/or denial of service if the system was built poorly enough. Doing extensive vulnerability assessments without consent is really not a good idea.
- awfkawekfjn 14y agoI know of a similar vulnerability in another large french school management system, but this just gives me one more reason not to report it.
- bstar77 14y agoI dealt with a situation at a college internship. The company was designing a marketing campaign for Nokia, but we were having major problems with the firewall software, which made for a very flaky Internet connection. Long story short, my manager disabled the firewall and we were hacked that night. I was let go the following day unceremoniously. I discovered soon after that the company blamed me for the attack, saying I turned the firewall off and hacked the servers myself. The school immediately started expulsion proceedings without even contacting me. Fortunately, my advisor personally addressed the issue and had everything dropped. The drama only lasted a few days, but the schools brain dead response to the issue gave me zero confidence in their ability to review anything objectively. I was so disgusted I refused to walk in the graduation ceremony, much to my parents disappointment.
- RRRA 14y agoGo sign the petition here: http://hamedhelped.com/petition/ http://hamedhelped.com/petition/
- accountswu 14y agoThanks, I just signed the petition!
- kimmel 14y agoI would like to point out that open source projects love, absolutely LOVE when you report security bugs to them. Many projects have procedures and special mailing lists to get a hold of the correct people in a prompt manner. To me this stinks of the "closed mind" problem.
- just2n 14y ago“All software companies, even Google or Microsoft, have bugs in their software,” said Mr. Taza. “These two students discovered a very clever security flaw, which could be exploited. We acted immediately to fix the problem, and were able to do so before anyone could use it to access private information.” Yes, even Google and Microsoft have bugs in their software. This isn't an excuse to bully people who tell you about the bugs in yours. The difference between you and Google is that Google pays people who find bugs in their software, especially serious security flaws, even if they aren't employed by Google, rather than threatening them with legal action.
- hn-miw-i 14y agoProblem is he used an auditing/penetration testing tool POST disclosure, and did it without authorization. The availability of these tools puts weapon grade exploits in the hands of those with limited understanding of the consequences. I don't have an issue with the availablity -- best we lighten our history with Full Disclosure and provide best of breed tools to simulate attackers -- however, responsibility and individual accountability is at an all time low. These tools will light up the alarms immediately and the user will have limited understanding. Let's assume it was not SQLi but an authorization application logic bug ie: by changing parameter passed by browser allowed access to whole record set. He did the right thing and told the vendor -- but after the fact he ran a tool that probably simulated SQLi on every damn parameter! Like smashing a car window after telling the owner he has left it unlocked. Even a brain dead sysadmin would notice it In the logs, and likely whatever SIEM would fire a high priority alert. He did this without auth and the company did the right thing here. In this post aaronsw world we can't just assume that every n00b clown whitehat hacker is totally innocent of all crimes even if done with the best intentions. People need to take responsibility for their actions. An ignorant click can be just as criminally negligent as stabbing a dude in the face.
- Dylan16807 14y agoWhat is with all these analogies that equate testing with smashing things. Stop it. Stop. It.
- realrocker 14y agoI was in a similar situation in college. Was asked to sign a Non-Disclosure Agreement or get arrested. Told them to go to hell and file a lawsuit if they want too. Nothing happened eventually. Thank God for the excruciatingly painful justice system of India :P
- aaron695 14y agoAm I the only one that sees that the title/headline is pretty close to a lie and that he ran a 'Web Vulnerability Scanner' on someone else's web site? This is illegal! Most people seem to be missing this. If you're going to break the law at your own University at least cover your tracks. Don't annoy the crap out of them(Rightly or wrongly) then go on to black hat them.
- kyllo 14y agoMaybe consider punishing the negligence of the person who wrote the insecure code instead? But I don't think most people, especially lawmakers, even understand that security vulnerabilities are caused by flawed code, which is caused by human error. So they tend to shoot the messenger instead.
