Live data from Hacker News

IoT hacking and rickrolling my high school district

whitehoodhacker.net

181–190 of 399 posts

Re: IoT hacking and rickrolling my high school district

#181

Someone I know did something similar, was arrested in their college dorm, and at the sentencing hearing in federal court was fined and sentenced to 5 years probation, and now has a criminal record. This kid is very very lucky. Obviously they violated the CFAA which carries severe criminal penalties. They engaged in actual hacking without any permission or defined scope. And they exploited the system without any respo…

Posts like yours validate the insane over criminalization of what essentially amounts to a prank. I had literally the exact same experience in high school. Got expelled and had to get a GED. They could have easily pressed charges. Part of the issue is people like you who advocate for respecting "the system" and essentially scaring kids into not doing anything. Except that simply re-enforces the draconian laws that ar…

validate the insane over criminalization

I think you misread the GP. He's not defending the system, just describing it, and how the OP was lucky that the people in charge were unusual and open-minded. He's warning others that the risk/reward implied by the OP's experience is misleading.

I suspect that most commenters on this site applaud the kids adventurousness and style. A great hack! But we are uniquely aware of how rare it is that anyone with authority, school administrators or law enforcement, would show any leniency or self-restraint in these cases. On balance, the instinct seems to go for the jugular, dehumanize the kid as a criminal hacker, and ruin his life. No-one is saying that's good, or reasonable. It's just how it is.

Re: IoT hacking and rickrolling my high school district

#182
I was at my own community college 2 years ago, and they had those Smart TVs showing news and weather everywhere, as well as custom images uploaded by the clubs on campus.

It was supposed to be that a club could log into them, make, and submit a graphic to display on the TVs, but the school would have to review them before they would be displayed.

However, I would later find out, a software update had messed up the roles system and so that club username/password which was in a public document actually had the ability to post things immediately on the TVs, without review. I found this out when I made a Math Club poster, hit the button, and it was immediately live without a check.

I just reported it and it was fixed the next day. My instructor said that could have been really really bad considering some more unscrupulous college kids who would have (not naming names) probably gotten a kick out of throwing pr0n on them...

Re: IoT hacking and rickrolling my high school district

#183

Serious question. What, if any, instruction do kids these days receive regarding what's allowed on computer systems? I remember in high school poking around a network drive until I found an executable with the name "SEND" in the name. I had a sense that it would send some kind of message somewhere, but I honestly didn't know where or to how many people. I was quite surprised when all the screens in our computer lab f…

Kids have been jumping fences for millennia.

That said, I did know a kid that had charges pressed against him when I was in school so things weren’t necessarily innocent back then either. He was admittedly an idiot and borderline malicious though.

Re: IoT hacking and rickrolling my high school district

#184
I went to Buffalo Grove High School in this same district and graduated many years ago. At the time no IPTV systems or EPIC bell systems were in place. However, as soon as I walked in my freshman year I noticed the 'teacher' WiFi was only using MAC Address Filtering. One minute scan and a spoof later I was poking around to discover a whole lot was visible from this privileged network. “...From the results, we found various devices exposed on the district network. These included printers, IP phones... and even security cameras without any password authentication!” It was even worse back then. It was all exposed on wide open WiFi!

My senior prank was going to revolve around the printers. We were shocked to discover every printer not just in BG but across the entire district was accessible with no authentication of any kind. We cooked up ideas and were planning to print either porn or I has cheezburger/lolcat memes via telnet (I'm dating myself.)

Ultimately I got into other trouble before we could execute and figured this wasn’t worth not graduating over. I moved on and so happy to see a much better prank on this same network happen so many years later with almost no repercussions. Congratulations and great prank!

Re: IoT hacking and rickrolling my high school district

#185

I feel so dumb when I read kids doing these things. Back in High School all I knew was how I could run arbitrary executable files by renaming them to calc.exe. We also did the classic "take a screenshot of the desktop, set it as the wallpaper, then remove all icons and the start menu" thing.

All this. Plus TI-86 king fu. Though this was 1991-1995, IoT didn’t exist and email and web access was mostly through AOL or Prodigy.

Re: IoT hacking and rickrolling my high school district

#186
Preface this by saying this was a smaller school, and the students had limited access to wifi. For example a teacher would create a set of radius credentials that would only be active for 1 hour. Since data was also expensive that was not an easy work around.

In my grade 11 electronics class, one project we were assigned was to create a digital clock with notifications for one of the teachers. Me and a friend set up a raspberry pi with magic mirror installed on it, and modified some available plugins at the time to allow a google calendar for test dates embedded on the display. The teacher was quite pleased with this, but we convinced him to hard wire it to the network for "stability". In the background we had installed a vpn connection to one of my vps that I used to host my website, and created a new set of sudo enabled credentials naming it magic-mirror or something. The teacher then reviewed the project and changed the normal user credentials etc. Then right before it was installed in the ceiling, we attached a wifi adapter to the pi. A week or so later we remoted in through the tunnel and enabled a wireless hotspot from the pi. This provided us with internet while we were close to the classroom for the next year. People also over time learned that you could extend the range by hot spotting additional jumps using laptops.

Re: IoT hacking and rickrolling my high school district

#187

Serious question. What, if any, instruction do kids these days receive regarding what's allowed on computer systems? I remember in high school poking around a network drive until I found an executable with the name "SEND" in the name. I had a sense that it would send some kind of message somewhere, but I honestly didn't know where or to how many people. I was quite surprised when all the screens in our computer lab f…

I can't answer your question, but I strongly suspect the backstory on your furious IT admin went something like this:

  * SEND happened
  * Minor kerfluffle ensued among various functionaries
  * Big Boss worried that something Big was going on
  * IT admin was questioned and had no answers
  * Simmer for a few days, Big Boss repeating questions and IT admin being flummoxed
  * Eventually adequate logs are found and correlated that place you as the likely responsible party
  * IT admin is lathered up about a big nothing because Big Boss keeps asking and their competence is in question
  * IT admin unleashes the pent up frustration of a few days of stupidity and job security uncertainty on you, and is not satisfied that all this drama was initiated by boredom and not malice
  * IT admin reports to Big Boss, who basically brushes it off because they have moved on to other things -- and at the end of the day knows they run an organization filled with kids, some of whom are more curious than others
  * Issue disappears

Re: IoT hacking and rickrolling my high school district

#188
post #2

The fact that the administration didn't choose to sue them to oblivion is refreshing. I hope we'll see a trend in the future of educator being smart enough to admit that they made a mistake and to encourage the students to develop their talent. One can only hope.

Yep. What they did was wrong. And by doing so they threw themselves at the mercy of the entity they hacked. The refreshing part is that the entity did the morally right thing and showed mercy.

> What they did was wrong.

It was certainly against the rules. I'm not so sure it was wrong.

Re: IoT hacking and rickrolling my high school district

#189

Earlier quoted context omitted.

Many criminal cases require establishing intent. Pranks may be harmful as you allude to, but the intent still matters.

How does that work? Can you murder someone for a prank and say your intent was just a prank so it was fine?

Intent separates murder from manslaughter in most states in thr USA, so yeah, a death from a prank is tangible different.

Re: IoT hacking and rickrolling my high school district

#190

Earlier quoted context omitted.

How does that work? Can you murder someone for a prank and say your intent was just a prank so it was fine?

Intent separates murder from manslaughter in most states in thr USA, so yeah, a death from a prank is tangible different.

But they did intend to disrupt the systems in this case. The impact was their exact intent.
Post reply on HN