Live data from Hacker News

IoT hacking and rickrolling my high school district

whitehoodhacker.net

341–350 of 399 posts

Re: IoT hacking and rickrolling my high school district

#341

Earlier quoted context omitted.

I 'worked' for my own high school's IT dept, a few hours a week, as a student. It was an amazing experience working with those guys. I learned so many things, from how to punch, terminate, and run cables to how to set up a Ghost image and deploy it en masse across the district. One day one of the old macs was showing the frowny face in a in-session classroom. Boss sent me down there with specific instructions: "pull…

> ...pull out the HD. I beat it with the handle, like a good 10 times... Heh. Nice. A coworker's Mac wouldn't boot. I couldn't hear the hard drive. It was a model with the tip of the spindle exposed. I found a pencil with a gummy eraser. Gave the spindle a twist as I turned the power on. Told the amazed user, "Do not turn off your computer until after you have backed up your data. That probably won't work twice." Goo…

Had a similar experience with the external HDD of a friend of a friend.

HDD wouldn't be recognized, sticking my ear to it i could only hear the motor emit a beep-like sound, no spin up.

Her masters thesis on it, inaccessible, i've opened up the case, removed the HDD, unscrewed the top and there was the drive arm, stuck in the mid of the platters...

Took a Torx screwdriver, turned the platters backwards and unstuck the drive arm...

Copied all data off of it and sent here to the nearest computer hardware store to get another drive...

Master thesis was successfully recovered!

Re: IoT hacking and rickrolling my high school district

#342
post #146

I'm interested to know how was he able to remote access to seemingly any machine in the network, from outside?

I had Chrome RDP access on a few machines setup earlier, since I could come in-person with my team for security competitions.

Hey, thanks for the reply. Appreciate the writeup too, it was a fun read. Hope you don't mind but I have a few more questions.

How were you able to get Chrome RDP access setup without admin privileges? I assume this is automatically blocked via group policy.

Now that you have Chrome RDP setup, how were you able to access these machines from outside the network from home?

"since I could come in-person with my team for security competitions" I'm really intrigued now. What were these security competitions about and were they part of a class you were in?

Re: IoT hacking and rickrolling my high school district

#343

Working in IT/tech for school district is the worst. My experience from many years ago - around 2002, I think: 1. First day on the job, email to boss: "Hey, the computer lab at Springfield High has a ton of known security flaws that are begging to be exploited." 2. Reply, 1 week later: "Sorry, we don't have any money for that. Just keep everything up-and-running." 3. 3 weeks later the computer lab at Springfield High…

My first thought: Your district had an IT department? I guess that's probably more common now than when I went to HS in the 90s but I'm fairly certain IT duties are still farmed out to a small business for the districts I live near.

Outside of that, though, I've talked to folks who worked in IT at a nearby hospital[0] and knew several who worked in IT at a University a town over and heard variations of your story. After ransomware hit a few hospitals across the country, my hope is that this is less common but I'd be surprised if anything is meaningfully better.

The problem with getting non-technical people to understand the importance of securing things is that they assume that everything provides a basic level of security. They read about hacks/attacks and hear about them on the news but they have probably not experienced one, personally[1]. They apply physical security considerations to the virtual world -- for instance, the keys you use to lock your front door are almost certainly terrible[2] but requiring physical access to the lock makes attacks on them rare. And that's the rub, it's the mistake in thinking that "Nobody cares about my stuff enough to hack me" which is the evidence used to justify the "it's never going to happen to me". It's a failure to understand that even if it were true that an attacker would literally have no use for anything you're protecting with a password (which is absolutely false -- your identity is enough) that another target will be chosen ahead of you[3]. On the internet, every target can be attacked at once, silently, from a distance and targets are chosen based on whether or not the attack succeeds.

In a High School, you can fully expect there's at least one of me in every graduating class. I'm surprised things like this don't happen all the time given how little attention is paid to network security/endpoint security in these places. No amount of threats of expulsion, legal action, etc will serve to help when your attackers are High School students[4]. The same part of their brain that makes them believe they're immortal/causes irresponsible behavior early-on in driving causes them to not understand the real probability that they will face criminal charges which is coupled with them not fully understanding how badly those criminal charges will affect the rest of their lives.

[0] The discussion arose after he had watched Season 1 of Mr. Robot and said "that's exactly how it is here except we have a (technical) staff of two rather than one"

[1] I can't tell you how many extended family members have shared that they still use a single password for every account and in a few cases, that password might as well be a variation of "Password".

[2] I have a close friend who learned how to pick locks as a hobby; he filed me off a bump key and taught me how to use it, whacking it with a branch of a tree; I was able to open my supposedly "extra secure" dead bolt pretty consistently with about 15 minutes of practice, he's picked each of my locks at one time or another.

[3] The old "You can't outrun the bear, but if you and your friend are being chased by the same bear, you only need to outrun your friend".

