Live data from Hacker News

IoT hacking and rickrolling my high school district

whitehoodhacker.net

201–210 of 399 posts

Re: IoT hacking and rickrolling my high school district

#201

Earlier quoted context omitted.

> a prank Why do we tolerate pranks? You shouldn't be able to interfere with someone else and say 'just a prank bro'. Leave other people's things alone. Don't create work for other people. Don't bother people just trying to do their jobs. Don't impose your sense of humour on others. These all seem like basics to me? If you think someone's funny? Great. Just don't bother other people with it. Do it with your own stuff…

> Why do we tolerate pranks? As the author points out early on in this article, most school districts would not have tolerated a prank like this. In fact this is the only example I know about a prank this big that got the response of toleration the author documented in the article. > You shouldn't be able to interfere with someone else and say 'just a prank bro'. The students made a report of what they did and presen…

> The students made a report of what they did and presented it to the administration.

So what?

Can I push you down in the street and then hand you a report explaining how I was able to push you down and that makes it all ok?

Re: IoT hacking and rickrolling my high school district

#202
post #103

Reminds of me my school leaving prank. I rewrote the whole internet on my school's computers. Google's logo became "Leavers '08", Facebook became "Hatebook" and was red, YouTube only played videos of cats, amongst other things. These were the days when nothing had SSL, so you could just intercept and rewrite traffic! My only requirement was: do no actual damage It was implemented as a Debian live CD that you could dr…

I don't think this happened.

I'm less skeptical. OP already mentioned that most things were not encrypted back then, so this was probably still in the days of transparent proxies, so OP could have "just" added one with some ARP spoofing. They were somewhat common in school and office networks, and like regular HTTP proxies (except the transparent ones had the traffic redirected forcefully to them) they essentially consumed HTTP requests and sent new ones out to The Internet. While mostly used for caching and blocking, it seems relatively simple to me that OP could have just replaced e.g. some stylesheets served back to the client.

Re: IoT hacking and rickrolling my high school district

#203

Earlier quoted context omitted.

Who had to clean up here? Author cleaned up their own problem and literally delivered a detailed security report on how to fix the issue (not the damage done by the prank, which was zero).

Seems like it disrupts a class to me? What about the students who don't want to have their class disrupted? What about the teacher who has to catch up later? What if these people don't want your sense of humour imposed on them? I think it's ethically wrong.

>One of our top priorities was to avoid disrupting classes, meaning we could only pull off the prank before school started, during passing periods, or after school.

Re: IoT hacking and rickrolling my high school district

#204

Earlier quoted context omitted.

Seems like it disrupts a class to me? What about the students who don't want to have their class disrupted? What about the teacher who has to catch up later? What if these people don't want your sense of humour imposed on them? I think it's ethically wrong.

>One of our top priorities was to avoid disrupting classes, meaning we could only pull off the prank before school started, during passing periods, or after school.

Their own video literally shows a class of people watching it happen.

Re: IoT hacking and rickrolling my high school district

#205
post #194
post #103

Reminds of me my school leaving prank. I rewrote the whole internet on my school's computers. Google's logo became "Leavers '08", Facebook became "Hatebook" and was red, YouTube only played videos of cats, amongst other things. These were the days when nothing had SSL, so you could just intercept and rewrite traffic! My only requirement was: do no actual damage It was implemented as a Debian live CD that you could dr…

Wow, somehow that use of random and slowly ARP proxying as a duct-taped together load balancing mechanism makes this so much cooler. I'm not sure I quite understand the details, though. I assume there was only one gateway for the segment, so were the spoofed ARP replies unicast instead of broadcast? Otherwise, wouldn't all clients just switch to whatever machine announced their spoof for the gateway IP last?

This was 13 years ago so my memory is fuzzy... if I recall correctly, spoofed ARP replies were unicasted to every possible address on the network. It switched from machine to machine slowly, which is fine because they all served the same content.

There were several subnets at the school, each with its own gateway. I remember having to set up live CDs in several computer labs to cover each of the subnets.

