Live data from Hacker News

IoT hacking and rickrolling my high school district

whitehoodhacker.net

271–280 of 399 posts

Re: IoT hacking and rickrolling my high school district

#271

Working in IT/tech for school district is the worst. My experience from many years ago - around 2002, I think: 1. First day on the job, email to boss: "Hey, the computer lab at Springfield High has a ton of known security flaws that are begging to be exploited." 2. Reply, 1 week later: "Sorry, we don't have any money for that. Just keep everything up-and-running." 3. 3 weeks later the computer lab at Springfield High…

I 'worked' for my own high school's IT dept, a few hours a week, as a student. It was an amazing experience working with those guys. I learned so many things, from how to punch, terminate, and run cables to how to set up a Ghost image and deploy it en masse across the district. One day one of the old macs was showing the frowny face in a in-session classroom. Boss sent me down there with specific instructions: "pull…

And now ... a group of 30 - no-longer - students treat their IT equipment with hits by a screw driver ... because it works.

Our education system is amazing ;)

Re: IoT hacking and rickrolling my high school district

#272
post #158

Earlier quoted context omitted.

This is a very complicated problem. Unless you kill someone I generally don’t believe in life long criminal records. They only serve to drive people into further criminality. I imagine for a robbery you could get 5 years in prison, 5 years with it on your record and then automatically get it expunged. Back to the topic at hand , what if the IT hack stopped people from getting paid on time. How many suffered emotional…

I don't think it's the record's duty to keep you from being employed. That's the employer's decision. Even if I agree that it's a dumb practice, you're proposing a world where employers are free to refuse your hire if you (eg.) were fired from a job 26 years ago, but not because you were convicted of a crime.

You don't have to tell them you were fired

Re: IoT hacking and rickrolling my high school district

#273

Working in IT/tech for school district is the worst. My experience from many years ago - around 2002, I think: 1. First day on the job, email to boss: "Hey, the computer lab at Springfield High has a ton of known security flaws that are begging to be exploited." 2. Reply, 1 week later: "Sorry, we don't have any money for that. Just keep everything up-and-running." 3. 3 weeks later the computer lab at Springfield High…

> First day on the job, email to boss

That email chain could be used to prove that you did what you could before the incident. If you were so inclined.

Re: IoT hacking and rickrolling my high school district

#275

Earlier quoted context omitted.

Id actually wonder if criminal history matters when you have skills like this that are very much in demand. If this went to court, the charges of malicious intent would likely not stick, so jailtime could likely be avoided in leu of fine/community service. Competent tech companies will not give a shit about criminal record of this nature. Expulsion from school is pretty much irrelevant, especially for CS careers. You…

It depends on how regulated the particular industry is. If you're building consumer web apps at a startup, it probably won't matter. If you want to be a government contractor, it's probably a nonstarter.

Most of the industry where the guy will be paid appropriately is going to be private. Cyber security specialists for things like AWS get paid much more than any government contractor.

Re: IoT hacking and rickrolling my high school district

#276

Earlier quoted context omitted.

> a prank Why do we tolerate pranks? You shouldn't be able to interfere with someone else and say 'just a prank bro'. Leave other people's things alone. Don't create work for other people. Don't bother people just trying to do their jobs. Don't impose your sense of humour on others. These all seem like basics to me? If you think someone's funny? Great. Just don't bother other people with it. Do it with your own stuff…

By saying that you're imposing your sense of humor on others too (as in, the prankster's sense of humor is "pranks are funny"; your sense of humor is "pranks are not funny"; according to your comment your stance is that pranks shouldn't be tolerated). You don't have to laugh, and you're free to say you don't like pranks. But tolerating other people's opinions/sense of humor/whathaveyou seems like basics to me. (Maybe…

It’s like smoking. I should tolerate someone smoking in their own home. Should I have to tolerate someone smoking on public transport next to me? Absolutely not. Even if it’s their opinion that smoke is nice.

Re: IoT hacking and rickrolling my high school district

#277

Earlier quoted context omitted.

> All the computers displayed a popup window When I engaged in `net send` shenanigans at the local community college, at least the IT staff was smart enough to know where to scramble a runner whenever those dialog boxes popped up across campus. "ALL YOUR BASE ARE BELONG TO US" was quite the meme then, but apparently they thought it was some form of cyber-terrorism.

O mannn I was suspended from HS, and banned for 2 years from touching school computers for net send shenanigans as I wasn't smart enough to cloak the originating workstation. My message to every single computer in our HS: "Hey what's up!" my friend added to this: "Your network (H:/) drive is being deleted." School administrators and teachers did not find this funny.

About a year after the college prank, I was recounting the incident to a helpdesk coworker on a relatively quiet Saturday. He refused to believe that "net send" even existed, and dared me to do it. So I did, the content of that message being a rather tame "This is a test message, press OK to close."

He was on phones, got about twenty calls including one from a VP - with even more popping in throughout the following week as people returned to workstations to see the dialog. We were able to play it off as "testing the network" (not wrong I suppose), but our manager was a responsible sort and had it blocked with a group policy shortly after.

Re: IoT hacking and rickrolling my high school district

#278
Fellow high school students just loved me when, after giving up on ophcrack, I found out that on Windows XP, a limited account could simply escalate privileges by scheduling a command.

First installed some open source FPS on all computers. They got found and removed, and we all got moved to guest accounts.

I then found something called DreampackPL. Just pop in the CD, boot on it, replace the pinball game with their executable, reboot. And voilà, access to everything. Just remember to put the pinball back afterwards.

That’s when the BIOS got password protected.

My next step? Opening the machines up to move a jumper. Do everything all over again, but this time on a hidden windows account.

The IT admin was a student’s parent. Just spent years making the poor guy run in circles before the school administration finally gave up.

Re: IoT hacking and rickrolling my high school district

#279
post #247

Earlier quoted context omitted.

> All the computers displayed a popup window When I engaged in `net send` shenanigans at the local community college, at least the IT staff was smart enough to know where to scramble a runner whenever those dialog boxes popped up across campus. "ALL YOUR BASE ARE BELONG TO US" was quite the meme then, but apparently they thought it was some form of cyber-terrorism.

A good buddy of mine did the same, but with the message "DOOM!" His punishment was community service, and the service was having to be basically an intern for the school IT guy. Smart administration, really.

I received a similar punishment for running an autoclicker against some charity adware installed by a well-meaning administrator.

That semester of internship was pretty fun, all things considered.

Re: IoT hacking and rickrolling my high school district

#280

Working in IT/tech for school district is the worst. My experience from many years ago - around 2002, I think: 1. First day on the job, email to boss: "Hey, the computer lab at Springfield High has a ton of known security flaws that are begging to be exploited." 2. Reply, 1 week later: "Sorry, we don't have any money for that. Just keep everything up-and-running." 3. 3 weeks later the computer lab at Springfield High…

This is not unique to school districts at all, but any organisation, large or small, that treats IT/tech only as a necessary inconvenience, instead of an actual part of the org deserving of resources, planning, and people.

If you work in tech/IT, and the big bosses consider you and your org disparagingly, leave immediately. Something bad will happen with their IT, and you will be blamed, hassled, and harrassed for it.

Post reply on HN