- plouvre 14y agoWho in their right mind would think it's a good idea to use a penetration tool against their college?? The title is all wrong. He got expelled for using a penetration, not finding a flaw. He was congratulated for that! I heard someone else from the team even got some kind of prize for it. Sensationalist journalism is what it is. After a little bit of research, I discovered it's written by someone who used to be in Dawson's Student Union, so I guess he has a teeth against the administration. "Ethan Cox is a 28-year-old political organizer and writer from Montreal. He cut his political teeth accrediting the Dawson Student Union against ferocious opposition from the college administration and has worked as a union organizer for the Public Service Alliance of Canada."
- hso9791 14y agoMaybe the right response would be to legally punish - by fine - both parties. After all, there is private data insufficiently safeguarded. Some poor girl could end up getting stalked if the right kind of sleeze came across this.
- dutchbrit 14y agoReminds me of when I was a kiddo, I almost got expelled because I found a security issue in the schools network. I could access everyones files. They also didn't like it when I pointed out they were running cracked versions of Macromedia Flash on all their pc's. Let's just say, I'm glad I didn't get expelled. But I'm pretty sure they just saw me as an annoying fuck & that's all. I don't think they really cared, but were 'forced' to put time and effort making their network more secure.
- malandrew 14y agoI'm wondering if that NDA included the clause that urges you to get advice from a lawyer. The conditions under which he signed it sound very suspicious (i.e. coercive language) and I wonder if it would be grounds to nullify the NDA entirely.
- illuminate 14y agoI'm curious, how often does this occur? "included the clause that urges you to get advice from a lawyer" I can't recall being offered a NDA with this language.
- malandrew 14y agoAll the contracts of some form or another in the jurisdiction of California that I've reviewed recently include some language to that effect, usually at the end among the warranties and disclaimers.
- biggeek 14y agoMost schools have an acceptable use policy for their students which covers unauthorized vulnerability probing and port scanning. I can understand Ahmed's youthful curiosity about whether the vulnerabilities that he identified had been fixed...But he had handed off the info to the Dawson College IT team and the ball was no longer in his court. Running Acunetix against the college's/SkyTech's server(s) was a pretty dumb move. But hell, when you are in your early 20s, that's when you are supposed to make dumb mistakes. I'm all for teaching moments, but this "One Strike And You Are Expelled" issue irks me. Ultimately, this is about Edward Taza of Skytech Communications being sleazy and manipulative by threatening a scared, inexperienced 20 y/o college student with expensive legal action and implying the possibility of jail time unless he signed a non-disclosure agreement. The EFF should probably take a look at this.
- rwg 14y agoI've already posted my "almost got arrested for using zsh" story, so here's another one: I used to work at a large public university. One day, a grad student brought me his laptop and asked if I would take a look at it because "the Internet [was] really slow." It turned out that his computer was part of a botnet controlled via IRC, and it was being used to attack hosts on the Intertubes. After sniffing the IP address + port of the IRC server and the channel name and password the botnet was using, I joined the channel with a regular IRC client. "/who #channel" listed thousands of compromised clients, including hundreds with .edu hostnames. (One university had a dozen hosts from .hr.[university].edu in the channel. Sleep tight knowing your direct deposit information is in good hands.) There was no way I could notify everyone, so I concentrated on e-mailing abuse@ the .edu domains. In my e-mails, I explained who I was and where I worked, that one of our computers had been compromised by hackers (yeah yeah terminology), and that in the course of investigating, I found that computers at their university had also been compromised by the same hackers. I also included a list of the compromised hostnames at their university and the IRC server's information so their networking people could look for other compromised hosts connected to the IRC server if they wanted to. Relatively basic IT stuff. I didn't get replies from the majority of the universities I sent messages to, including the .hr.[university].edu one. I got a few thank yous, but I got just as many replies from IT Security Officers and CIOs (including at big name universities) accusing me of hacking their computers and demanding that I stop immediately or face legal action. Those people just didn't understand, and they were in charge of (or ultimately responsible for) their universities' IT security efforts... It was completely mind-boggling to me at the time.
