Live data from Hacker News

IoT hacking and rickrolling my high school district

whitehoodhacker.net

211–220 of 399 posts

Re: IoT hacking and rickrolling my high school district

#211
post #103

Reminds of me my school leaving prank. I rewrote the whole internet on my school's computers. Google's logo became "Leavers '08", Facebook became "Hatebook" and was red, YouTube only played videos of cats, amongst other things. These were the days when nothing had SSL, so you could just intercept and rewrite traffic! My only requirement was: do no actual damage It was implemented as a Debian live CD that you could dr…

Unless you had a special case for the hijacking machines to ignore the spoofed ARPs, the whole thing probably fell apart when they ended up with a loop between each other rather than a path to the real gateway.

Re: IoT hacking and rickrolling my high school district

#212
post #103

Reminds of me my school leaving prank. I rewrote the whole internet on my school's computers. Google's logo became "Leavers '08", Facebook became "Hatebook" and was red, YouTube only played videos of cats, amongst other things. These were the days when nothing had SSL, so you could just intercept and rewrite traffic! My only requirement was: do no actual damage It was implemented as a Debian live CD that you could dr…

Unless you had a special case for the hijacking machines to ignore the spoofed ARPs, the whole thing probably fell apart when they ended up with a loop between each other rather than a path to the real gateway.

Oh, yeah. That's a very good point. That's probably why it stopped working. I always thought the network admins pulled the plug assuming they'd been hacked.

Re: IoT hacking and rickrolling my high school district

#213
post #103

Reminds of me my school leaving prank. I rewrote the whole internet on my school's computers. Google's logo became "Leavers '08", Facebook became "Hatebook" and was red, YouTube only played videos of cats, amongst other things. These were the days when nothing had SSL, so you could just intercept and rewrite traffic! My only requirement was: do no actual damage It was implemented as a Debian live CD that you could dr…

Used to be that Windows allowed programs to hook into each others’ event busses. (It might still, I’m not sure.) This might be why a few of my Highschool’s computers would interpret every 5th right click in minesweeper as a left click

Re: IoT hacking and rickrolling my high school district

#214
post #212

Earlier quoted context omitted.

Unless you had a special case for the hijacking machines to ignore the spoofed ARPs, the whole thing probably fell apart when they ended up with a loop between each other rather than a path to the real gateway.

Oh, yeah. That's a very good point. That's probably why it stopped working. I always thought the network admins pulled the plug assuming they'd been hacked.

That's a common issue with distributed systems.

Something has to be "the leader" and you need a system for choosing a new one once the old one is offline for a certain amount of time.

Add in a sprinkling of how to figure out if you have more than one leader active at a time.

Re: IoT hacking and rickrolling my high school district

#215

I went to Buffalo Grove High School in this same district and graduated many years ago. At the time no IPTV systems or EPIC bell systems were in place. However, as soon as I walked in my freshman year I noticed the 'teacher' WiFi was only using MAC Address Filtering. One minute scan and a spoof later I was poking around to discover a whole lot was visible from this privileged network. “...From the results, we found v…

In middle school all classrooms had their own printer. They were also shared on the entire school network with no security. We had a lot of fun printing stuff to other classes and never got caught.

Re: IoT hacking and rickrolling my high school district

#216

Earlier quoted context omitted.

Hypothetically it could happen and even if it isn’t true, I feel it adds something to the conversation. Besides, you cited as many sources as they did.

Sounds way overly complex for a high schooler to pull off. At least the OP sounded legitimate, the details didn't sound over the top.

Sounds like you hung out with the wrong kids in high school.

A couple friends and I pulled off some stunts of comparable non-digital complexity. (This was the 80s, schools didn't have networks.) They were more of the logistics and misdirection sort; for instance, having your own version of the printed graduation programs delivered, instead of the boring, official one.

Re: IoT hacking and rickrolling my high school district

#217

Someone I know did something similar, was arrested in their college dorm, and at the sentencing hearing in federal court was fined and sentenced to 5 years probation, and now has a criminal record. This kid is very very lucky. Obviously they violated the CFAA which carries severe criminal penalties. They engaged in actual hacking without any permission or defined scope. And they exploited the system without any respo…

Posts like yours validate the insane over criminalization of what essentially amounts to a prank. I had literally the exact same experience in high school. Got expelled and had to get a GED. They could have easily pressed charges. Part of the issue is people like you who advocate for respecting "the system" and essentially scaring kids into not doing anything. Except that simply re-enforces the draconian laws that ar…

Warns kids against jumping off cliffs. Accused of causing gravity.

Re: IoT hacking and rickrolling my high school district

#218
post #196

Earlier quoted context omitted.

I don't think this happened.

https://www.dropbox.com/s/hyt24p4j43szpdi/logo.gif?dl=0

Wow takes me back to old Google's former logo! It looked so much better with old logo.

Re: IoT hacking and rickrolling my high school district

#219

Preface this by saying this was a smaller school, and the students had limited access to wifi. For example a teacher would create a set of radius credentials that would only be active for 1 hour. Since data was also expensive that was not an easy work around. In my grade 11 electronics class, one project we were assigned was to create a digital clock with notifications for one of the teachers. Me and a friend set up…

Nice! I used to carry around a wireless router in my backpack for the same reason, and made sure to surreptitiously plug it in at the back of every class. Similarly, the school had very restricted WiFi, but no restrictions on the wired network. Fun times.

Re: IoT hacking and rickrolling my high school district

#220

Earlier quoted context omitted.

Hypothetically it could happen and even if it isn’t true, I feel it adds something to the conversation. Besides, you cited as many sources as they did.

Sounds way overly complex for a high schooler to pull off. At least the OP sounded legitimate, the details didn't sound over the top.

Not really. Sounds like this was class of '08, and at the time BackTrack would have been readily available and popular enough for a curious highschooler with a bit of computing background to find. As I recall etercap was built in and I wouldn't be at all surprised if there were tutorials for setting up scenarios almost exactly like what is described.

Even the ARP balancing thing is the kind of too-clever-by-a-half solution a naive youngin' would come up with since it would lead all the nodes thinking each other are the gateway and crushing the network with routing loops.

Post reply on HN