Teen Reported to Police After Finding Security Hole in Website
wired.com
wired.com
It would let you try one time, tell you you entered the wrong password (saving it to file) and exit, at which point windows would load the novell login screen that looked exactly the same.
Good times.
I collected many passwords - I never used them or intended to, I just wanted to see if I could do it.
I made the classic mistake though - I told someone about it. A few days later word got around. I was suspended for a week and was banned from computers for the rest of my time there.
Edit: Now that I think about it (I haven't in years): What kind of response is that? Someone shows some creative thinking and does so in a way that is obviously[1] quite naive/without ill intent. While I understand that you want to discourage the specific behavior, perhaps steering the culprit to use talents with more foresight would have been a better answer.
[1] Looking back, I was something of an asshat in the personal skills department so it's entirely possible that they simply didn't believe my lack of nefarious intent.
So in the simplest possible manner you became a "known threat", and they dealt with you in the simplest possible manner, digital ostracism.
Now we can all tell the alternative story, about the wise teacher who sees something special about us in the misdeed, and who takes the time and the risk to cultivate that positive seed rather than throw the baby out with the bathwater, so to speak. Our very own Mr. Miyagi to safe us from a misspent youth, and who understands our behavior as an expression of exploration ignoring limits, outsmarting the system, rather than your basic mean-spirited destruction for no reason. (Although tagging and hacking do share many qualities, and both are driven, I think, by a young man's desire to prove himself, and yes, even aggrandize himself as someone special - bold, clever, crafty, and someone who can't be "kept down by the man". Rebellious, but also desperately needing to prove himself.)
(Of course in this story the Mr. Miyagi would have hacked onto your personal systems, encrypted the passwords you'd stored, and then left a personal message notifying you that if you wish to understand what he did and how he did it, he'll meet you after school in room 10 for a primer on real hacking.)
We did end up getting the admin password and getting access to the server. I had written another program (also in VB) that would run hidden in the background and randomly open and close the CD-ROM drive. I uploaded this program to the server and attempted to get it to push to all of the computers in the school, but I don't believe I was successful as I didn't really know anything about Novell and never saw it working on any machines.
One of my fellow classmates also found the schools SOCKS proxy so we were able to run AIM and ICQ on the school machines. Our teacher pretty much let us do whatever we wanted in that class. It was my third year taking a programming class with her and she allowed the advanced students to work on their own projects. In that class I also wrote a Group/IM chat client in VB with a Perl server. As GrinningFool said, responding to teens who are obviously interested in computers with bans or expulsion or worse is just stupid. If I hadn't had the freedoms that my teacher gave us in those classes, I wouldn't have learned anywhere near as much as I did.
I also figured out how to access the middle school's library database without a login. [That wasn't secured, nor did it require a password]
Also, nearly got in trouble with the IT administrators at my high school because I found out how to send Novell messages.
I was a very bored kid.
Why would they?
A blatant oversight is a sign of incompetence and by making such incompetence public, you're threatening their job security. Why would anyone react positively?
You're better off making the disclosure anonymously.
When the info comes from an anonymous source they can't take their frustration out on the messenger. (Instead of thanking the messenger as they should.) I don't get why these hackers often give up their anonymity.
My guess is that it's because they're hackers, and they don't expect that the other side consist mostly of boring incompetents with zero sense of humour or professional pride. Geez, if I were to ever be responsible for ITSEC in a school, I'd take such hacker for a beer and dare him to try and break some more stuff. The state of mind which leads people to prosecute hackers is a very sad one.
I'll conjure up respected Arthur C. Clarke - Third law: Any sufficiently advanced technology is indistinguishable from magic. Put scared people and magic together and you got bonfires going. This why hackers rot in jail for longer than murderous psychopaths.
But then again I was more of a black hat for most of my life than white.
my 2c
Because I found this, I was able to find the RM (Research Machines) Management Console and use a teachers (actually the deputy head) password "teacher" (no word of a lie) to create a hidden admin user in the list of student accounts. Through this I could get to RM Tutor 3 which allowed me to control every PC in the school.
