How we hacked Blackboard and changed our grades (2018)
1–10 of 94 posts
Re: How we hacked Blackboard and changed our grades (2018)
#2Re: How we hacked Blackboard and changed our grades (2018)
#3Seems to be no mention of a bug bounty (or a thank you email), despite the severity of the bug and its cleverness.
> 02/27: Attended conference call with Blackboard and NTNU to explain exploit
> Blackboard stopped responding to our e-mails 02/28.
Re: How we hacked Blackboard and changed our grades (2018)
#4Seems to be no mention of a bug bounty (or a thank you email), despite the severity of the bug and its cleverness.
Worse, > 02/27: Attended conference call with Blackboard and NTNU to explain exploit > Blackboard stopped responding to our e-mails 02/28.
Re: How we hacked Blackboard and changed our grades (2018)
#5And second, how did they actually exploit it? Presumably the authentication works by some kind of token, right? Is the client js generally allowed to perform http requests outside of the origin domain? If not how did they hijack the authentication?
Re: How we hacked Blackboard and changed our grades (2018)
#6Re: How we hacked Blackboard and changed our grades (2018)
#7Ok, I might be a little out of date with my web development knowledge, but my first question would not be about the origin but about the embedding itself. The user's input is rendered in the web frontend of blackboard? Why? And second, how did they actually exploit it? Presumably the authentication works by some kind of token, right? Is the client js generally allowed to perform http requests outside of the origin do…
As someone who used blackboard in college I can tell you it's a mess. Neither teachers nor students like it. It integrates with a ton of 3rd party libraries to be "helpful" by embedding content like this but ends up with a ton of different, inconsistent and often broken experiences.
Re: How we hacked Blackboard and changed our grades (2018)
#8Changing your grades may look like a thrill now but in the long run you're only screwing yourselves.
Re: How we hacked Blackboard and changed our grades (2018)
#930 Minutes later I was in my professor's account. Their birthday month and day were public on Facebook, so it was only a matter of guessing their age.
I reported this to our IT department and they were not pleased. They let me know they had the power to expel me but wouldn't.
A week later, I found another exploit. I think blackboard group chat allowed JS execution outright. I redirected the class to "disney.com" but never disclosed it to IT because of the earlier threats.
Re: How we hacked Blackboard and changed our grades (2018)
#10When I was a junior, I mentioned to my housemate that I had forgot my Blackboard password. "It's just your birthday" he said, and I looked at him shocked. 30 Minutes later I was in my professor's account. Their birthday month and day were public on Facebook, so it was only a matter of guessing their age. I reported this to our IT department and they were not pleased. They let me know they had the power to expel me bu…