{"id":2639,"date":"2010-04-24T12:46:13","date_gmt":"2010-04-24T16:46:13","guid":{"rendered":"http:\/\/rbachnet.wwwmi3-ss40.a2hosted.com\/?p=2639"},"modified":"2022-08-27T13:28:50","modified_gmt":"2022-08-27T17:28:50","slug":"9-year-old-hacks-school-system","status":"publish","type":"post","link":"https:\/\/rbach.net\/index.php\/9-year-old-hacks-school-system\/","title":{"rendered":"9 Year Old Hacks School System"},"content":{"rendered":"<p><a href=\"https:\/\/www.google.com\/url?sa=i&amp;rct=j&amp;q=&amp;esrc=s&amp;source=images&amp;cd=&amp;ved=2ahUKEwjPgJKxsankAhVFsZ4KHWT2DscQjB16BAgBEAM&amp;url=https%3A%2F%2Feconomictimes.indiatimes.com%2Findustry%2Fservices%2Fadvertising%2Fcyber-attack-on-wpp-group-disrupts-work-at-india-units%2Farticleshow%2F59360095.cms&amp;psig=AOvVaw2Ytu4DWGROBO7OdSrin5M1&amp;ust=1567212926100107\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" class=\"alignleft wp-image-102263\" title=\"9 Year Old Hacks School System\" src=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/hackers17-1-e1567126307133-150x116.jpg?resize=142%2C110&#038;ssl=1\" alt=\"9 Year Old Hacks School System\" width=\"142\" height=\"110\" srcset=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/hackers17-1-e1567126307133.jpg?resize=150%2C116&amp;ssl=1 150w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/hackers17-1-e1567126307133.jpg?resize=75%2C58&amp;ssl=1 75w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/hackers17-1-e1567126307133.jpg?w=760&amp;ssl=1 760w\" sizes=\"auto, (max-width: 142px) 100vw, 142px\" \/><\/a><a href=\"https:\/\/www.computerworld.com\/\" target=\"_blank\" rel=\"noopener noreferrer\"><em>ComputerWorld<\/em><\/a> reports that officials at <a href=\"http:\/\/www.fcps.edu\/index.shtml\" target=\"_blank\" rel=\"noopener noreferrer\">Fairfax County Public Schools<\/a> thought they had a <strong>hacker on their hands<\/strong>. It was <a href=\"https:\/\/web.archive.org\/web\/20100422210053\/http:\/\/www.computerworld.com:80\/s\/article\/9175699\/Police_called_after_9_year_old_steals_password?\" target=\"_blank\" rel=\"noopener noreferrer\">reported<\/a> that someone was changing teacher passwords on the <a title=\"Falls Church, Virginia\" href=\"http:\/\/maps.google.com\/maps?ll=38.8822222222,-77.1711111111&amp;spn=0.1,0.1&amp;q=38.8822222222,-77.1711111111 (Falls%20Church%2C%20Virginia)&amp;t=h\" target=\"_blank\" rel=\"geolocation noopener noreferrer\">Falls Church, Virginia<\/a>, school district&#8217;s <strong>Blackboard<\/strong> system. <a title=\"Blackboard Inc.\" href=\"http:\/\/www.blackboard.com\" target=\"_blank\" rel=\"homepage noopener noreferrer\">Blackboard<\/a> (<a href=\"https:\/\/www.prnewswire.com\/news-releases\/blackboard-to-be-acquired-by-providence-equity-partners-for-4500-per-share-in-cash-or-164-billion-124844289.html\" target=\"_blank\" rel=\"noopener noreferrer\">BBBB<\/a>) gives teachers, students, and parents a way to communicate and stay on top of homework assignments and class announcements over the Web. Blackboard\u2019s website says more than 5,000 K-12 and higher-education institutions nationwide use its software.<\/p>\n<p><a href=\"https:\/\/www.blackboard.com\/\" target=\"_blank\" rel=\"noopener noreferrer\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" class=\"alignright wp-image-102266 size-full\" title=\"Blackboard logo\" src=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/blackboard_logo.jpg?resize=88%2C88&#038;ssl=1\" alt=\"Blackboard logo\" width=\"88\" height=\"88\" srcset=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/blackboard_logo.jpg?w=88&amp;ssl=1 88w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/blackboard_logo.jpg?resize=75%2C75&amp;ssl=1 75w\" sizes=\"auto, (max-width: 88px) 100vw, 88px\" \/><\/a>The District contacted local authorities when teachers and staff members reported their passwords were changed preventing access to their accounts because according to <em>ComputerWorld<\/em>. Changes to content and enrollment information for some courses was also discovered. The local police investigated and pulled a search warrant for <a href=\"https:\/\/www.cox.com\/\" target=\"_blank\" rel=\"noopener noreferrer\">Cox Communications<\/a>, the <em><a href=\"https:\/\/www.washingtonpost.com\/\" target=\"_blank\" rel=\"noopener noreferrer\">Washington Post<\/a><\/em> <a href=\"http:\/\/www.washingtonpost.com\/wp-dyn\/content\/article\/2010\/04\/14\/AR2010041404159.html\" target=\"_blank\" rel=\"noopener noreferrer\">reports<\/a>. They traced the\u00a0 IP address which accessed the Blackboard system to the <a title=\"McLean, Virginia\" href=\"http:\/\/maps.google.com\/maps?ll=38.9341666667,-77.1775&amp;spn=0.1,0.1&amp;q=38.9341666667,-77.1775 (McLean%2C%20Virginia)&amp;t=h\" target=\"_blank\" rel=\"geolocation noopener noreferrer\">McLean, Virginia<\/a> physical address of the home of a<strong> 9-year-old student<\/strong> in Fairfax County Public Schools. The police initially suspected the student&#8217;s mother, but after interrogating both of them it became clear that the child was to blame.