I was gathering information to give to the IT staff, but I was grassed on instead, so I was in the wrong. I spent 3 weeks explaining everything and how to fix it, then I was allowed to continue my quest so long as I asked permission and gave info straight away rather than hoarding it.
Apparently if I had denied it they would've got the police involved, but I was honest and upfront when they asked me.
My brother started the same school three years ago (I've been gone for 8 years) and I was still able to access a few things with the remote panel — after which I alerted the school to it. I don't think they were best pleased to hear from me...
The problem is that this is usually a terrible gamble to make. I'm glad it worked out for you, but my general advice for anybody else would be not to talk to the administrators, the same way you should never talk to the police.
You never know if they're going to involve the police anyway after you spill the beans, and if they do, you'd rather they do it without already having a confession from you.
I was definitely worried about this, but I figured that if anything, I've not lied to anybody, so I'd be happy with myself.
Unfortunately, that's not the way police encounters work in practice. Even if you've done nothing wrong, talking to the police can really only hurt you. For example, this re-enactment is based on a true story in which an old lady in Baltimore was convicted of drug possession because some neighborhood children had left a dime bag under her sofa (which she didn't even know about) https://www.youtube.com/watch?v=s7RYH8Py6lY[0]
Just because you think you've done nothing wrong doesn't mean others will agree, especially when it's their job to think you're guilty.
[0] This is part of an hour-long video which shows several more cases like this, but for some reason I can't find the full version anymore.
Or you report it anonymously? Then, depending on how you got the access, they may find out who you are anyway from the logs.
It's a reasonable course of action.
And this is why we can't have nice things. Admins at The Age (in this case) see someone trying to "report" a vulnerability and instantly jump to the conclusion that the user is someone like you, who has already compromised and exploited the system and at this point just wants to gloat on top of it all.
Surely there is a spectrum between white and black hat hacking. But this is over the line, sorry. Once you start trying to guess passwords and modifying state to add backdoors (seriously!?), you have to reasonably expect the rest of us to try to resist and suppress you, by law enforcement if necessary.
Personally, I don't think this or anything close should be made illegal. Who was hurt? What was the damage and the cost? Private data was likely at risk, and maybe there's a case to be made there, but I'm not entirely convinced that shouldn't be laid at the feet of the organization for shoddy security practices.
> Once you start trying to guess passwords and modifying state to add backdoors (seriously!?), you have to reasonably expect the rest of us to try to resist and suppress you, by law enforcement if necessary.
In this setting (a school) I'd reasonably expect the "rest of you" to play the game, not to swing the legal hammer. If your system is so easily compromised, you should feel professional shame and try to attone, not reach for law enforcement and general grown-up dullness. Especially given that this school, one would hope that everything there, including the computer infrastructure, should be a part of learning experience, as long as no one gets seriously hurt.
BTW. in my high school, the school server and computer rooms were managed by students, not teachers or any hired staff. Everything worked well most of the time, and at the same time every generation of students was busy putting their backdoors everywhere, while searching and removing ones left by their predecessors. It was fun, and we learned a lot.
I'm fine with that.
This is bad news for everyone who runs a website.
> (1) Have a security contact, (2) publish a GPG key and accept GPG mail, (3) respond promptly with a "security flaw ID".
I have no doubt, that the coming generations will have big difficulties to distinguish between right and wrong.
We don't have the problem now with single fallen states, but with a fallen human kind.
And then some poor teen believes it and thinks "maybe it's wise to inform the site first" and subsequently goes to jail for doing the 'responsible' thing. And so the cycle continues.
At one time, there was a law in Minnesota that it was a misdemeanor to leave your car unlocked in a public place, so the idea is not totally without precedent.
I think there should be a digital whistleblower law to protect people who report such things in good faith. It should include a clause to make it negligence to ignore such a valid report.