Re: IoT hacking and rickrolling my high school district

#206
Working in IT/tech for school district is the worst. My experience from many years ago - around 2002, I think:

1. First day on the job, email to boss: "Hey, the computer lab at Springfield High has a ton of known security flaws that are begging to be exploited."

2. Reply, 1 week later: "Sorry, we don't have any money for that. Just keep everything up-and-running."

3. 3 weeks later the computer lab at Springfield High got "hacked". All the computers displayed a popup window that said, "Miss Krabappel is a dyke!" (sorry for the offensive language)

4. Next day, email from boss: "The computer lab at Springfield High was hacked! Figure out how to fix this and make sure it doesn't happen again!"

5. A few days later Miss Krabappel filed to sue the school district. The local newspaper picked up the story.

6. Email from boss, in full panic mode: "I need you to figure out who hacked the computer lab at Springfield High so we can report him to the police!"

7. A week later an independent consulting firm was brought in to help identify the person behind the "hack". I heard they were paid $50K and found nothing. However, the kid got ratted out when he told all his friends. (It wasn't Bart Simpson! ;) )

8. Several weeks later: meeting to discuss working with a consulting firm that's gonna fix all the security issues because the current staff (me and my team) lacks the skills.

9. About 6 months later, I quit.

Re: IoT hacking and rickrolling my high school district

#207
post #4

Earlier quoted context omitted.

I'm glad to see a kid using bash and not something like gulp PowerShell

Credit where credit is due, we all WISH *nix had something like PowerShell. Passing strings from program to program is a pain, passing around .NET objects instead is a great step forward, as can be seen by the several attempts at similar shells passing around JSON objects.

Parsing strings in Powershell is super complicated compared to regular Unix tools

Re: IoT hacking and rickrolling my high school district

#208

Earlier quoted context omitted.

Hypothetically it could happen and even if it isn’t true, I feel it adds something to the conversation. Besides, you cited as many sources as they did.

Sounds way overly complex for a high schooler to pull off. At least the OP sounded legitimate, the details didn't sound over the top.

I think you're underestimating motivated high schoolers.

When I was in high school I was a huge Linux fan and had a side job as a network administrator for small companies in my town. I don't know if I would have gotten the "random ARP load balancing" idea, but overall it seems well within the knowledge admins of the days had about TCP/IP.

When I was between 15 and 17 or so, I wrote small HTTP, DNS servers etc. in C++ for fun (straightforward implementations and not better in any way, so in the end just learning exercises), and I definitely had friends who did similar things.

Re: IoT hacking and rickrolling my high school district

#209
post #103

Reminds of me my school leaving prank. I rewrote the whole internet on my school's computers. Google's logo became "Leavers '08", Facebook became "Hatebook" and was red, YouTube only played videos of cats, amongst other things. These were the days when nothing had SSL, so you could just intercept and rewrite traffic! My only requirement was: do no actual damage It was implemented as a Debian live CD that you could dr…

based on http://www.ex-parrot.com/pete/upside-down-ternet.html by chance? or parallel evolution? :D

Re: IoT hacking and rickrolling my high school district

#210

Working in IT/tech for school district is the worst. My experience from many years ago - around 2002, I think: 1. First day on the job, email to boss: "Hey, the computer lab at Springfield High has a ton of known security flaws that are begging to be exploited." 2. Reply, 1 week later: "Sorry, we don't have any money for that. Just keep everything up-and-running." 3. 3 weeks later the computer lab at Springfield High…

Are you me?! This basically was my experience working for a very large school district in the early 2000's. My favorite was they asked me to train a school bus driver to be the newest member of the IT staff because "they wanted to learn computers", it also just so happened that this person was the only person their budget could afford (less than 40k/year).

I worked for them as a contractor for a while and one of the big issues they had was they had tons of money to implement new technology (mostly from grants and things like that), but nearly nothing to maintain old tech. They could buy new computers all day long, but if something needed to be repaired/updated/maintained, there was no budget or resources to do it. So there were all sorts of fun issues, like they would buy computers and before they could get deployed their warranty would expire (since they weren't allowed to buy 3 year warranties on the computers) and computers with bad HDDs would get disposed of, even though the fix might be $50 and 10 minutes of time.

Post reply on HN