<\/p>\n<p>Turns out that the Blackboard system was not hacked. The student had simply <strong>taken a teacher&#8217;s password from a desk and used it<\/strong> to change enrollment lists and other teachers&#8217; passwords. &#8220;<em>This was a case where an individual &#8230; got hold of a teacher&#8217;s password, and the <strong>passwords had administrative rights<\/strong>,<\/em>&#8221; said Paul Regnier, a school board representative. &#8220;<em>It was actually not a hack, unless you consider the <strong>9-year-old<\/strong> took the teacher&#8217;s username and password from the desk a hack,<\/em>&#8221; said Michael Stanton, Blackboard&#8217;s senior vice president of corporate affairs. Although there will be no criminal charges filed against the perpetrator, citing school policy, Regnier wouldn&#8217;t confirm that it is a student, the Fairfax school board is taking the incident seriously, Regnier said. &#8220;<em>Nothing bad happened this time, but we have to make sure that &#8230; it doesn&#8217;t happen again,<\/em>&#8221; he said.<\/p>\n<p><strong><em>rb-<\/em><\/strong><\/p>\n<p><em>T<a href=\"https:\/\/web.archive.org\/web\/20140702144642\/http:\/\/beantin.se\/post\/36668648514\/security-usability-sms-password-ux\" target=\"_blank\" rel=\"noopener noreferrer\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" class=\"alignright wp-image-102269 size-medium\" title=\"Password on post it\" src=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/password_bad.jpg?resize=150%2C86&#038;ssl=1\" alt=\"Password on post it\" width=\"150\" height=\"86\" srcset=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/password_bad.jpg?resize=150%2C86&amp;ssl=1 150w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/password_bad.jpg?resize=75%2C43&amp;ssl=1 75w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/password_bad.jpg?w=420&amp;ssl=1 420w\" sizes=\"auto, (max-width: 150px) 100vw, 150px\" \/><\/a>his event correlated with the recent (04\/14\/2010) <a href=\"http:\/\/tufin.com\/\" target=\"_blank\" rel=\"noopener noreferrer\">Tufin Technologies<\/a> survey results of the hacking habits of 1,000 New York City teenagers. The <a href=\"https:\/\/web.archive.org\/web\/20130921134544\/http:\/\/www2.tufin.com:80\/news_events_press_releases.php?index=2010-04-14\" target=\"_blank\" rel=\"noopener noreferrer\">survey found<\/a> that 39% of the teens surveyed think hacking is &#8220;cool&#8221; and 16%, or roughly one in six, admitted to trying their hand at it. Only 15% of the entire sample has either been caught or knows someone who has &#8211; particularly disturbing considering 7% of young hackers reported they did so for money and 6% view it as a viable career path. <\/em><\/p>\n<p><em>The big lesson here is, of course, <strong>SECURE YOUR PASSWORDS<\/strong><\/em><\/p>\n<p>&nbsp;<\/p>\n<p><em><a title=\"Ralph Bach\" href=\"https:\/\/rbach.net\/index.php\/new-resume\/\" target=\"_blank\" rel=\"noopener noreferrer\">Ralph Bach<\/a>\u00a0has been in IT long enough to know better and has blogged from his\u00a0<a title=\"Bach Seat\" href=\"https:\/\/rbach.net\/\" target=\"_blank\" rel=\"noopener noreferrer\">Bach Seat<\/a> about IT, careers, and anything else that catches his attention since 2005. You can follow him on <a class=\"broken_link\" href=\"http:\/\/www.linkedin.com\/in\/rb48334\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">LinkedIn<\/a>,\u00a0<a href=\"https:\/\/www.facebook.com\/ralph.bach.14\" target=\"_blank\" rel=\"noopener noreferrer\">Facebook<\/a>,\u00a0and\u00a0<a href=\"https:\/\/twitter.com\/rbach48334\" target=\"_blank\" rel=\"noopener noreferrer\">Twitter<\/a>. Email the Bach Seat\u00a0<a href=\"mailto:\/\/bach.seat@gmail.com\" target=\"_blank\" rel=\"noopener noreferrer\">here<\/a>.<\/em><\/p>\n","protected":false},"excerpt":{"rendered":"<p>A 9-year-old VA boy took a school teachers username and password from the desk and made unauthorized changes to a Blackboard system<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4],"tags":[3240,181,128,209,4,1844],"class_list":["post-2639","post","type-post","status-publish","format-standard","hentry","category-security","tag-3240","tag-blackboard","tag-k12","tag-password","tag-security","tag-weak"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/posts\/2639","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/comments?post=2639"}],"version-history":[{"count":12,"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/posts\/2639\/revisions"}],"predecessor-version":[{"id":130068,"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/posts\/2639\/revisions\/130068"}],"wp:attachment":[{"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/media?parent=2639"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/categories?post=2639"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/tags?post=2639"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}