Live data from Hacker News

They Hacked Their School District When They Were 12

edweek.org

21–30 of 55 posts

Re: They Hacked Their School District When They Were 12

#21
post #10

Earlier quoted context omitted.

I'm wondering how one would break into a CCTV system without physical access. Are these systems connected to the internet?

If you're referring to the boys, they found a sticky note on a guard's laptop containing the login details. For general cctv, many are installed to allow monitoring while away from the house. Nanny cams for example. Installing cctv to an existing network will put it online automatically. The most important issue to consider is these devices - routers, cameras, alarms, locks... come with default passwords. And almost…

Ok, thanks. I was under the impression that CCTV systems are always "closed systems", in the sense that one can watch the recorded video only after an incident (where an authority has to provide the password).

Re: They Hacked Their School District When They Were 12

#23
post #20

Is it just me or does the story inexplicably blow up the boys tech proficiencies and then almost casually mentions that all they did was log in to school computers with credentials from a post-it on the machine itself in a public space? How are they at fault if said credentials grants them access to unprotected sensitive records and an obviously badly exposed administration system?

It goes to show the districts poor understanding of technology that their incompetence led to calling what they did ‘hacking’

Re: They Hacked Their School District When They Were 12

#25

I'm almost surprised that school administrators are still pulling the same shit they did 19 years ago. I have basically the same story. I dropped out and got a GED after I was framed by a malicious network admin and expelled, the record of which followed me to each subsequent school. I still managed to work my way into having a career, luckily. But the effects on my family and my development as a kid were significant…

A friend and I managed to gain superuser access to my school's systems (including remote screen access to every teacher's laptop) when I was in secondary school.

After a little playing around we handed the duty technician a post-it note with the superuser password on it and told them we would explain how we found it if they wanted.

I was summoned to the office of the head of IT, congratulated, asked to explain how we did it, and told that we had to keep the password a secret until they had a chance to fix the issues. A week later they told us it was fixed. After I graduated my school hired me as a freelancer.

This is in Australia, but I'm unsure how well my experience generalises here.

Re: They Hacked Their School District When They Were 12

#26
post #20

Is it just me or does the story inexplicably blow up the boys tech proficiencies and then almost casually mentions that all they did was log in to school computers with credentials from a post-it on the machine itself in a public space? How are they at fault if said credentials grants them access to unprotected sensitive records and an obviously badly exposed administration system?

They boys are clearly tech-savvy to a degree (they build their own PCs, mined crypto, understood Windows user permissions, etc.), but I seriously doubt that they would or could have broken into the district's systems without two things: 1/ an admin password left on a sticky note and 2/ clear text storage of other user passwords in an excel file published in a shared folder on the first machine they accessed (a public machine in the middle school library!). Other issues: old user accounts left still active; no review of access logs or logs of server usage (which would have spotted Monero mining). Note: the boys reported that passwords on sticky notes was routine throughout the district (and how they got access to the security cameras, too).

Re: They Hacked Their School District When They Were 12

#27

I'm almost surprised that school administrators are still pulling the same shit they did 19 years ago. I have basically the same story. I dropped out and got a GED after I was framed by a malicious network admin and expelled, the record of which followed me to each subsequent school. I still managed to work my way into having a career, luckily. But the effects on my family and my development as a kid were significant…

Wow, expelled?!?

After a similar inicident in middle school, my only punishment was that I had to start a computer club at the school and run it with the IT guy that got pwned.

Although I detested the punishment at the time, it turned out to be a lot of fun. I got to build PCs on the school’s dime.

Re: They Hacked Their School District When They Were 12

#28

I'm almost surprised that school administrators are still pulling the same shit they did 19 years ago. I have basically the same story. I dropped out and got a GED after I was framed by a malicious network admin and expelled, the record of which followed me to each subsequent school. I still managed to work my way into having a career, luckily. But the effects on my family and my development as a kid were significant…

It seems school district security practices are pretty atrocious universally. In my junior year of high school me and a buddy realized that all passwords for our district were 6 digit numbers. We didn't have to be mad geniuses to realize how easy that would be to crack. And sure enough there was a webmail login form on the district's front page that apparently didn't involve a nonce or security token. So we whipped up a visual basic app (because that's all we knew) and cracked a teachers password in two days.

Once we were in, we eventually found access to the district website server and found the admin password for the entire district (it was a big district) sitting in plaintext on the school website server.

We were smart enough never to do anything malicious or even questionable, apart from getting there in the first place. And we kept it a secret for years. But the amount of sensitive info we had access to was unreal. That same password was used for every major system (school lunches, grading, etc).

And whats crazier is that about ten years later I had bumped into somebody at a bar who was on the IT staff for that district. He was stunned to hear the story, and even worse, that the same password was still being used.

Re: They Hacked Their School District When They Were 12

#29
I wonder if the security guard or the librarian who left the post-it notes on their machines are reprimanded in any way. Or the librarian who left the student list excel file unlocked on the machine, that contains sensitive information.

While what the kids did is simple to us, it is magic to these other people who can't even fathom the security implications of such a system. And that's the scary part. The technology is adapted faster than it is being understood.

Re: They Hacked Their School District When They Were 12

#30
post #5

I had a similar level of access to my school's network when I was 12. It was really easy, just watch the teacher slowly peck-type her password. It was "teach". That gave me access to everything for her class. Later on she had to log in to the admin account, and that password was "burger". It turned out to be the password for every admin account in every school in my district. I'm guessing they were all set up by the…

> It was really easy, just watch the teacher slowly peck-type her password. It was "teach".

Exact same story on my side, and the password wasn't much better either. The worst is that she hinted at what the password could be (I assumed it was a joke to calm down curious kids) but it was totally right when I managed to actually see that password for myself.

Post reply on HN