Live data from Hacker News

IoT hacking and rickrolling my high school district

whitehoodhacker.net

321–330 of 399 posts

Re: IoT hacking and rickrolling my high school district

#321

Working in IT/tech for school district is the worst. My experience from many years ago - around 2002, I think: 1. First day on the job, email to boss: "Hey, the computer lab at Springfield High has a ton of known security flaws that are begging to be exploited." 2. Reply, 1 week later: "Sorry, we don't have any money for that. Just keep everything up-and-running." 3. 3 weeks later the computer lab at Springfield High…

I 'worked' for my own high school's IT dept, a few hours a week, as a student. It was an amazing experience working with those guys. I learned so many things, from how to punch, terminate, and run cables to how to set up a Ghost image and deploy it en masse across the district. One day one of the old macs was showing the frowny face in a in-session classroom. Boss sent me down there with specific instructions: "pull…

I believe the term for this is ‘percussive maintenance’

Re: IoT hacking and rickrolling my high school district

#322

Earlier quoted context omitted.

I haven’t thought of net send in years. Circa 2000 I worked at Cisco and added some javascript to my profile in the corporate directory that sent me a net send message with the hostname of the computer that viewed my profile. At that time the hostname usually included the employees username, so I had a nice heads up that somebody was looking me up. I should have left it at that, but Ingot cheeky and also did a net se…

Curious how you escaped a (browser?) With JS to do "native" net send? Assume it was some activeX?

The js probably pinged their own server with then did the 'net send'

Re: IoT hacking and rickrolling my high school district

#323
Ugh. I worked school IT in the past. You're not as smart as you think you are. These vulnerabilities are typically known but there's not enough time, money, or the devices themselves can't really be locked down or hacker proofed anymore than they already.

IF you do something like this at least consider that someone else is going to be cleaning your mess up.

School kids are the worst users you can ask for. Unlike a normal business where they'd be punished or removed for something like this the kids will deliberately try to destroy the school network.

Re: IoT hacking and rickrolling my high school district

#324

Earlier quoted context omitted.

It depends on how regulated the particular industry is. If you're building consumer web apps at a startup, it probably won't matter. If you want to be a government contractor, it's probably a nonstarter.

Most of the industry where the guy will be paid appropriately is going to be private. Cyber security specialists for things like AWS get paid much more than any government contractor.

That's not really the best example; AWS is a government contractor. It isn’t a coincidence that HQ2 is a few blocks away from the Pentagon.

Re: IoT hacking and rickrolling my high school district

#325
post #34

When I was in High School (early 90's) we got a new computer system that nobody was using yet. I discovered there was an email system of some kind and that every student had an email address that we were not told about. I also discovered Tetris installed in a directory on the server. I was able to play Tetris and I could show other students how to access it, but it was inconvenient to get to. Therefore I decided I wo…

In like '89 when I was 19 and at university my work-study job was with the IT/ComputingResources department (old names). I worked as a graveyard shift NOC operator swapping tapes and handing out print-jobs, running system tests and stuff like that. We had several 24/7 computer labs full of Sun 3/50(60) workstations and things like that. But there was one lab that was closed from 10-5 overnight and I thought to myself "hey, there's a whole room of workstations not doing anything" so I wrote some scripts rsh/NFS and used that lab one night to run distributed ray-tracing jobs. The next day my account was disabled and I had to go talk to Security. They sorta laughed a bit then went like NO don't do that. I worked for the IT department for the next four years. Then I left for a decade. Then I came back and applied for a job. The interview lasted all of five minutes, I worked for a few months before being forcibly promoted up into the upper circle. My first task was to go around to the dozen others who had root and ask for advice and update the root-speech documentation. I got to Security.... tippity tappity "Oh, hello Mr. zengargoyle, let's see... '89 'misuse of computing resources'." LOL, still had root by the end of the day.

So, this is just to say... that places like education where people may stick around for a long while in the system and such. They probably do remember a bunch of events from even a decade ago. It's the good places that have a sense of humor or appreciation for a worthy harmless infraction. They may even be secretly proud or have some admiration.

Though I do sorta fear that I just happened to hit the tail end of old-school hackery where such things are such things are rewarded. Now get off my lawn.

Re: IoT hacking and rickrolling my high school district

#326
post #247

Earlier quoted context omitted.

> All the computers displayed a popup window When I engaged in `net send` shenanigans at the local community college, at least the IT staff was smart enough to know where to scramble a runner whenever those dialog boxes popped up across campus. "ALL YOUR BASE ARE BELONG TO US" was quite the meme then, but apparently they thought it was some form of cyber-terrorism.

A good buddy of mine did the same, but with the message "DOOM!" His punishment was community service, and the service was having to be basically an intern for the school IT guy. Smart administration, really.

Same punishment for me back in high school when I "guessed" the admin password. They all knew I didn't guess it and was given the job/community service. They kept the same password.

Re: IoT hacking and rickrolling my high school district

#327

Earlier quoted context omitted.

Intent separates murder from manslaughter in most states in thr USA, so yeah, a death from a prank is tangible different.

But they did intend to disrupt the systems in this case. The impact was their exact intent.

When people say "establishing intent" in terms of criminal cases, this is usually a shorthand for something more specifically defined in the law, like "intent to do harm" or something.

To use the murder example again: many people who commit manslaughter have all kinds of various intentions. The one murder is concerned with is whether or not they specifically had the intent to kill the person. "Establishing intent" in this scenario is specifically regarding that one intent. Not any intent.

Re: IoT hacking and rickrolling my high school district

#328
post #318

Earlier quoted context omitted.

There have been REPLs like PowerShell for ages, it's nothing really new. The only nuance in this is that it is new in the Windows ecosystem to have something like that supported by Microsoft. Ironically, it hasn't managed to displace the command prompt or batch files, so instead of having to deal with one thing, you now have to deal with two things. As for the passing of strings: it might seem like a pain, but as soo…

> Ironically, it hasn't managed to displace the command prompt or batch files It don't think they expect that people would rewrite their old scripts. That is actually silly to consider. Even with console vs terminal, they are concerned of backward compatibility and leaving it as is: > Windows Console will continue to ship within Windows for decades to come in order to ensure backward compatibility with the many milli…

They could just have an alternative interpreter mode to support batch files, or even have a cmdlet that does just that. If people like to point and click, associate that with a cmdlet (they can do that, right?) and there you go.

Re: IoT hacking and rickrolling my high school district

#330
post #223

Three things are remarkable about this, and make it a happy story. First, that the pranksters were so egregiously responsible in the way they went about it. They avoided disrupting any actual educational activities; it was meant to be harmless fun, not vandalism. No harm came to anything here. Second, that they documented their findings to the administration as part of the action, including recommendations for improv…

The school district itself was relatively chill, however the individual deans freaked out. Because the penetration report was sent to the tech team and not the deans, the deans were intent on finding out exactly who did the hack to find something to report to their bosses (and according to them concern about the grade book system being exposed?? Not sure how you’re supposed to rick roll a grade book but if anyone has…

> grade book system being exposed

In our high school they didn't expose the gradebook in that you could get in and change it, but we were able to see everyone else's grades. Teachers would post grades for their class and "obscure" it by posting it with the student ID (you were only supposed to know your own) next to the grade. But when the posted, the entire list was still in alphabetical order so it wasn't hard to figure out everyone's grade and student ID.

And the cherry on top of this was that all the students' passwords were their student ID.

Post reply on HN