- zx2c4 14y agolink to zsh story: http://news.ycombinator.com/item?id=3901634 http://news.ycombinator.com/item?id=3901634
- lordlicorice 14y agoIn high school I had to write a long apology essay in part because my computer teacher testified to the principal that the Windows command line is "a high-security area of the computer that students have no business accessing." I tried to explain that she was wrong, but you can guess how well that went.
- chris_wot 14y ago"This type of software should never be used without prior permission of the system administrator, because it can cause a system to crash." Remind me to never, ever use Omnivox, or any Skytech software, ever.
- d0m 14y agoYou probably won't have to, but as a student, you don't have the choices ;) Your courses information, schedule, homework, etc. is all on it.
- chris_wot 14y agoIn Australia, I'm happy to say all I need to do is report a data leak to the privacy commissioner and they'll basically investigate what's happening and force changes.
- peripetylabs 14y agoI think the college administrators are bullying this student because they are embarrassed. The threats by the Skytech CEO Edouard Taza; the college not allowing the professors to hear the student before voting; his transcripts vandalized with zeroes so he cannot continue his studies elsewhere... What exactly is the relationship between Skytech and this college? I've signed the petition to reinstate Hamed: http://www.hamedhelped.com/petition/ http://www.hamedhelped.com/petition/ Hamed, stick to your guns. You did the right thing.
- Khao 14y agoI used to work at Skytech. We already had a case of a student discovering a flaw in our code while I was there and things went very smoothly. We contacted the student, he told us what the flaw was, we corrected it. Edouard made him sign a non-disclosure agreement and made him delete all the data he had gotten from our servers and that was the end of it. This student was a brilliant student with excellent grades just like Hamed. Now why is this story different this time? I'm not too sure since I've left a couple years ago, but my guess would be that the college administrators have taken this decision. Knowing Edouard Taza, I doubt he would have pushed for this student to be expelled, since he clearly has a great future in software and could be one day employed at Skytech to fix even more security holes. Edit : hadn't finished reading the article, it seems the professors decided to kick the student out : "Following this meeting, the fifteen professors in the computer science department were asked to vote on whether to expel Mr. Al-Khabaz, and fourteen voted in favour." To me what this says is their computer science department is full of idiots. Any good CS professor would have understood that Hamed didn't have any malicious intent.
- unreal37 14y agoNo, what this tells me is that Mr Al-Khabaz continued trying to hack the server even when told to stop. Whats the difference between the reaction we all expect (including your story) and this? The difference is Mr Al-Khabaz continuing to try to break into the web servers. He got kicked out of CEGEP. He'll survive unharmed. Sad that he thinks getting publicity is worth it though.
- olalonde 14y agoIt doesn't come much as a surprise to me that Omnivox has at least a few security flaws. I had to use it during my CEGEP years in Montreal and it's a huge piece of garbage.
- rurounijones 14y agoThe administration of Dawson College clearly saw things differently, proceeding to expel Mr. Al-Khabaz for a “serious professional conduct issue.” He is a student, how can be have a "Professional conduct issue"
- puerto 14y agoUnauthorized security testing == Malicious attack The actions of Mr. Al-Khabaz were unlawful and unethical. If he only accidentally found the flaw and reported it to the responsible person, things would be fine. But security testing without the permission of the system owner is the same as unauthorized access attempt! I work as a security professional for 7 years, and I recently did a guest lecture on the college discussing the example like this. Most students were not aware where the problem is. Maybe it would help imagining how would story like this look in the physical world: Let's suppose you come back home and find someone picking on your door lock with a lock picking tool. You ask him "what are you doing?" and he says "I'm just checking is your lock safe. I do it for your security." Would you believe him? Or would you call the police immediately, without asking him anything? Let's add to this that security testing tools can sometimes degrade the tested system's performance or sometimes even crash it. In this case, it's not just unauthorized access attempt, but successful denial-of-service attack! Never, ever, do a security testing of the system without the written permission of the system owner. If you get the permission, you will probably be asked to sign an NDA in return. You will also need to provide some information, like source IP address you're using and emergency contacts that can be used to stop the testing in case of problems (like crashes, etc.). This is the only lawful and ethical way to do these kind of procedures on someone else's system. I'm not discussing if the penalty is OK in this case. It really doesn't matter if most people here cannot tell what he did wrong in the first place.
