Live data from Hacker News

Hamed Helped. Help Hamed.

hamedhelped.com

31–40 of 52 posts

Re: Hamed Helped. Help Hamed.

#31

Moral of the story: Sanitise your query params.

I think the moral of the story is - whatever you do anonymize your tracks and do not inform the authorities. There is substantial risk and no reward for acting otherwise.

Having nearly been fired from an university for responsible disclosure, I agree completely, there is substantial risk and no reward for public disclosure of any kind in university environments.

Re: Hamed Helped. Help Hamed.

#32
If anywhere should be more tolerant of intellectual curiosity, it should be in a college environment.

Unless they can prove he had intent to cause damage, which it sounds like they could not do, they should just forgive and forget and stop trying to cover the overpaid butts of the sysadmin who didn't fix the hole in the first place.

Hell society forgave all the banks and wallstreet for their actual crimes.

Re: Hamed Helped. Help Hamed.

#33
I have to wonder how much this will help. A colleague and I made a responsible exposure to a vendor that provides the application software for the California State University system. The vulnerability I chanced upon, and that my colleague was able to verify to be fully open, made it possible to obtain the private details of hundreds of thousands of applicants from their system. How were we rewarded for quietly and responsibly disclosing this to the vendor? The vendor threatened a lawsuit against the university, and the university cowtailed and nearly fired my colleague, severely reprimanding him and myself. Little did I know this would become a theme of my stint in working for academia, of the universities not caring at all about students and their private data. I worked for multiple universities and it was the same at each one. They seemed to think the problem was with people not with buggy, overpriced, insecure software.

Re: Hamed Helped. Help Hamed.

#34
post #8

Earlier quoted context omitted.

Here's his expulsion letter, stating why he was expelled according to the school. http://www.documentcloud.org/documents/560325-al-khabaz-expu...

Translation: On Sept 21st our site was vulnerable to a simple SQL injection attack. On Sept 22nd you documented this information for us. On Oct 26th our site was STILL vulnerable to a simple SQL injection attack. On Oct 29th you again documented this information for us. On Nov 12th we expelled you for our discovering our abysmal security.

What kind of IT Policy was applied? Was this automatic, did they detect the event before he alerted them, or did they do this after he had disclosed the vulnerability?

The first application of the IT Policy is the interesting one here, as it lays the foundation for - or undermines Hamed's case as a white hat.

Re: Hamed Helped. Help Hamed.

#35
post #25

Earlier quoted context omitted.

http://news.ycombinator.com/item?id=5090007 A few days after reporting the flaw, he got caught using http://www.acunetix.com/ (web vulnerability scanner) on their network. He says he was checking to see if they fixed the flaw. I don't think he was intentionally being malicious, but his explanation doesn't jive with his actions. I still think it sucks that they expelled him. But I am unable to logically see how he did…

It sounds like he's being screwed over by the vendor, who forced him to sign an NDA. To be honest anyone using Acunetix isn't looking to hack into anything. It's an enterprise scanner that looks for general web app issues rather than something that's typically used to conduct actual attacks. You'd expect an actual attack to be conducted with a tool like Havij, Sqlmap, Burp or Zap proxy.

He did manage to slow the site down significantly, to the point of being unusable. Not surprising given the code quality of an app where replacing the student id in a url parameter gives you access to their file.

However the vendor offered him a job and a scholarship, so it seems like it's the university's over-reaction.

Re: Hamed Helped. Help Hamed.

#36
This goes on to show how out of touch with reality our educational systems currently are. They are incentivized by the wrong things, which reflects in the kind of people and policies that are put in place.

Before the web and the free dissemination of information it brought about, the average academician was more 'smarter' than the average student just by the fact that the students hadn't yet had access to the sources of information their teachers had.

However, we now live in times when you can expect anybody in the society to grow to their full potential, thanks to the free web.

This changes the fundamental role educational institutions has to play. They can't continue to be passive devices of information transmission. Yes, there are an elite bunch of institutions that provide more value than that. But as these events show, the educational sector around the world in general are mediocre and are pretty inefficient.

You now have smarter students and they don't need you to tell them what the world is about. That is the changed reality of the market and it is going to affect this sector for the better in the long run.