[4] I used to tell my kids that our High School not only had no doors in the stalls of the mens room, there had never been any doors designed into the plan. The partitions were brick, there were no holes, anywhere, where doors had been removed. I figured this was to make it easier to catch kids smoking but while fixing his PC, I asked the principal about it. His answer was "vandalism" -- students would rip them out. Reallt?! I couldn't imagine this. Fast forward to this year, the doors on the stalls at my kid's HS were ripped out by students during the first week of class. The kids were caught, criminally charged and had to pay for the damage. Their reason? They saw someone do it on TikTok and didn't think they'd get caught (there are 2 dome cameras at the entry to each bathroom!). Despite paying for the damage, the doors are not coming back this year -- I'd wager they'll never come back.

Re: IoT hacking and rickrolling my high school district

#344
post #286

Working in IT/tech for school district is the worst. My experience from many years ago - around 2002, I think: 1. First day on the job, email to boss: "Hey, the computer lab at Springfield High has a ton of known security flaws that are begging to be exploited." 2. Reply, 1 week later: "Sorry, we don't have any money for that. Just keep everything up-and-running." 3. 3 weeks later the computer lab at Springfield High…

I got two Saturday detentions for finding that same tool (also ~2002) - though I just typed “Hi” and hit send - to everyone on the school network. I of course didn’t really know what I was doing. Looking back, this was a very strange punishment. Jokes on them I guess - left Oklahoma after HS and am now a software engineer in the Bay Area.

If only we could have reframed our approach to these situations.

Provided what was sent/defaced/etc wasn't hate speech or punching down on someone else, we should have really used these events as flags for identifying kids who could hone their computer skills into something "productive".

Re: IoT hacking and rickrolling my high school district

#346

Three things are remarkable about this, and make it a happy story. First, that the pranksters were so egregiously responsible in the way they went about it. They avoided disrupting any actual educational activities; it was meant to be harmless fun, not vandalism. No harm came to anything here. Second, that they documented their findings to the administration as part of the action, including recommendations for improv…

For contrast, I once got suspended from the school computer labs for two weeks for the heinous crime of... running an unauthorized executable from a flash drive.

It was Rainmeter; I was showing it to a friend. The IT guy even was like "yeah Rainmeter's pretty cool, I read about it in a magazine". But it was auto-detected and school policy, apparently.

Re: IoT hacking and rickrolling my high school district

#347

Earlier quoted context omitted.

I graduated high school in 2015. I remember similarly poking around a network drive until I found a file in plaintext which contained everyone's student ID and whether or not they had a nut allergy (protected by HIPAA), for the bus system. I didn't think much of it, but some other students caught wind. Before I knew it, the superintendent threatened to have the police involved and press legal action for "hacking conf…

> whether or not they had a nut allergy (protected by HIPAA) Personal pet peeve: Your high school is not a covered entity and is not acting as a business associate of a covered entity. HIPAA does not apply. They are free to keep a plaintext file with your name, nut allergies, COVID vaccination status, and anything else they want to put in there - without HIPAA entering into the discussion. FERPA could apply, but I do…

Nut allergy info that was collected by the school (teacher, admin, nurse, whoever) is part of the student records and would be protected information under FERPA.

Re: IoT hacking and rickrolling my high school district

#348

Earlier quoted context omitted.

I 'worked' for my own high school's IT dept, a few hours a week, as a student. It was an amazing experience working with those guys. I learned so many things, from how to punch, terminate, and run cables to how to set up a Ghost image and deploy it en masse across the district. One day one of the old macs was showing the frowny face in a in-session classroom. Boss sent me down there with specific instructions: "pull…

I believe the term for this is ‘percussive maintenance’

I haven't needed to use it since....

last Tuesday

Re: IoT hacking and rickrolling my high school district

#349

Earlier quoted context omitted.

> All the computers displayed a popup window When I engaged in `net send` shenanigans at the local community college, at least the IT staff was smart enough to know where to scramble a runner whenever those dialog boxes popped up across campus. "ALL YOUR BASE ARE BELONG TO US" was quite the meme then, but apparently they thought it was some form of cyber-terrorism.

O mannn I was suspended from HS, and banned for 2 years from touching school computers for net send shenanigans as I wasn't smart enough to cloak the originating workstation. My message to every single computer in our HS: "Hey what's up!" my friend added to this: "Your network (H:/) drive is being deleted." School administrators and teachers did not find this funny.

What year was this? I remember a time in the mid 90s (c. 1996?) when Novel had just upgraded to "intranetware" and all the computers had fancy "web browsers" which was fun, there was a 64k ISDN for the computer suite (we actually had two, but the other was RM Nimbus machines which could just about run netwars). This was in the UK

I changed the homepage to a webpage which redirected to file://c:/con/con (which for those who don't know caused a windows BSOD at the time).

IT teacher thought it was hilarious, used it as part of the lesson about how computers can be broken into, and told everyone "ok we've seen that, don't do it again".

Another time I remember writing a simple program, probably in qbasic, which captured passwords to a file. It only wrote a the first 4 or so letters to the file - showed what we could do, had a little fun, tricked the teacher into logging in, and then told him "ha ha".

As long as you came up with creative things (not just copying others, which is tedious), which didn't cause too much disruption (no deleting files), and stopped doing it once you proved it could be done, you were fine.

Networked IT was new and exciting then though, to the students and the teachers. A few years earlier and it was all BBC Micros, a few years later and everyone was on the internet and trying to install backorifice, but for a brief moment well meaning harmless (for a teenager) curiosity was rewarded.

Post reply on HN