- aaron695 14y agohttp://www.acunetix.com/blog/web-security-zone/should-you-test-development-staging-or-production/ http://www.acunetix.com/blog/web-security-zone/should-you-te... what can happen when production Web applications are tested including: Email floods Junk data inserted into databases News feeds filling with random input Log files filling up Accounts getting locked out Internet bandwidth consumption Scans that take longer to complete High server and database utilization Incident response teams and managed security providers having to deal with alerts Final cleanup needed after the fact
- puerto 14y agoYeah, those things also.. ;)
- d0m 14y agoSo.. here's something that happened to me in my engineering software university. A friend of me just had a summer internship in a security firm and learned a trick or two. And, looking at the html/javascript code of a page, there was an obvious entry point that gave access to anyonela else account provided you had their student number (i.e. skip the password step). So my friend showed it to me and I suggested he tell the IT department. Obviously, the next thing we know, he's accused of "Hacking" and get menaced by the IT department. A couple days later, we check back the website and realize that a trivial encryption is added.. I.e. you have to reverse the student number or something like that. And, obviously, just on the client-side. A little bit pissed, we decided to take our revenge of being menaced for just being nice. So we create a web page where it explains the story (That we found an entry point, that we told the IT, etc.) and then, we say "Try it!" [<enter student number>] which directly logs you in into their account. We e-mail that page to the main directors of the school by suggesting a quick fix. And, we make sure to CC the IT departments. The day after it was fixed and we received a real "thanks" from the authority. I guess the trick is to contact a higher authority rather than directly contacting the IT department.
- kamaal 14y agoThis is a perfect example of 'No good deed goes unpunished'. The best action to take while you find a security flaw is to do nothing. Let some one evil abuse the flaw and make the guys miserable enough to realize the importance of a responsible disclosure. Without this the guys ego is going to take this as- 'How dare he point a problem in my/our work' and not 'Thanks for saving my life before some body could screw me'.
- munin 14y agoit seems like there's more to this story, and the more to this story is around his actions two days after the report. I've seen things like this happen before. You find a bug, you report it, they tell you "oh we're getting on it immediately". Some time goes by and you think, hey, did they fix it? You look, discover "nope", think "man I bet those guys would fix it if I lit a fire under their ass" and try and use the bug to deface the site, or something. this is logic that makes sense to a 20 year old (speaking as a former 20 year old..). I've seen that happen before. the article doesn't say this, but perhaps reading between the lines the second attempt did not have a pure motivation behind it...
- maeon3 14y agoWhen it comes to software and security flaws, finding them is like an exercise in witchcraft. Throw the person who found the software bug into the lake, if they float, then they were a witch, and deserve to die. And people wonder why security is so poor and Chinese hackers find it so easy to hack into all our stuff. Because America Punishes people who focus on bulletproof secure code. I guess we'll need to hire some special interests to pay-off the news networks cnn/fox/msnbc/etc to add the "Hackers are not witches" to their narratives. We would probably need bribes on the order of billions.
- Karunamon 14y agoThis headline is somewhat misleading. The student was expelled, not for finding and disclosing a security flaw (he was actually congratulated and thanked for this), but for later running a pentest software suite without permission to "verify" if the bug had been fixed. That's not to say that the expulsion still doesn't reek of BS, but Ahmed's hands are not completely clean here.
- tomp 14y agoThat is probably just their excuse. I think it's quite reasonable to check if someone fixes a security flaw that puts your own information to the risk. It's like trying to open (without the key) the safe at the bank that has your money in it.
- Karunamon 14y agoTry walking into the safe deposit box area at the bank absent escort or previous notification and see how that works out for you. Again, the school is on record as giving him kudos for reporting the error - it's perfectly reasonable to assume that someone will not launch offensive penetration testing tools at your site, without notice or permission, just because they have reported the bug in the past. He could have tested the bug without the pentest software, besides. Just because someone points out a crack in your window doesn't give them carte blanche to try breaking it after you said you fixed it.