Re: Hamed Helped. Help Hamed.

#37

Earlier quoted context omitted.

http://news.ycombinator.com/item?id=5090007 A few days after reporting the flaw, he got caught using http://www.acunetix.com/ (web vulnerability scanner) on their network. He says he was checking to see if they fixed the flaw. I don't think he was intentionally being malicious, but his explanation doesn't jive with his actions. I still think it sucks that they expelled him. But I am unable to logically see how he did…

> but his explanation doesn't jive with his actions. I think it's perfectly congruent. An entity has your data as well as information on many other people. You come across and report a vunerability. You check that something was done about it. I see no holes in this (aside from the ones in Montreal college's security).

Just saying,

If he found the vulnerability without using Acunetix, why did he have to use Acunetix later to check if the same vulnerability has been fixed or not?

Couldn't he re-check using the same way that he initially found the vulnerability?

Re: Hamed Helped. Help Hamed.

#38
post #37

Earlier quoted context omitted.

> but his explanation doesn't jive with his actions. I think it's perfectly congruent. An entity has your data as well as information on many other people. You come across and report a vunerability. You check that something was done about it. I see no holes in this (aside from the ones in Montreal college's security).

Just saying, If he found the vulnerability without using Acunetix, why did he have to use Acunetix later to check if the same vulnerability has been fixed or not? Couldn't he re-check using the same way that he initially found the vulnerability?

Perhaps he was using a wider net to see if there were any other problems which, given the level of (in)competence displayed by the techs working for the college, was a distinct possibility.

Re: Hamed Helped. Help Hamed.

#39
This wasn't the first time Ahmed (not hamed, ahmed) reported the problem. When they ignored it, left the software running, and notified none of the students, he used some free white-hat web security scanner to generate a report to make it more clear for the business people what was wrong.

The business people have decided that the security scanner is "a hacking tool" and that Ahmed needed permission from the school to see if the software that was imposed on him which was leaving his private data exposed after the staff knew was still broken.

The way Richard Filion, who runs the school, tries to make excuses around this is appalling.

http://www.cbc.ca/homerun/2013/01/21/dawson/

The software vendor gave the poor kid a scholarship and asked the school to change its mind.

http://www.cbc.ca/news/canada/montreal/story/2013/01/21/mont...

The RCMP declined to be involved.

The running excuse they're giving is "it was against our code of conduct." And, I mean, most schools don't even kick binge drinkers who got in an accident and nearly killed people out for code of conduct.

So clearly this isn't an excuse.

The people responsible for the decision are the head of the Computer Science department, Ken Fogel, and Dianne Gauvin, one of the deans. Predictably, they do not respond when contacted.

This is a computer science department where a panel of 14 out of 15 "professors" actually chose to stand behind this - though nobody will release their reasoning or names. So don't expect Ken Fogel to get it on grounds that you imagine he's one of us.

The school ombudsman, whose job it is to stand up for Ahmed, has been whitewashing its Facebook page of all criticism. The main school Facebook page is just ignoring the criticism instead; they post inbetween literally hundreds of people (including students and alums) to chat with people on posts from before this started getting public.

And, a reminder? They did this in November. They've been sitting on this for months. They aren't going to change their minds without a very good reason.

Not shockingly, other students have been posting reams of existing security holes on their various servers, and evidence of compromises that are claimed to be years old.

Staff is doing just as nothing about those as they did about this the first time Ahmed reported it.

Re: Hamed Helped. Help Hamed.

#40

I have to wonder how much this will help. A colleague and I made a responsible exposure to a vendor that provides the application software for the California State University system. The vulnerability I chanced upon, and that my colleague was able to verify to be fully open, made it possible to obtain the private details of hundreds of thousands of applicants from their system. How were we rewarded for quietly and re…

They got so embarrassed that they challenged the school to change its mind, and offered the kid a full scholarship to wherever he goes next.

http://www.cbc.ca/news/canada/montreal/story/2013/01/21/mont...

In the meantime, their student body is furious that the staff have been knowingly leaving their private information public for months.

So I'd say "a lot."

Post reply on HN