I was put into isolation for three weeks during high school when I was found to be hacking my way through the network. In reality I had found access to the remote server through the winword.exe open dialog that didn't require passwords and was displaying in the list of network drives, but didn't in explorer. Because I found this, I was able to find the RM (Research Machines) Management Console and use a teachers (act…
> I had found access to the remote server [...]. I was able to find the [...] Management Console and use a teachers [...] password [...] create a hidden admin user [...]. Through this I could [...] control every PC in the school. And this is why we can't have nice things. Admins at The Age (in this case) see someone trying to "report" a vulnerability and instantly jump to the conclusion that the user is someone like…
> Once you start trying to guess passwords and modifying state to add backdoors (seriously!?), you have to reasonably expect the rest of us to try to resist and suppress you, by law enforcement if necessary.
In this setting (a school) I'd reasonably expect the "rest of you" to play the game, not to swing the legal hammer. If your system is so easily compromised, you should feel professional shame and try to attone, not reach for law enforcement and general grown-up dullness. Especially given that this school, one would hope that everything there, including the computer infrastructure, should be a part of learning experience, as long as no one gets seriously hurt.
BTW. in my high school, the school server and computer rooms were managed by students, not teachers or any hired staff. Everything worked well most of the time, and at the same time every generation of students was busy putting their backdoors everywhere, while searching and removing ones left by their predecessors. It was fun, and we learned a lot.