I was put into isolation for three weeks during high school when I was found to be hacking my way through the network. In reality I had found access to the remote server through the winword.exe open dialog that didn't require passwords and was displaying in the list of network drives, but didn't in explorer. Because I found this, I was able to find the RM (Research Machines) Management Console and use a teachers (act…
> I had found access to the remote server [...]. I was able to find the [...] Management Console and use a teachers [...] password [...] create a hidden admin user [...]. Through this I could [...] control every PC in the school. And this is why we can't have nice things. Admins at The Age (in this case) see someone trying to "report" a vulnerability and instantly jump to the conclusion that the user is someone like…
Personally, I don't think this or anything close should be made illegal. Who was hurt? What was the damage and the cost? Private data was likely at risk, and maybe there's a case to be made there, but I'm not entirely convinced that shouldn't be laid at the feet of the organization for shoddy security practices.