- Dylan16807 14y agoThe webserver did escort him into the room with the safe deposit boxes. He has a key, they let him in, that's their job. The problem is that he could open his box, or any other box, without actually using the key.
- Karunamon 14y agoWe're laboring a physical analogy quite hard, here. Again, the problem isn't that he found and disclosed a bug, the problem is that he attempted to exploit that bug after the fact. You do not have the right to do that. Pure and simple. Finding and disclosing a bug is one thing, utilizing it is something else entirely.
- HelgeSeetzen 14y agoAhmed, I am assuming that you are following this discussion. Based on the article, your life probably doesn't feel so good right now. Sorry to see a bright person in such a situation. Give me a ring if you are looking for an internship, job or start-up experience in Montreal. We are in town (walking distance from Dawson actually). By the nature of our business, we also have good connections with academia if that can help (www.tandemlaunch.com). My login is my name so you can reach me at [firstname].[lastname]@tandemlaunch.com
- georgespencer 14y agoAhmed if you're reading this and looking to get into software engineering, drop me a line (email in profile). I run a venture-funded startup and would be happy to take care of relocating you if your technical abilities are up to scratch.
- GiraffeNecktie 14y agoAs the saying goes "No good deed goes unpunished."
- lilsunnybee 14y agoThere should really be a Department of Computer Security run by most national governments where people can anonymously report exploits, and that Department takes care of contacting the company or organization. If that group also deals with certain types of personal information that is threatened, there should have 30-60 days to demonstrate that they addressed the vulnerability appropriately, or face penalties. Its really dumb that we're this far into the internet age already and companies and organizations can still play it so fast and loose with security and personal information. It's irresponsible and negligent.
- GFischer 14y agoThere are "Computer Emergency Readiness Teams" in most countries, the United States one is http://www.us-cert.gov/ http://www.us-cert.gov/ The one in my country gets anonymous report exploits for state-run software. Not sure what they do wit them though :)
- jiggy2011 14y agoThere needs to be (if it does not already exist) some method of doing completely anonymous and confidential disclosures that somehow get to the the right person.
- Gilipe 14y agoA fellow student and I discovered a similar flaw in my college's system a few years back, but not as serious as this (no social insurance numbers, but emails, full names, phone numbers and addresses). We brought it to the attention of the head of the IT Department by email. Later that week, the head visited our morning class to discuss this with us. He discussed the issue to the class and actually acknowledged his appreciation for students like us for reacting promptly and responsibly over the issue.
- vezycash 14y agoWarning to hackers Hackers are the new Sicilians and blacks. Don't snitch. Snitches get punished both by: The person being snitched upon The person who is being snitched to. This article and many other comments herein support this view.
- drucken 14y agoTwo completely different issues: 1. Exploit discovery. 2. Automated service attack. From the information given, it seems Al-Khabaz did exactly or better than what was expected of him for the first. But why, if he was simply check for the existing vulnerability after informing of the first, did he launch an automated attack? I suspect Dawson College has sound reasons to treat him the way they did for both instances.
- outside1234 14y agothe worst part about this whole article is that the professors voted to kick him out -- not the pointy hairs.
- readme 14y agoI don't agree that expulsion is the correct reaction, but when he ran the pen-test software, what he was doing was wrong. It's one thing to stumble upon a bug while you're developing an app, and report it. That's totally respectable. Running pen-testing software without permission is akin to walking up to a stranger's home and testing that all the windows are locked, with a crowbar.
- rapind 14y agoNo, that's a terrible analogy unless this stranger is not a stranger, and is known to be trusted holding tons of personally identifiable information of yourself and your peers, and has already been alerted they left a window wide open (in this example, minimal tech know how is required). And saying crowbar is intentionally misleading people into thinking that damage is somehow being done during the check.
- randomdata 14y agoI can't help but feel a better analogy is finding a rip in the seat of a bus, reporting it, and then poking at the rip a few days later to see if it has been repaired. Going at someone's windows with a crowbar doesn't seem to fit the situation at all, in my opinion.
