Earlier quoted context omitted.
I'm wondering how one would break into a CCTV system without physical access. Are these systems connected to the internet?
If you're referring to the boys, they found a sticky note on a guard's laptop containing the login details. For general cctv, many are installed to allow monitoring while away from the house. Nanny cams for example. Installing cctv to an existing network will put it online automatically. The most important issue to consider is these devices - routers, cameras, alarms, locks... come with default passwords. And almost…
They Hacked Their School District When They Were 12
21–30 of 55 posts
Re: They Hacked Their School District When They Were 12
#22With the school being technically inept, how did they get caught?
Re: They Hacked Their School District When They Were 12
#23Is it just me or does the story inexplicably blow up the boys tech proficiencies and then almost casually mentions that all they did was log in to school computers with credentials from a post-it on the machine itself in a public space? How are they at fault if said credentials grants them access to unprotected sensitive records and an obviously badly exposed administration system?
Re: They Hacked Their School District When They Were 12
#24I first profiled the story of one of the two boys at https://k12cybersecure.com/blog/moths-to-a-flame/ . AMA.
Re: They Hacked Their School District When They Were 12
#25I'm almost surprised that school administrators are still pulling the same shit they did 19 years ago. I have basically the same story. I dropped out and got a GED after I was framed by a malicious network admin and expelled, the record of which followed me to each subsequent school. I still managed to work my way into having a career, luckily. But the effects on my family and my development as a kid were significant…
After a little playing around we handed the duty technician a post-it note with the superuser password on it and told them we would explain how we found it if they wanted.
I was summoned to the office of the head of IT, congratulated, asked to explain how we did it, and told that we had to keep the password a secret until they had a chance to fix the issues. A week later they told us it was fixed. After I graduated my school hired me as a freelancer.
This is in Australia, but I'm unsure how well my experience generalises here.
Re: They Hacked Their School District When They Were 12
#26Is it just me or does the story inexplicably blow up the boys tech proficiencies and then almost casually mentions that all they did was log in to school computers with credentials from a post-it on the machine itself in a public space? How are they at fault if said credentials grants them access to unprotected sensitive records and an obviously badly exposed administration system?
Re: They Hacked Their School District When They Were 12
#27I'm almost surprised that school administrators are still pulling the same shit they did 19 years ago. I have basically the same story. I dropped out and got a GED after I was framed by a malicious network admin and expelled, the record of which followed me to each subsequent school. I still managed to work my way into having a career, luckily. But the effects on my family and my development as a kid were significant…
After a similar inicident in middle school, my only punishment was that I had to start a computer club at the school and run it with the IT guy that got pwned.
Although I detested the punishment at the time, it turned out to be a lot of fun. I got to build PCs on the school’s dime.
Re: They Hacked Their School District When They Were 12
#28I'm almost surprised that school administrators are still pulling the same shit they did 19 years ago. I have basically the same story. I dropped out and got a GED after I was framed by a malicious network admin and expelled, the record of which followed me to each subsequent school. I still managed to work my way into having a career, luckily. But the effects on my family and my development as a kid were significant…
Once we were in, we eventually found access to the district website server and found the admin password for the entire district (it was a big district) sitting in plaintext on the school website server.
We were smart enough never to do anything malicious or even questionable, apart from getting there in the first place. And we kept it a secret for years. But the amount of sensitive info we had access to was unreal. That same password was used for every major system (school lunches, grading, etc).
And whats crazier is that about ten years later I had bumped into somebody at a bar who was on the IT staff for that district. He was stunned to hear the story, and even worse, that the same password was still being used.
Re: They Hacked Their School District When They Were 12
#29While what the kids did is simple to us, it is magic to these other people who can't even fathom the security implications of such a system. And that's the scary part. The technology is adapted faster than it is being understood.
Re: They Hacked Their School District When They Were 12
#30I had a similar level of access to my school's network when I was 12. It was really easy, just watch the teacher slowly peck-type her password. It was "teach". That gave me access to everything for her class. Later on she had to log in to the admin account, and that password was "burger". It turned out to be the password for every admin account in every school in my district. I'm guessing they were all set up by the…
Exact same story on my side, and the password wasn't much better either. The worst is that she hinted at what the password could be (I assumed it was a joke to calm down curious kids) but it was totally right when I managed to actually see that password for myself.