Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
Shaggar
Apr 26, 2006

Carbon dioxide posted:

So, Facebook felt it was necessary to "correct" some Belgian security report which showed that Facebook sucks.

https://newsroom.fb.com/news/h/setting-the-record-straight-on-a-belgian-academic-report/

It's quite funny, really, lots of weaseling.
Misleadingly?
Ah. It was not their intention that the 'bug' would be found. They're fixing it so the 'bug' can't be found by outside researchers any more.
Additionally, they say nothing about tracking non-Facebook users using other methods, without cookies. Such as IP-based tracking, which certainly happens.
Fact: they'll randomly opt you back in without telling you whenever they update their systems.

This Richard Allan figure would make a very good politician.

was the report titled "Things everyone already knows facebook does" ?

Adbot
ADBOT LOVES YOU

Wheany
Mar 17, 2006

Spinyahahahahahahahahahahahaha!

Doctor Rope

Parallel Paraplegic posted:

also i'm the random syntax highlighting that makes no goddamn sense

it's probably a screenshot of an editor with syntax highlighting for .sh files, but since the syntax makes no sense, neither does the highlighting

Progressive JPEG
Feb 19, 2003

Lysidas posted:

if [ "code altered"]
then
trigger detonation

hackers can turn your hex editor into a bomb

Shame Boy
Mar 2, 2010

Wheany posted:

it's probably a screenshot of an editor with syntax highlighting for .sh files, but since the syntax makes no sense, neither does the highlighting

idk half of it seems like it's trying to syntax highlight sh/bash but a bunch of it seems like they added it after the fact to emphasize the "bomb" parts, and other parts just make no sense at all.

Carthag Tuek
Oct 15, 2005

Tider skal komme,
tider skal henrulle,
slægt skal følge slægters gang



Parallel Paraplegic posted:

idk half of it seems like it's trying to syntax highlight sh/bash but a bunch of it seems like they added it after the fact to emphasize the "bomb" parts, and other parts just make no sense at all.

probs a screenshot of some editor but with added colors

Lain Iwakura
Aug 5, 2004

The body exists only to verify one's own existence.

Taco Defender
http://gawker.com/eight-grader-charged-with-felony-for-changing-teachers-1696985062

quote:

Another devious, young techno-wiz was placed safely behind bars this past Wednesday after authorities say he deftly "hacked into his school's secure computer network" by guessing the password (his teacher's last name). The crime? Changing the desktop background to two dudes kissin'. The punishment? Arrest on felony charges.

The hacker wunderkind of Holiday, Florida's Paul R. Smith Middle School, Domanik Green, explained that he uncovered the secret password by "watching the teacher type it in." At which point, and like a young Julian Assange, he "logged into a teacher's computer who [he] didn't like and tried putting inappropriate pictures on his computer to annoy him."

Unfortunately for Green, once his narc of a substitute saw the two men touching lips on his desktop, the school took the matter straight to the authorities. According to district spokeswoman Linda Cobbe, "The school district is in the process of changing the network password." How long the arduous process of picking a new password could take, though, is anyone's guess. Green also had access to computers with encrypted standardized test questions stored on them, though officials claim he didn't view or change the encrypted files.

The cyber mastermind was arrested, but released later the same day. No one is safe.

Cyanide Sandwich
Oct 24, 2010

thought i was reading the onion. jfc

Carthag Tuek
Oct 15, 2005

Tider skal komme,
tider skal henrulle,
slægt skal følge slægters gang




article isnt clear, it says charged in the title but is he really charged or just arrested+released pending further etc?

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

Cyanide Sandwich posted:

thought i was reading the onion. jfc

k12 schools in the US have IT as incompetent as their administrations are fascist

at my high school it was a bunch of future goons and yosposters that did all the work

and then the actual employee got arrested for handcuffing a student to a pillar in his house and shooting a gun or something when he thought that student stole a computer

Carthag Tuek
Oct 15, 2005

Tider skal komme,
tider skal henrulle,
slægt skal følge slægters gang



Cocoa Crispies posted:

and then the actual employee got arrested for handcuffing a student to a pillar in his house and shooting a gun or something when he thought that student stole a computer

holy poo poo :stare:

