Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

I had to inform a professor he was running an open home directory like that. Pretty tricky to do as it implies you were looking for it in the first place.


I learned my lesson about never talking about the security flaws i found in school.

Our web access went over secured proxy servers, which determined via our windows login which services to allow or disallow us. As our deputy rector considered himself an open IT advocate, he ensured all browsers we're installed on all machines, including Opera. Back then Opera couldn't use the Windows login to auth with the proxy server, which he "fixed" by using a pre-configured user which just had student rights.

As i'd never use opera i didn't notice it until one of my teachers tried to block me from using any webmail client as a way to transfer files to the school pc.

Trying different things i got the tip from a classmate to start opera. I was struck by a preentered login box which i was told to just hit ok. I got curious and inspected the fields. The loginname had admin in it, so i thought the password might be used elsewhere...

Well, i've seen our deputy rector on our central win 2003 server via windows remote desktop before, so i connected to it, using the user and pass from opera and logged in to an open session on the server which stored all critical school data, including grades of all students attending that school and the transfer tool to send the grades to the statewide server which would make the grades final.

As it was so ridiculously easy i got scared that someone from my class would do the same and then get into deeper trouble for actually trying to change grades or something, i immediately went to our deputy rector and told him all about it.

He banned me from using school pc's for the rest of the year and afterwards all teachers were told to keep their eyes on what i was doing on the school pcs...


Imagine if you had just changed the background picture on the server you accessed to a lolcat or something funny, and left a short text file how you got in, saying that you didn't change anything.

Even better would be to change the password, then leave him an anonymous typed note with it, which would prevent others from abusing the system.

True anonymous reporting is almost as good as whistleblower protection.


But this may be even more frightening to the person you're "reporting" the breach to, who is obviously no tech genius. Now they've been burgled by invisible elves. Even if the elves appear to have done nothing but leave behind delicious cookies and thoughtfully-written notes, it's pretty freaky to the uninitiated.

They may literally change their locks and buy an alarm system. Worse, when some idiot comes along peddling a "magical charm to ward off the bad e-criminals that lurk invisibly on your Facebook page" they'll be in a nice receptive state of free-floating subliminal panic.

The moral of this story is, I guess, is that as a solo whistleblower without institutional or cultural support all available options are bad. We are slowly educating the world's organizations - lots of sites and services these days have security officers who might understand the social dynamics of exploit reports and not be so quick to fly off the handle - but I'm sure there's room for a lot more basic training. Meanwhile, it's hard being a pioneer. ;)


I had a similar story, though not as technically amusing. In HS I noticed that our copies of MS Office allowed macros, i.e. you could run any VB you wanted. Of course, even in the horror that is VBA, you can easily run escalated privileges (e.g. installers). I made the mistake of showing one friend how to install ROMs (I just use it for winamp + a CD from home, because I was 1337 enough to have bought a $400 2X CD-RW). Needless to say, it spread like wildfire and I found myself in front of a dean and the IT director.

Thankfully, that Dean (a) liked me and (b) had a disdain for the drowning bureaucracy that was public high school. So, I explained everything, explained how it was because the IT guy (who was 3ft away) was incompetent, and said I had no intention of hurting anybody. I apologized for not reporting it directly.

That probably is what helped me get into IT/ITsec, because I wasn't punished for being curious.


How did you do it?




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: