Live data from Hacker News

IoT hacking and rickrolling my high school district

whitehoodhacker.net

231–240 of 399 posts

Re: IoT hacking and rickrolling my high school district

#231

Working in IT/tech for school district is the worst. My experience from many years ago - around 2002, I think: 1. First day on the job, email to boss: "Hey, the computer lab at Springfield High has a ton of known security flaws that are begging to be exploited." 2. Reply, 1 week later: "Sorry, we don't have any money for that. Just keep everything up-and-running." 3. 3 weeks later the computer lab at Springfield High…

Oh yeah the early 2000s, not a great day to be a hacker (by hacker I mean actual hacker: http://catb.org/~esr/faqs/hacker-howto.html).

I remember getting yelled at for changing the display resolution and typing a few commands in DOS to change file names quickly.

Computers were never up to date of course, we had cathodic displays up to 2010.

Re: IoT hacking and rickrolling my high school district

#232

I told my district that I could change my race at-will via a hidden form on the profile page. I changed it to "Purple". Got a call back from some IT guy telling me I accessed their computer without authorization, and that if it happened again, they'd press charges. I asked to be put through to the IT administrator, and he laughed and told me don't worry about it... Sometimes, they can handle it well. Very glad they d…

I think the dilenation point comes in with whether they are an IT "person" or a school administrator. Regularly, I would end up in trouble in my High School for things like bypassing the root account (using ShellShock), or nullifying their executable restrictions (because I needed to run my own executables for a work/study program). If I got caught, the IT admin would sit down and we'd chat about what happened, how t…

This is spot on. I Used to work as a sysadmin for a large private school and always enjoyed the red/blue dynamic of tech team vs the smarter students trying to poke through the restrictions of their laptops and network.

It was always disappointing when they took it too far and were directly caught by teachers or administration before I could tell them they were being a bit too blatantly malicious.

Re: IoT hacking and rickrolling my high school district

#233

Someone I know did something similar, was arrested in their college dorm, and at the sentencing hearing in federal court was fined and sentenced to 5 years probation, and now has a criminal record. This kid is very very lucky. Obviously they violated the CFAA which carries severe criminal penalties. They engaged in actual hacking without any permission or defined scope. And they exploited the system without any respo…

The CFAA exists to make sure that nobody can use computers and the internet to have any power over even tyrannical authorities.

CFAA and the DMCA are some of the worst, most authoritarian laws ever created, and they exist to do nothing other ensure a system where being rich enough to afford lawyers means you don't have to do anything else.

Use default passwords like an idiot and someone uses their autofill? They're the criminal, not you.

Let people just change the account number in the address bar and switch accounts with zero authorization or authentication? They're the criminal, not you. (Bank of America literally did this.)

Have open access for students to download papers and one of them uses it to download all of them? They're the criminal, not you. (RIP Aaron Swartz)

I support jury nullification for the CFAA and DMCA and so should everyone reading this.

Re: IoT hacking and rickrolling my high school district

#234

Earlier quoted context omitted.

> What they did was wrong. It was certainly against the rules. I'm not so sure it was wrong.

If I broke into your home tonight to play a prank on you and then handed you a white paper about how to better secure it, how would you feel?

Breaking and entering vs. playing a harmless video at the end of the day in school.

False equivalence.

Re: IoT hacking and rickrolling my high school district

#235

Earlier quoted context omitted.

Posts like yours validate the insane over criminalization of what essentially amounts to a prank. I had literally the exact same experience in high school. Got expelled and had to get a GED. They could have easily pressed charges. Part of the issue is people like you who advocate for respecting "the system" and essentially scaring kids into not doing anything. Except that simply re-enforces the draconian laws that ar…

Unfortunately, "desensitizing" people to existing law by illegal rebellions is a Pyrrhic victory at best when the consequences are so impactful to the individuals that martyr for The Cause. There are processes for changing the laws without sending kids to jail, having to treat kids like terrorists, or potentially making the law even harsher because it isn't effective enough to dissuade lawbreaking. If the laws feel d…

>There are processes for changing the laws without sending kids to jail, having to treat kids like terrorists, or potentially making the law even harsher because it isn't effective enough to dissuade lawbreaking.