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug

one of the weird kids that was on the fringe of my peer group and was working at the police department but wasn't a cop or something was there too

Nintendo Kid
Aug 4, 2011

by Smythe

Cocoa Crispies posted:

k12 schools in the US have IT as incompetent as their administrations are fascist

at my high school it was a bunch of future goons and yosposters that did all the work

and then the actual employee got arrested for handcuffing a student to a pillar in his house and shooting a gun or something when he thought that student stole a computer

when i was in high school the district it department used deepfreeze on all the computers in the district so students couldn't mess them up, cuz they'd reset to the original image at reboot

except they just created the deepfreeze images based on how each computer already was, which meant like a third of them had malware and adware baked into the image (comet cursor, bonzi buddy, that thing that made random words int ext into ad links). this didn't get fixed until they upgraded the computers to xp.

Cocoa Crispies
Jul 20, 2001

Vehicular Manslaughter!

Pillbug
somebody almost got expelled for clicking around in the Network Neighborhood

Venuz Patrol
Mar 27, 2011

http://www.clickhole.com/article/meet-brilliant-12-year-old-hacker-who-breached-bud-1122

quote:

Prepare to feel old. The latest computer hacker to generate a national controversy isn’t a rogue CIA employee or even a college student at MIT. He’s 12 years old—and he just changed the way we think about our security online. But Jeremy Baxter didn’t steal NSA secrets or embezzle from a hedge fund; his aims were higher. Nine years short of his 21st birthday, the computer whiz decided he was going to try to visit budlight.com.

Nope, you didn’t read that wrong. Jeremy set his sights on the strictly adults-only official home page for the alcoholic beverage Bud Light. But even more amazingly? He pulled it off.

MancXVI
Feb 14, 2002

Cocoa Crispies posted:

somebody almost got expelled for clicking around in the Network Neighborhood

what a criminal

also said IT guy and principal (who is still there) used school funds and computers to run stock day-trading software

FCKGW
May 21, 2006

http://www.fbi.gov/birmingham/press-releases/2015/ua-student-charged-with-unauthorized-access-to-university-computer

quote:

On April 15, 2011, Jackson created the e-mail address, uaeduhousing@gmail.com, and began using that account and others to send e-mails to Alabama students, falsely claiming the message was from the University of Alabama Housing Department. She sent the e-mails to about 60 students, many of them her friends or acquaintances, asking that they reply with their “My Bama” university account username and password. More than 40 students responded with that information.

Jackson used the information she collected with her phishing e-mails to access at least 25 user accounts between July 27, 2013, and Aug. 13, 2013. In doing so, Jackson obtained information from a protected computer in order to illegally obtain money from others’ federal and state student loan funds.

Jackson tried to get the money by changing direct bank deposit information for seven accounts and reroute those students’ loan funds to Green Dot reloadable money cards she controlled. Two of her attempts were successful and she transferred $9,598 to a Green Dot card she registered in the name of another student whose personal identifying information she had obtained without permission. Jackson used that same student’s information to establish a Western Union account.

Jackson got $1,001 in cash from the Green Dot card through an ATM withdrawal and a Western Union transfer. The University of Alabama was able to freeze the account before more was removed.

40 replies out of 60 emails is an amazing response for a phishing email.

prefect
Sep 11, 2001

No one, Woodhouse.
No one.




Dead Man’s Band

if the picture he posted was sexy enough, i bet they could get him onto the sex-offender list

Shame Boy
Mar 2, 2010


tbf it sounds like a well-tailored phishing email rather than the sent-to-millions "hi i am from facebawk ur account has been hacked!!!! plz click here and answer some questions!" ones

Carbon dioxide
Oct 9, 2012

Cocoa Crispies posted:

somebody almost got expelled for clicking around in the Network Neighborhood

Back in my high school, it was fine to play browser games or do whatever on the library computers, as long as there weren't any kids waiting to use the computers for actual school work. They usually didn't even mind if you hacked it somewhat, because that allowed the IT guy to see where he could improve the system security.

I got detention once, for subverting their block on chat protocols. I think I managed to log in to MSN Messenger or somesuch. I got detention because chatting from the school computers was absolutely banned. They said the reason was that online communities are full of rapists and the school didn't want any possibility of being held responsible if someone meets their future rapist online.

