Live data from Hacker News

IoT hacking and rickrolling my high school district

whitehoodhacker.net

191–200 of 399 posts

Re: IoT hacking and rickrolling my high school district

#192
post #103

Reminds of me my school leaving prank. I rewrote the whole internet on my school's computers. Google's logo became "Leavers '08", Facebook became "Hatebook" and was red, YouTube only played videos of cats, amongst other things. These were the days when nothing had SSL, so you could just intercept and rewrite traffic! My only requirement was: do no actual damage It was implemented as a Debian live CD that you could dr…

I don't think this happened.

Re: IoT hacking and rickrolling my high school district

#193
post #103

Reminds of me my school leaving prank. I rewrote the whole internet on my school's computers. Google's logo became "Leavers '08", Facebook became "Hatebook" and was red, YouTube only played videos of cats, amongst other things. These were the days when nothing had SSL, so you could just intercept and rewrite traffic! My only requirement was: do no actual damage It was implemented as a Debian live CD that you could dr…

I don't think this happened.

Hypothetically it could happen and even if it isn’t true, I feel it adds something to the conversation. Besides, you cited as many sources as they did.

Re: IoT hacking and rickrolling my high school district

#194
post #103

Reminds of me my school leaving prank. I rewrote the whole internet on my school's computers. Google's logo became "Leavers '08", Facebook became "Hatebook" and was red, YouTube only played videos of cats, amongst other things. These were the days when nothing had SSL, so you could just intercept and rewrite traffic! My only requirement was: do no actual damage It was implemented as a Debian live CD that you could dr…

Wow, somehow that use of random and slowly ARP proxying as a duct-taped together load balancing mechanism makes this so much cooler.

I'm not sure I quite understand the details, though. I assume there was only one gateway for the segment, so were the spoofed ARP replies unicast instead of broadcast? Otherwise, wouldn't all clients just switch to whatever machine announced their spoof for the gateway IP last?

Re: IoT hacking and rickrolling my high school district

#195

Earlier quoted context omitted.

> But do it with your own things then. Don't bother anyone else or touch anyone else's things. You're really oversimplifying here. Something tells me this highschooler doesn't personally own the breadth of commercial equipment that he hacked for this prank. > And no worker should ever have to do any work (such as reset a computer system) because of your prank. Workers have enough work to do and enough hassles in thei…

> Something tells me this highschooler doesn't personally own the breadth of commercial equipment that he hacked for this prank. So they shouldn't have done it. > Okay, let's all be worker robots :) It's not about what you want to do. It's about what some low-paid worker who has to clean up after you thinks. Or some other student inconvenienced by your prank thinks. If you're impacting on someone else's life then you…

Who had to clean up here? Author cleaned up their own problem and literally delivered a detailed security report on how to fix the issue (not the damage done by the prank, which was zero).

Re: IoT hacking and rickrolling my high school district

#196
post #103

Reminds of me my school leaving prank. I rewrote the whole internet on my school's computers. Google's logo became "Leavers '08", Facebook became "Hatebook" and was red, YouTube only played videos of cats, amongst other things. These were the days when nothing had SSL, so you could just intercept and rewrite traffic! My only requirement was: do no actual damage It was implemented as a Debian live CD that you could dr…

I don't think this happened.

https://www.dropbox.com/s/hyt24p4j43szpdi/logo.gif?dl=0

Re: IoT hacking and rickrolling my high school district

#197

Earlier quoted context omitted.

> Something tells me this highschooler doesn't personally own the breadth of commercial equipment that he hacked for this prank. So they shouldn't have done it. > Okay, let's all be worker robots :) It's not about what you want to do. It's about what some low-paid worker who has to clean up after you thinks. Or some other student inconvenienced by your prank thinks. If you're impacting on someone else's life then you…

Who had to clean up here? Author cleaned up their own problem and literally delivered a detailed security report on how to fix the issue (not the damage done by the prank, which was zero).

Seems like it disrupts a class to me? What about the students who don't want to have their class disrupted? What about the teacher who has to catch up later?

What if these people don't want your sense of humour imposed on them?

I think it's ethically wrong.

Re: IoT hacking and rickrolling my high school district

#198

Earlier quoted context omitted.

I don't think this happened.

Hypothetically it could happen and even if it isn’t true, I feel it adds something to the conversation. Besides, you cited as many sources as they did.

Sounds way overly complex for a high schooler to pull off. At least the OP sounded legitimate, the details didn't sound over the top.

Re: IoT hacking and rickrolling my high school district

#199

Earlier quoted context omitted.

Posts like yours validate the insane over criminalization of what essentially amounts to a prank. I had literally the exact same experience in high school. Got expelled and had to get a GED. They could have easily pressed charges. Part of the issue is people like you who advocate for respecting "the system" and essentially scaring kids into not doing anything. Except that simply re-enforces the draconian laws that ar…

> a prank Why do we tolerate pranks? You shouldn't be able to interfere with someone else and say 'just a prank bro'. Leave other people's things alone. Don't create work for other people. Don't bother people just trying to do their jobs. Don't impose your sense of humour on others. These all seem like basics to me? If you think someone's funny? Great. Just don't bother other people with it. Do it with your own stuff…

> Why do we tolerate pranks?

As the author points out early on in this article, most school districts would not have tolerated a prank like this. In fact this is the only example I know about a prank this big that got the response of toleration the author documented in the article.

> You shouldn't be able to interfere with someone else and say 'just a prank bro'.

The students made a report of what they did and presented it to the administration.

I guess to be generous I could reinterpret your concern to be, "Do students in every school district in the U.S. get to avoid criminal prosecution under the draconian CFAA by constructing a complex hack tailored to avoid interrupting regular school business, then writing up a report and giving a powerpoint presentation to an apparently enlightened and tech-savvy administration to help them strengthen their network defenses?" In that case, point taken.

Re: IoT hacking and rickrolling my high school district

#200

I told my district that I could change my race at-will via a hidden form on the profile page. I changed it to "Purple". Got a call back from some IT guy telling me I accessed their computer without authorization, and that if it happened again, they'd press charges. I asked to be put through to the IT administrator, and he laughed and told me don't worry about it... Sometimes, they can handle it well. Very glad they d…

I think the dilenation point comes in with whether they are an IT "person" or a school administrator.

Regularly, I would end up in trouble in my High School for things like bypassing the root account (using ShellShock), or nullifying their executable restrictions (because I needed to run my own executables for a work/study program). If I got caught, the IT admin would sit down and we'd chat about what happened, how they could improve their security and such. An administrator caught on to one of my shenanigans, bypassing the content block because I wanted to read a "hacking" article, and threatened me with suspension. Supposedly, she reported the incident to IT, and IT told her to not bother me anymore.

Post reply on HN