IoT hacking and rickrolling my high school district
101–110 of 399 posts
Re: IoT hacking and rickrolling my high school district
#102Someone I know did something similar, was arrested in their college dorm, and at the sentencing hearing in federal court was fined and sentenced to 5 years probation, and now has a criminal record. This kid is very very lucky. Obviously they violated the CFAA which carries severe criminal penalties. They engaged in actual hacking without any permission or defined scope. And they exploited the system without any respo…
I remember back in high school we had this computer lab that was all locked down. Didn't allow opening the CD-ROM drives, only allowed certain educational websites, etc. I put a little remote access app on my share drive as a way to open my own CD drive, mostly just to see if I could do it. The school's computer guy came and found me and was like "hey, a file pinged as malware, what's up with that" and we had a fun d…
Re: IoT hacking and rickrolling my high school district
#103These were the days when nothing had SSL, so you could just intercept and rewrite traffic!
My only requirement was: do no actual damage
It was implemented as a Debian live CD that you could drop into any school computer. It would boot up, then Ettercap would MITM the whole network by spoofing the router. It routed all HTTP traffic via Squid and a custom ICAP server that did the actual rewriting. If you removed the live CDs, the network just went back to normal within a couple of minutes.
Routing the whole school's network through one old Pentium machine wouldn't work though, so I figured out a way of doing distributed load balancing: it would do the ARP spoofing slowly and randomly. So, as you added more machines, it would just magically balance between them.
It worked great for about an hour then whole network mysteriously stopped working for the rest of the day. I left all the live CDs in the computers as a calling card.
Sorry, school network admins.
Re: IoT hacking and rickrolling my high school district
#104Earlier quoted context omitted.
I'm glad to see a kid using bash and not something like gulp PowerShell
Credit where credit is due, we all WISH *nix had something like PowerShell. Passing strings from program to program is a pain, passing around .NET objects instead is a great step forward, as can be seen by the several attempts at similar shells passing around JSON objects.
Who is "we". I've worked exclusively on a windows stack so used powershell on the job. But at home, I use bash. I don't want something like powershell in nix and don't use powershell on nix even though it's been available on nix for many years now.
> Passing strings from program to program is a pain
You can argue it's the basis of computer science and also pretty efficient.
> passing around .NET objects instead is a great step forward, as can be seen by the several attempts at similar shells passing around JSON objects.
Passing around objects can be slow, inefficient, wasteful, etc though it can be convenient.
If you are on a windows stack then go with powershell. If not, then go with bash. Nobody should be on a windows stack but sadly, much of the business world has been captured by microsoft.
Re: IoT hacking and rickrolling my high school district
#105There's a few comments about the risks along with a little surprise/at least applause for the administration choosing not to waste the courts/various other parts of the justice system with this prank. I completely agree -- I don't know if I'm terribly surprised they chose that route (whether or not they were truly upset in the first place). I applaud the students for executing this so carefully/well and if my kids pulled something like this off with this level of care -- well, they'd at least be getting a dinner out of their choosing -- probably a trip to a nearby theme park.
I suspect the kids involved were also certain that their approach, attention paid to keep from disrupting class and (thankfully thorough) testing that helped avoid a harmless prank turning into expensive litigation/really pissed off parents. But I'll bet there was a lot of fear around that, anyway! Had something gone awry -- and that's always where the risk is -- I'm guessing the outcome would have been more severe for these kids.
They really played the social engineering/covering their hind-quarters side of this prank very well. A large amount of effort was put toward making sure class was not interrupted[1], things worked and were tested and they provided detailed information to the administration on how to secure their systems -- that last piece allowing them to say "Without our minimally invasive prank and report you'd have never known these issues existed. We're not that special; a more malicious student could have discovered these flaws, opted for a porn broadcast and made it difficult/impossible to find them to punish." They probably understand their own school's administration and took an educated guess as to how they might handle something like that, too. At least for the scope of anything I did, I knew I wouldn't hear from the Vice Principal or Principal -- I'd solved various computer problems for them by then that the worst I'd get would be "that was cool, but please don't do that again."