Lysidas
Jul 26, 2002

John Diefenbaker is a madman who thinks he's John Diefenbaker.
Pillbug
i am glad i messed with my high school's stuff in like 2001 and not now

Luigi Thirty
Apr 30, 2006

Emergency confection port.

I remember when we learned how to connect Cisco 2500s to each other in class. all we did after that was detach the computers from the school network, connect them to each other in the computer lab, and play halo

Shame Boy
Mar 2, 2010

Carbon dioxide posted:

Back in my high school, it was fine to play browser games or do whatever on the library computers, as long as there weren't any kids waiting to use the computers for actual school work. They usually didn't even mind if you hacked it somewhat, because that allowed the IT guy to see where he could improve the system security.

I got detention once, for subverting their block on chat protocols. I think I managed to log in to MSN Messenger or somesuch. I got detention because chatting from the school computers was absolutely banned. They said the reason was that online communities are full of rapists and the school didn't want any possibility of being held responsible if someone meets their future rapist online.

my school had a bizarre rule that chatting was banned but remote desktop / vnc was grey area don't ask don't tell sorta stuff so they'd kick you off if you tried to go to like, meebo, but if you remoted into your home computer and chatted that way it was fine.

MononcQc
May 29, 2007

Parallel Paraplegic posted:

tbf it sounds like a well-tailored phishing email rather than the sent-to-millions "hi i am from facebawk ur account has been hacked!!!! plz click here and answer some questions!" ones

But those are also well-crafted -- their objective is to only get answers by sure targets going to give info. They aim to get people who are so bad at detecting phishing it's gonna be a slam dunk and avoid spending time baiting people who will chicken out: http://research.microsoft.com/apps/pubs/default.aspx?id=167713

Carthag Tuek
Oct 15, 2005

Tider skal komme,
tider skal henrulle,
slægt skal følge slægters gang



in high school i "installed" the quake demo (unzipped to a network share) and had my login taken away for breaking the rules.

except it was win95 so lol :getin:

anthonypants
May 6, 2007

by Nyc_Tattoo
Dinosaur Gum

Carbon dioxide posted:

Back in my high school, it was fine to play browser games or do whatever on the library computers, as long as there weren't any kids waiting to use the computers for actual school work. They usually didn't even mind if you hacked it somewhat, because that allowed the IT guy to see where he could improve the system security.

I got detention once, for subverting their block on chat protocols. I think I managed to log in to MSN Messenger or somesuch. I got detention because chatting from the school computers was absolutely banned. They said the reason was that online communities are full of rapists and the school didn't want any possibility of being held responsible if someone meets their future rapist online.
my school had a ban on forums and instant messenger but i never got an explanation for it. and i was a lil smartass so i argued with him that if instant messaging was banned how come email wasn't????

Wayne Knight
May 11, 2006

My highschool had multiple access databases of student information on the network share. full names, addresses, ssns, phone #s, class schedules. I discovered this through less than ethical means, so I didn't say anything. I probably would have ended up expelled and in a news article just like that.

BangersInMyKnickers
Nov 3, 2004

I have a thing for courageous dongles

I noticed the novell netware "tree" whatever thing on the computers was left unlocked one day and it allowed full access to everything because apparently back in the day if one of the admins typed in the right password it completely opened the entire thing to edits from any account and quietly told the IT guy that this was going on and he yelled at me and disabled my account for the rest of the year

kitten emergency
Jan 13, 2008

get meow this wack-ass crystal prison
i guessed that the password to the admin account for the tech lab macs was the name of our school and got in-school suspension for it. i had to watch a really cheesy 80s video from att about hackers.

Winkle-Daddy
Mar 10, 2007

uncurable mlady posted:

i guessed that the password to the admin account for the tech lab macs was the name of our school and got in-school suspension for it. i had to watch a really cheesy 80s video from att about hackers.

this sounds rad as hell

kitten emergency
Jan 13, 2008

get meow this wack-ass crystal prison

Winkle-Daddy posted:

this sounds rad as hell

i'm trying to find it on the internet but not having a lot of luck

Subjunctive
Sep 12, 2006

✨sparkle and shine✨

apparently cpython doesn't build with ASAN. I mean, don't run untrusted code with python, but still. still.