- unreal37 14y agoNo, he didn't check if this one bug was fixed. I mean, he could have done that without downloading pen test software - just by checking what he previously checked to discover the bug in the first place. What he did do was download pen test software to automatically check the website for flaws AFTER BEING TOLD NOT TO. He went to every bus and checked every seat, door, window, engine, tire, seat belt for dozens of different flaws without permission. And yes, pen test software can be destructive. It can put bad data in a database, crash a server, overrun log files, and corrupt things. Penetration testing is not a passive process.
- jokeofweek 14y agoJust to let you know, Dawson wrote a response to the media which can be seen at http://www.dawsoncollege.qc.ca/ http://www.dawsoncollege.qc.ca/
- AYBABTME 14y agoI'm going against the general idea here, but the college issued a statement: http://www.dawsoncollege.qc.ca/home http://www.dawsoncollege.qc.ca/home Basically, they say Ahmed did more than just what is reported in the article, and they can't publicly say what he did - because that's private info about Ahmed that they're legally obliged to protect. Now I'm not taking a position in favor of the college or in favor of Ahmed. I'm just saying, it's not all black (or white). The National Post article is biased and we're missing some info. We should remember about that before going crazy on the witch hunt.
- deltaqueue 14y agoThe site is now 403'ing but I'm really curious what else he could have done and didn't admit to for his story. Personally, this all makes sense right up until the point where the president of Skytech says Ahmed should not have run his tests but that he understands Ahmed was not being malicious. But then Skytech wants him expelled, and the university wants to protect Skytech's interests? Expelling him would get the story out and accomplish literally the opposite of saving face, even with his inability to disclose details. Based on other stories of bureaucratic ignorance it's easy to jump on the administrative / cover-up blame train, but something about this doesn't quite mesh, and the fact that the story's only alibis are 1) Ahmed and 2) a generic students' rights organization makes it difficult to digest.
- alexcoco 14y agoI graduated from CS at Dawson and know the faculty quite well. I had the same exact reaction as most people when reading the article up until the point where I saw that 14/15 of the faculty members voted in favour of expelling the student. That right there makes me wonder what else he did. The faculty told me that there are other things that caused this and they are unable to discuss them with me. I wish it were possible to get that information but I know them and I trust them.
- staplesowns 14y agoI also graduated from CS at Dawson. I've been told that Taz and François Paradis know each other quite well and this is probably the result of said friendship. But this is all heresay.
- JimmaDaRustla 14y agoApparently he refused to "cease and desist" his actions. So...he brought on the expulsion!? Dawson statement on the article: The reasons cited in the National Post article for which the student was expelled are inaccurate. The process which leads to expulsion includes a step in which a student is issued an advisory to cease and desist the activities for which he or she is being sanctioned, particularly in the area of professional code of conduct.
- sergiotapia 14y agoThere a difference is finding an exploit accidentally and reporting it from running a penetration testing tool on a production server. What did this kid expect?
- runarb 14y agoLooks like this news is starting to go global. Even the local it newspaper her in Norway has an article about it: http://www.digi.no/909958/utvist-etter-aa-ha-varslet-om-saarbarhet http://www.digi.no/909958/utvist-etter-aa-ha-varslet-om-saar... (in Norwegian). The Streisand effect has struck again :)
- lucastech 14y agoPeople are always afraid of what they don't understand, but to think that prosecuting or punishing people for helping prevent malicious people from finding these types of bugs is just ignorant. No ones code is perfect, and it often takes dozens of eyes before issues like this are found. The longer people are punished for helping, the worse our "cyber security" will digress moving forward.