I didn't get in trouble because the pranks worked similarly -- I tested/avoided disruption (most of the time), did no permanent damage and anything was resolved by a reboot (DOS and no fixed disk) and our harm was necessarily limited since there are only so many computers you can covertly pop a floppy disk in -- there was no network. The biggest factor, though, was that our programming teacher sometimes got involved, himself. He was the head of the math department, not your traditional "computer geek" and I was doing things that he wasn't teaching, so he encouraged it. The guy was amazing (passed away in the mid-00s).
So, kids, if you do try this at home, make sure it all works, provably, very very well and don't do anything that will give them other reasons to throw the book at you. And if your administration has more than the typical "Zero Tolerance[2]" stance on things, it's just a bad idea regardless.
I'm sure there were a few among the ranks that became furious but cooler heads prevailed. The report at the end was a nice touch.
[0] Mostly contained in the computer lab, which was non-networked, but when we discovered the three-letter-acronym TSR (DOS's Terminate and Stay Ready) and realized it was rare that another student would reboot an already booted machine (it took forever counting to the 512KB or so RAM installed). Incredibly, I graduated in the late 90s -- my Senior year, the lab that taught (Turbo, then Borland) Pascal was 15 years behind what most people had at home... these diskless all-in-one bastards wouldn't break.
[1] I'm sure it took the kids a little longer to get to their classes after that all happened -- that's a minor, completely expected, situation here and at least a small reward for the efforts involved.
[2] The school ten miles north of us was in a rural district and had a parking lot full of trucks with hunting rifles attached sitting in the parking lot every day (well after all of the schools installed additional locks and added security theater to make parents feel better post-Columbine)...that wasn't forbidden at least as far back as the early 00s and I wouldn't be surprised if a blind eye is mostly turned, today in some parts of that district.
Re: IoT hacking and rickrolling my high school district
#106Someone I know did something similar, was arrested in their college dorm, and at the sentencing hearing in federal court was fined and sentenced to 5 years probation, and now has a criminal record. This kid is very very lucky. Obviously they violated the CFAA which carries severe criminal penalties. They engaged in actual hacking without any permission or defined scope. And they exploited the system without any respo…
That said, maybe we should lighten up on minors performing harmless/non-destructive pranks. Not everything warrants felony charges for kids.
Re: IoT hacking and rickrolling my high school district
#107Someone I know did something similar, was arrested in their college dorm, and at the sentencing hearing in federal court was fined and sentenced to 5 years probation, and now has a criminal record. This kid is very very lucky. Obviously they violated the CFAA which carries severe criminal penalties. They engaged in actual hacking without any permission or defined scope. And they exploited the system without any respo…
This post is 100% spot on. While the local school district may treat it as a prank, in the U.S. the federal authorities may not. To see how seriously the government takes this act, look at the penalties section of the relevant U.S. code. https://www.law.cornell.edu/uscode/text/18/1030
Re: IoT hacking and rickrolling my high school district
#108Earlier quoted context omitted.
The students were extremely lucky. The advice given to me in high school (I was working on tech projects after school for several teachers and groups) was to not even try or explore poking around the IT networks it no matter how good my intentions were. All it takes is one grumpy school administrator to feel undermined or to misunderstand your report and you could be expelled. When you're in a position like a student…
He had already graduated, so expulsion wasn't an option.
Re: IoT hacking and rickrolling my high school district
#109I found more severe vulnerabilities including being able to lift home addresses of students by querying an unprotected endpoint. Didn’t get in trouble for this one, and reported it promptly to the IT administrator.
Re: IoT hacking and rickrolling my high school district
#110Someone I know did something similar, was arrested in their college dorm, and at the sentencing hearing in federal court was fined and sentenced to 5 years probation, and now has a criminal record. This kid is very very lucky. Obviously they violated the CFAA which carries severe criminal penalties. They engaged in actual hacking without any permission or defined scope. And they exploited the system without any respo…
Looks like they paid out millions in bounty in 2020:
https://www.zdnet.com/article/hackerones-2020-top-10-public-bug-bounty-programs/