Westie
May 30, 2013



Baboon Simulator
For about four years my school blocked everything except from ports 80, 8080, 443, etc.

My obvious response was to this was to set up sshd to listen also on 443 and just irssi away to my heart's content. Rebellious or what?!

Even funnier was that we were allowed personal computers into the network, on some sort of guest LAN thing that went through the web filter too. So, there I was, browsing YouTube and e-mails (super verboten stuff!!!) over a SSH tunnel.

I think the IT guys might have been monitoring the connections as within a year all SSH connectivity on the guest LAN was blocked. Even on port 80.

Oh well, at least the internal school LAN still was able to connect to my SSH server via the use of a lovely java applet.

chemosh6969
Jul 3, 2004

code:
cat /dev/null > /etc/professionalism

I am in fact a massive asswagon.
Do not let me touch computer.

Cocoa Crispies posted:

somebody almost got expelled for clicking around in the Network Neighborhood

I had an IT guy in the Air Force tell me to knock it off when I did that one afternoon. Honestly surprised it didn't turn into a huge issue since nobody has anything better to do during peacetime.

Was also told when we had to email someone a username and password to put them in different emails because apparently hackers can only catch one email at a time with their butterfly nets, so they'll never get both emails.

A few months ago at my school, someone downloaded a movie from a public tracker. I guess we got a letter sent about it and IT blocked internet access to the IP that did it. As far as we knew, IT couldn't tell if it was an employee in our office or a student/random person off the street just connected to our open wifi, that doesn't require any network authentication, and did it.

chemosh6969 fucked around with this message at 19:44 on Apr 10, 2015

Westie
May 30, 2013



Baboon Simulator
Also socially engineering teachers is p. cool. I managed to wiggle my way to have unfettered access to Gmail, my personal mail account, YouTube amongst others by just saying to a teacher "HELP!!! I NEED ACCESS!!!!!" and because of my trustworthy nature they just the request to unblcok sent it right off.

Sure, the IT guy had an argument with one of the teachers because he was thinking that I wasn't going to be accessing Gmail for school work purposes, but still got it in the end.

atomicthumbs
Dec 26, 2010


We're in the business of extending man's senses.
i have learned from my mom that every parent of someone who was in my class in elementary school apparently thinks I hacked into and crashed the school district/county's computer network when I was 9.

This never happened and I have no idea how the rumor started other than that I was a little nerd who liked messing with the computers. :shrug:

chemosh6969
Jul 3, 2004

code:
cat /dev/null > /etc/professionalism

I am in fact a massive asswagon.
Do not let me touch computer.

Westie posted:

Also socially engineering teachers is p. cool. I managed to wiggle my way to have unfettered access to Gmail, my personal mail account, YouTube amongst others by just saying to a teacher "HELP!!! I NEED ACCESS!!!!!" and because of my trustworthy nature they just the request to unblcok sent it right off.

Sure, the IT guy had an argument with one of the teachers because he was thinking that I wasn't going to be accessing Gmail for school work purposes, but still got it in the end.

Catholic school?

pseudorandom name
May 6, 2007

one of the terrible computer classes I took in high school had us doing data entry for the next year's student class schedules.

this was done by connecting to the district's AIX DB2 server using a TN3270 emulator with a single shared account (username = password) and starting a form application from the command line.

it didn't use shadow passwords. many of the other accounts also had passwords the same as the username.

one of my classmates improved his grades and then took basically whichever class he wanted for the next couple years.

Tangra
May 1, 2008

Rrrreligion?

It's the catnip of the purrrrrrrrletariat


Mad about your :10bux: ?

:haw:

we ARE talking about Alabama, after all

in a well actually
Jan 26, 2011

dude, you gotta end it on the rhyme

Westie posted:

Even funnier

neither one was funny, hth

Adbot
ADBOT LOVES YOU

Luigi Thirty
Apr 30, 2006

Emergency confection port.

was it the cgi one that showed the PING OF DEATH and TCP/IP packets as train cars full of coal

  • Locked thread