And none of them work, or will ever work in this oligarchy. The rich own the congress, and the senate, and they benefit greatly from these things. America hasn't been a functioning republic in at least 50 years.

Re: IoT hacking and rickrolling my high school district

#236

Working in IT/tech for school district is the worst. My experience from many years ago - around 2002, I think: 1. First day on the job, email to boss: "Hey, the computer lab at Springfield High has a ton of known security flaws that are begging to be exploited." 2. Reply, 1 week later: "Sorry, we don't have any money for that. Just keep everything up-and-running." 3. 3 weeks later the computer lab at Springfield High…

Are you me?! This basically was my experience working for a very large school district in the early 2000's. My favorite was they asked me to train a school bus driver to be the newest member of the IT staff because "they wanted to learn computers", it also just so happened that this person was the only person their budget could afford (less than 40k/year). I worked for them as a contractor for a while and one of the…

That's funny, I worked for a school district about 10 years ago and our IT director was also the transportation director. He knew nothing about IT but I guess they had to give the role to someone at one point and it was him. I think I lasted 2 years before finding my current job.

Re: IoT hacking and rickrolling my high school district

#237

In case anyone else is wondering how the heck the kid got access to the district's network, the key sentence is hidden in the middle of the post: Since freshman year, I had complete access to the IPTV system. I only messed around with it a few times and had plans for a senior prank, but it moved to the back of my mind and eventually went forgotten. Not sure why they don't go into more detail about how exactly "comple…

He explains it quite clearly that him and his friends were port scanning the schools network for funsies.

"From the results, we found various devices exposed on the district network. These included printers, IP phones... and even security cameras without any password authentication!"

Re: IoT hacking and rickrolling my high school district

#238
post #103

Reminds of me my school leaving prank. I rewrote the whole internet on my school's computers. Google's logo became "Leavers '08", Facebook became "Hatebook" and was red, YouTube only played videos of cats, amongst other things. These were the days when nothing had SSL, so you could just intercept and rewrite traffic! My only requirement was: do no actual damage It was implemented as a Debian live CD that you could dr…

> I rewrote the whole internet

The web is not the whole internet, and Google, Facebook and YouTube are not the whole web.

Makes me sad to think that someone could possibly believe either of these things. I suspect the rest is just something you read somewhere, but don't understand what the words mean. Enjoy your MIPs (meaningless internet points).

Re: IoT hacking and rickrolling my high school district

#239
post #223

Three things are remarkable about this, and make it a happy story. First, that the pranksters were so egregiously responsible in the way they went about it. They avoided disrupting any actual educational activities; it was meant to be harmless fun, not vandalism. No harm came to anything here. Second, that they documented their findings to the administration as part of the action, including recommendations for improv…

The school district itself was relatively chill, however the individual deans freaked out. Because the penetration report was sent to the tech team and not the deans, the deans were intent on finding out exactly who did the hack to find something to report to their bosses (and according to them concern about the grade book system being exposed?? Not sure how you’re supposed to rick roll a grade book but if anyone has…

>and according to them concern about the grade book system being exposed??

Junior year in high school, I got suspended for "hacking."

The tl;dr is that I was using a proxy to fetch assignments for class (because the county decided "yeah, this state run Moodle instance is obviously not appropriate for education" and one of my classes used Moodle) and got caught with the proxy configuration screen open. I wish I was joking.

Anyway, when I was sitting in the guidance counselor's office as the teacher was talking up how "dangerous" I was, I noticed a sticky note with a username and password written on it. Turns out it was an admin account for the gradebook, though I think it was just intended for scheduling.

I never did anything bad with those credentials, but that really tanked what little respect I still had for the administrators there.

On a lighter note, when stack exchange & co got blocked the next year, I was good friends with the librarians since I helped out a fair amount fixing up their laptop carts (and doing other things the sysadmins were too busy to take care of), and they were able to get them unblocked. It taught me a lot about office politics: people are willing to return favors, so you should always make those connections.

Post reply on HN