- krspaul 14y agokids make mistakes sometimes, and its unfortunate during this period of transition to adulthood that they fall victim to the swift guillotine of collegiate justice - which unlike a court of law, you dont get representation, you dont get a fair trial, you dont get allowed an intemediary who can communicate 'language' between both sides. you dont even get protections like freedom of speech these days. its all a flow chart if you make a mistake in school no matter if its tech stuff like this, or anything really. we live in a world of corporations, lawsuits and lawyers, insurance & liability - no room for grey area anywhere in there. wheres the incentive for the school to care? they already got your money. the worst part for the students is - they can have all sorts of good feelings built up towards their professors & classes. then the administration comes in and manages to sour all those feelings. those same professors, who may think the world of you, cant do a thing because at the end of the day its c.y.a. - and youre all alone. college kids need to get educated about how college justice works if you screw up - its always too late when they do learn.....lets spend money on athletic complexes instead right?
- MarlonPro 14y agoWhat Mr. Al-Kabaz would have done is secure a lawyer before he signed the NDA.
- john_fushi 14y agoThis story is somewhat complex, and lacks information on many aspects. I've made a kind of TLDR of what happened and added my thoughts. I've also cross compared the informations given in the article with those available on dawson's college web page and Skytech's omnivox. [he was] working on a mobile app to allow students easier access to their college account [.] -> Did he have authorisation? -> From who did he have authorisation? -> Omnivox does not seem to have a public API. “I saw a flaw which left the personal information of thousands of students, including myself, vulnerable,” "I felt I had a moral duty to bring it to the attention of the college and help to fix it, which I did. I could have easily hidden my identity behind a proxy. I chose not to because I didn’t think I was doing anything wrong.” -> Did he try to fix it, or only bring it to the attention of the college? -> Did he inform the college he tried/would try to fix the flaw? -> Did he try to fix the flaw after or before meeting with the college? "Mr. Paradis congratulated Mr. Al-Khabaz and colleague Ovidiu Mija for their work and promised that he and Skytech, the makers of Omnivox, would fix the problem immediately" -> Mr. Paradis is Dawson's Director of Information Services and Technology -> I precise only because it is not clear from the article if he works at the college or at Skytech "Mr. Al-Khabaz decided to run a software program called Acunetix" "to ensure that the issues he and Mija had identified had been corrected" -> Did they use acunetix the first time? -> If yes, did the college know? Did skytech noticed? -> Otherwise, why? They found the flaw without acunetix "Taza explained that he was quite pleased with the work the two students did identifying problems, but the testing software Mr. Al-Khabaz ran to verify the system was fixed crossed a line." The administration of Dawson College clearly saw things differently, proceeding to expel Mr. Al-Khabaz for a “serious professional conduct issue. Following this meeting, the fifteen professors in the computer science department were asked to vote on whether to expel Mr. Al-Khabaz, and fourteen voted in favour. Mr. Al-Khabaz argues that the process was flawed because he was never given a chance to explain his side of the story to the faculty -> Was there other incidents that could have influenced the judgment? -> College rarely want to expel students who ace all their courses. Especially in CS with the high rate of failure. -> According to the college : The process which leads to expulsion includes a step in which a student is issued an advisory to cease and desist the activities for which he or she is being sanctioned -> This, along with the "He said that this was the second time they had seen me in their logs" tend to indicate he probably ran the test multiple times. Or, the first time he foud the flaw, skytech took him for an attacked and the college warned him to stop developpement on his application. This would indicate that he had no authorisation in doing so.
- sopooneo 14y agoI think hackers need to realize that this type of reaction is the norm. If you find an exploit then use your discretion in deciding to report it, but don't be naive. There is no reason to risk martyring yourself for someone else's interests. The risk to those (including yourself) whose information is vulnerable should be taken into account, but countered by the risk that you will be persecuted for bringing the problem to light.
- WinnyDaPoo 14y agoHe treaded on thin water and he fell in. He should have asked for explicit permission to start pentesting instead of putting his academic career in a volatile state.
- GFischer 14y agoHowever, if the article framed things correctly, the college's response is overkill. I would have given him a second warning.
- 73ChargerFan 14y agoCompany offers scholarship to Dawson student who exposed security flaws http://www.cbc.ca/news/canada/montreal/story/2013/01/21/montreal-dawson-college-hack-hamed-al-khabaz.html http://www.cbc.ca/news/canada/montreal/story/2013/01/21/mont...