I was thinking of writing an email to the IT, but fuck that. I'm not paying for someone else's mistake.
The issue of anonymous disclosure is a real issue if you don't
Why do you think Wikileaks was such a big/new deal?
[1] http://www.forbes.com/sites/runasandvik/2013/12/18/harvard-s...
The FBI will help your sys admin investigate a bomb threat, obviously. Reporting a security hole will unlikely draw their interest. Yes, just using a fake gmail account is tracable without more protections (like correctly accessing Tor). Again, I doubt the FBI is going to investigate.
But hey, I'm all for paranoia and extra caution.
Plus, rtfa you linked. It says clearly in the first few paragraphs that Tor did NOT fail this guy, but that he's an idiot in how he accessed it.
Lastly, as mentioned, send an anonymous letter. It's not hard, kids!
I don't understand why weev is mentioned in the same article as this teen. Weev was allegedly discussing the practicalities of making money through fraud using the information he obtained. It's almost certain he wasn't wearing a completely white hat. This teen sounds like he was doing the proper white hat thing, but then got reported to the police anyhow, at least according to the information provided in the article.
A 30c3(30th Chaos Communication Congress) talk by Nate Cardozo(a lawyer) of EFF.
https://www.youtube.com/watch?v=oSi6PxVBOx4
My take on it? Don't do it, You will gain nothing and can loose everything.
Am I allowed to go to businesses and try to pick the locks, look inside, and then report to the business owner that their lock was pickable? Well... yes, but I'd probably be reported to police.
Websites, like locks, aren't bullet proof. How many web applications out there don't have a security flaw somewhere? Doing penetration tests on unwilling victims is risky. Trying to break wifi, company intranets, people's computers, etc. It's best to pentest as a professional, with willing victims or wait for a "pentest" contest.
A poorly protected website is more akin a house with no lock on it at all, and reporting that "this house has no lock" is not a criminal act.
What about this: seeing the house has no lock, opening the door, going inside, counting the money in the owners wallet, putting it back, then reporting that "Anyone could steal $300 from that guy".
Sometimes these discoveries aren't intentional. Let's say I lean against a door and it's not locked. Well, I never meant to open it up, but since I can't prove I didn't intend to, and since the business can't distinguish people with honorable intentions vs. those without, why risk telling them?
If you tar the helpful with the same brush as the crooks then you shall always learn the hard way from your mistakes.
E.g. my street address growing up was 1901 Mayor's Road.
Let me put that in another way, if a guest lean close to a lock and then look around to report that there is a defective lock or prone to fail I will be grateful. (But not if he pickit)
Physical-virtual analogies are difficult.
Last sentence in the third paragraph.
I notified them about it, and included information on what specifically was wrong, the impact it had (over 6 million credit cards, social insurance numbers, addresses, full names, and telephone numbers), and they hired me to help them fix it.
I often look back on that event and am quite thankful for how it turned out. I've read about plenty of stories where the person who found the vulnerability was not as fortunate.
It's pretty simple people this is against the law in most countries. SQL injection, default passwords, remote injection are illegal.
The big thing for me is not what happened to him but young people thinking this is legal. Why didn't he try and be anonymous?
Don't care whether it should or should not be legal to hack sites but how could he not know it was illegal? (I guess that's slightly rhetorical, he was 16)
A typical college management or government is designed to take orders from top. A persons ability to make decisions and process information is not often correlated with this position. But in this real world a 16 year old can beat a 50 years on basis of pure merit. As a society we are adapted to it but governments and management practices haven't. So when a teen calls up to report a security hole the lower level of administration panics.
As ever, a couple of short articles may not be giving us the big picture.
Personally i would have sold it to the highest bidder. Being "white hat" gets you in trouble more often than not.
Il stick to "gray hat" thank you very much. If i ever choose to disclose any vulnerability to the owners i will not reveal my identity and after arbitrary amount of time say... (1 month) if it's still present sell it to the highest bidder let them deal with the consequences.
