I'm most shocked by the fact that the news agency reported the white-hat. I thought revealing a source was looked down on in journalism.
Teen Reported to Police After Finding Security Hole in Website
61–70 of 123 posts
Re: Teen Reported to Police After Finding Security Hole in Website
#62In high school I was blacklisted from an admin position for demonstrating that you could write in Digital Command Language a program that simulated the login environment, stored login attempts, and then after three tries exited to the real login environment to let the user in. In college I was nearly expelled for just mentioning to the IT guys that they didn't have a password on some database, and I could get in with…
Why would they?
A blatant oversight is a sign of incompetence and by making such incompetence public, you're threatening their job security. Why would anyone react positively?
You're better off making the disclosure anonymously.
Re: Teen Reported to Police After Finding Security Hole in Website
#63I was put into isolation for three weeks during high school when I was found to be hacking my way through the network. In reality I had found access to the remote server through the winword.exe open dialog that didn't require passwords and was displaying in the list of network drives, but didn't in explorer. Because I found this, I was able to find the RM (Research Machines) Management Console and use a teachers (act…
> Apparently if I had denied it they would've got the police involved, but I was honest and upfront when they asked me. The problem is that this is usually a terrible gamble to make. I'm glad it worked out for you, but my general advice for anybody else would be not to talk to the administrators, the same way you should never talk to the police. You never know if they're going to involve the police anyway after you s…
Or you report it anonymously? Then, depending on how you got the access, they may find out who you are anyway from the logs.
It's a reasonable course of action.
Re: Teen Reported to Police After Finding Security Hole in Website
#64Earlier quoted context omitted.
> Apparently if I had denied it they would've got the police involved, but I was honest and upfront when they asked me. The problem is that this is usually a terrible gamble to make. I'm glad it worked out for you, but my general advice for anybody else would be not to talk to the administrators, the same way you should never talk to the police. You never know if they're going to involve the police anyway after you s…
So you don't report it at all? That would be irresponsible, as the holes would remain. Or you report it anonymously? Then, depending on how you got the access, they may find out who you are anyway from the logs. It's a reasonable course of action.
Re: Teen Reported to Police After Finding Security Hole in Website
#65Earlier quoted context omitted.
This is a bit different and would be like the neighbor opening the door and waking into your bedroom to tell you.
No, the kid didn't log into the website and make some postings to their internal communication systems (forums, email listings, etc). He attempted to contact them through official channels but was ignored. After that, he went to the local news agency. This is totally different.
Edit: I just want to clarify that I don't think the kid should be prosecuted, but I also don't like the fact that he went as far as to check for sensitive information inside of their system.
Re: Teen Reported to Police After Finding Security Hole in Website
#66In high school I was blacklisted from an admin position for demonstrating that you could write in Digital Command Language a program that simulated the login environment, stored login attempts, and then after three tries exited to the real login environment to let the user in. In college I was nearly expelled for just mentioning to the IT guys that they didn't have a password on some database, and I could get in with…
Funny enough, I did the exact same thing when I was in high school, only we were running Novell on NT4 and I did it in basic and started it from autorun.bat which loaded before the network login screen. It would let you try one time, tell you you entered the wrong password (saving it to file) and exit, at which point windows would load the novell login screen that looked exactly the same. Good times.
We did end up getting the admin password and getting access to the server. I had written another program (also in VB) that would run hidden in the background and randomly open and close the CD-ROM drive. I uploaded this program to the server and attempted to get it to push to all of the computers in the school, but I don't believe I was successful as I didn't really know anything about Novell and never saw it working on any machines.
One of my fellow classmates also found the schools SOCKS proxy so we were able to run AIM and ICQ on the school machines. Our teacher pretty much let us do whatever we wanted in that class. It was my third year taking a programming class with her and she allowed the advanced students to work on their own projects. In that class I also wrote a Group/IM chat client in VB with a Perl server. As GrinningFool said, responding to teens who are obviously interested in computers with bans or expulsion or worse is just stupid. If I hadn't had the freedoms that my teacher gave us in those classes, I wouldn't have learned anywhere near as much as I did.
Re: Teen Reported to Police After Finding Security Hole in Website
#67I'm most shocked by the fact that the news agency reported the white-hat. I thought revealing a source was looked down on in journalism.
Where do you see that the paper gave them the kid's info? All I see is he contacted them directly, and no indication that the followup from the paper is where they got his info.
Last sentence in the third paragraph.
Re: Teen Reported to Police After Finding Security Hole in Website
#68I was put into isolation for three weeks during high school when I was found to be hacking my way through the network. In reality I had found access to the remote server through the winword.exe open dialog that didn't require passwords and was displaying in the list of network drives, but didn't in explorer. Because I found this, I was able to find the RM (Research Machines) Management Console and use a teachers (act…
And this is why we can't have nice things. Admins at The Age (in this case) see someone trying to "report" a vulnerability and instantly jump to the conclusion that the user is someone like you, who has already compromised and exploited the system and at this point just wants to gloat on top of it all.
Surely there is a spectrum between white and black hat hacking. But this is over the line, sorry. Once you start trying to guess passwords and modifying state to add backdoors (seriously!?), you have to reasonably expect the rest of us to try to resist and suppress you, by law enforcement if necessary.
Re: Teen Reported to Police After Finding Security Hole in Website
#69In the U.S., hacker Andrew Auernheimer, aka “weev”, is serving a three-and-a-half-year sentence for identity theft and hacking after he and a friend discovered a hole in AT&T’s website that allowed anyone to obtain the email addresses and ICC-IDs of iPad users. I don't understand why weev is mentioned in the same article as this teen. Weev was allegedly discussing the practicalities of making money through fraud usin…
Re: Teen Reported to Police After Finding Security Hole in Website
#70Earlier quoted context omitted.
Funny enough, I did the exact same thing when I was in high school, only we were running Novell on NT4 and I did it in basic and started it from autorun.bat which loaded before the network login screen. It would let you try one time, tell you you entered the wrong password (saving it to file) and exit, at which point windows would load the novell login screen that looked exactly the same. Good times.
Hah! Exact same thing, I used... Borland Basic, IIRC, to build the executable that I called from autorun. I collected many passwords - I never used them or intended to, I just wanted to see if I could do it. I made the classic mistake though - I told someone about it. A few days later word got around. I was suspended for a week and was banned from computers for the rest of my time there. Edit: Now that I think about…
So in the simplest possible manner you became a "known threat", and they dealt with you in the simplest possible manner, digital ostracism.
Now we can all tell the alternative story, about the wise teacher who sees something special about us in the misdeed, and who takes the time and the risk to cultivate that positive seed rather than throw the baby out with the bathwater, so to speak. Our very own Mr. Miyagi to safe us from a misspent youth, and who understands our behavior as an expression of exploration ignoring limits, outsmarting the system, rather than your basic mean-spirited destruction for no reason. (Although tagging and hacking do share many qualities, and both are driven, I think, by a young man's desire to prove himself, and yes, even aggrandize himself as someone special - bold, clever, crafty, and someone who can't be "kept down by the man". Rebellious, but also desperately needing to prove himself.)
(Of course in this story the Mr. Miyagi would have hacked onto your personal systems, encrypted the passwords you'd stored, and then left a personal message notifying you that if you wish to understand what he did and how he did it, he'll meet you after school in room 10 for a primer on real hacking.)