You have to be strict when teaching people and this is no different. If you let them set the rules they could choose and unreasonable length of time like 1 year before they allow you to disclose anything.
You are the one in the position of power never let them take that away from you. By revealing you identity you give away all your power.
If you're not a threat people don't take you seriously.
Being "white hat" gets you in trouble more often than not.
Is beyond absurd.I think that covers 80% of this type of story cropping up quarterly in mainstream media.
People getting in trouble for reporting vulnerabilities is highly rare. Show me 100 cases of it, and I'll still tell you it's rare.
At least in private anyway if you ask them in public their force to keep up appearances.
Now we can argue about the percentages all day but you have to agree being "gray hat" and keeping the power on your side by not exposing your identity is the safer way to go about it unless you want bragging rights which is whole other level of psychology.
I'm not after the attention I'd rather be the guy who nobody notices.
Granted. I've lost clients this way, despite having been actually invited to do work on their systems; such experience has taught me that the political concerns around unsolicited vulnerability reporting dwarf the technical considerations involved, and that trying to navigate such minefields is worthwhile only when the status quo is utterly untenable.
> Personally i would have sold it to the highest bidder.
Well, that's a wholly different consideration, isn't it? Saying nothing is one thing. Gravely violating the ethics of your profession, and possibly criminal law as well, is quite another.
Them, and the innocent victims of this breach - the people who just wanted to buy a bus pass.
Why not disclose anonymously and publicly, instead of selling the data off?
I believe that if an organization wants to incriminate responsible disclosure then they have to have a public ToS stating any disclosure is subject to just that. Then they will dissuade any free help in a public fashion and left to their own devices. In that case there should be non-retaliation protection available via the state to anonymously submit without fear of being penalized.
If there was a big hole in the side of a bank and it was illegal to talk about it do you just accept it and move on? Do you continue to bank there? There's inherent risk with providing Internet based services. Deal with it instead of being ignorant about it.
Assumptions are the mother of all fuckups.
It should be the police's responsibility to make a decision about whether reports should be followed up or not. We should hold the police, prosecutors and the courts culpable for making reasonable judgements here, not random uninformed members of the public.
I am not sure about that:
http://www.wired.com/politics/law/news/2008/02/blind_hacker?...
- complain how white-hat practice are not well understood;
- advise to report, but anonymously.
It sounds like a simple enough website to set up. It would encourage script-kiddies to report anonymously, send a warning to the right person, and include explanations — maybe free best practice tips and references to known security professionals if necessary. Now that Scheider is in the news, his name could help reassure uninformed admins that this is not a racket.
I'm not a coder, and the furthest thing from a security professional, though.
After that, he went to the local news agency. This is totally different.
Edit: I just want to clarify that I don't think the kid should be prosecuted, but I also don't like the fact that he went as far as to check for sensitive information inside of their system.
If the hacker simply notified the people responsible before retrieving any data, I don't think that the hacker would be persecuted.
Your analogy doesn't hold. There are few spiders trying every door and window of every house. The risk profile (attack surface area) is much smaller in the physical world.
If a service publishes a port, many someone's will probe it, legitimately or not.
Where your analogy does hold is courtesy. If one of my neighbors sees my door open, does a walk thru to check things out (I might be bleeding out in the basement), finds nothing, then I absolutely do want her/him to clue me in.
Ditto my website(s).
Well, we need to know more about the particulars. It says it was SQL injection. It's entirely possible, given the limited information, that he just sent a correctly crafted GET request. In that case, a more apt analogy would be a warehouse where stepping on a particular part of the sidewalk unlocks the door.
And if you care about users' private data being leaked, said users can always use the assassinaton market to dispose said sites' admin staff.
I'm dead serious on both point. I would love to see somebody die a violent death over such shit as exposing user data and then reporting white hat to the police without even securing the system in the first place.