{"id":77384,"date":"2015-07-02T22:15:48","date_gmt":"2015-07-03T02:15:48","guid":{"rendered":"http:\/\/rbach.net\/blog\/index.php\/"},"modified":"2021-08-11T20:53:24","modified_gmt":"2021-08-12T00:53:24","slug":"the-enemy-within-at-school","status":"publish","type":"post","link":"https:\/\/rbach.net\/index.php\/the-enemy-within-at-school\/","title":{"rendered":"The Enemy Within at School"},"content":{"rendered":"<p><em><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" class=\"alignleft wp-image-104823\" title=\"The Enemy Within at School\" src=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/insider_threat1.jpg?resize=125%2C100&#038;ssl=1\" alt=\"The Enemy Within at School\" width=\"125\" height=\"100\" srcset=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/insider_threat1.jpg?resize=150%2C120&amp;ssl=1 150w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/insider_threat1.jpg?resize=75%2C60&amp;ssl=1 75w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/insider_threat1.jpg?w=300&amp;ssl=1 300w\" sizes=\"auto, (max-width: 125px) 100vw, 125px\" \/><a href=\"https:\/\/nakedsecurity.sophos.com\/\" target=\"_blank\" rel=\"noopener noreferrer\">Naked Security<\/a><\/em> <a href=\"https:\/\/nakedsecurity.sophos.com\/2015\/04\/14\/teen-charged-after-using-teachers-admin-password-to-access-school-computer\/\" target=\"_blank\" rel=\"noopener noreferrer\">reports<\/a>\u00a0on\u00a0a hack that combines two of our favorite\u00a0things on the <a href=\"https:\/\/rbach.net\/\" target=\"_blank\" rel=\"noopener noreferrer\"><strong>Bach Seat<\/strong><\/a><strong>, <a href=\"http:\/\/www.buzzfeed.com\/briangalindo\/25-things-youll-only-see-in-florida#.ddE4WE5jaP\" target=\"_blank\" rel=\"noopener noreferrer\">Florida<\/a>,<\/strong> and <strong>lax data security<\/strong> at school. The way the <a href=\"https:\/\/web.archive.org\/web\/20110607234024\/http:\/\/www.sophos.com\/\" target=\"_blank\" rel=\"noopener noreferrer\">Sophos<\/a> blog\u00a0tells the story, a 14-year-old <a title=\"Florida\" href=\"http:\/\/maps.google.com\/maps?ll=28.1,-81.6&amp;spn=3.0,3.0&amp;q=28.1,-81.6 (Florida)&amp;t=h\" target=\"_blank\" rel=\"geolocation nofollow noopener noreferrer\">Florida<\/a> boy is charged with being a hacker by <strong>trespassing<\/strong> on his school&#8217;s computer system.<\/p>\n<h3>Florida school hacker<\/h3>\n<p>The charges came after he <strong>shoulder-surfed<\/strong> a teacher typing in\u00a0his <strong>password <\/strong>and used it without permission to trespass in the network. The student then tried to embarrass a teacher he doesn&#8217;t like by swapping his desktop wallpaper with an image of two men kissing.<\/p>\n<p><a href=\"https:\/\/web.archive.org\/web\/20150924235041\/http:\/\/www.gfi.com\/blog\/insidious-insider-threat\/\" target=\"_blank\" rel=\"noopener noreferrer\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" class=\"alignright wp-image-104825\" title=\"an offense against a computer system and unauthorized access\" src=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/insider_threat-2-e1568845032576-118x150.jpg?resize=100%2C127&#038;ssl=1\" alt=\"an offense against a computer system and unauthorized access\" width=\"100\" height=\"127\" srcset=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/insider_threat-2-e1568845032576.jpg?resize=118%2C150&amp;ssl=1 118w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/insider_threat-2-e1568845032576.jpg?resize=59%2C75&amp;ssl=1 59w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/insider_threat-2-e1568845032576.jpg?w=183&amp;ssl=1 183w\" sizes=\"auto, (max-width: 100px) 100vw, 100px\" \/><\/a>A <em><a href=\"https:\/\/www.tampabay.com\/\" target=\"_blank\" rel=\"noopener noreferrer\">Tampa Bay Times<\/a> <\/em><a href=\"https:\/\/www.tampabay.com\/\" target=\"_blank\" rel=\"noopener noreferrer\">article<\/a> says that an <strong>eighth-grader<\/strong> was recently arrested for &#8220;an offense against a computer system and unauthorized access.&#8221; This is a <strong>felony in Fla<\/strong>. Sheriff Chris Nocco said that the teen logged onto the network of a <a title=\"Pasco County, Florida\" href=\"http:\/\/maps.google.com\/maps?ll=28.3,-82.44&amp;spn=1.0,1.0&amp;q=28.3,-82.44 (Pasco%20County%2C%20Florida)&amp;t=h\" target=\"_blank\" rel=\"geolocation nofollow noopener noreferrer\">Pasco County<\/a>\u00a0School District school using an <strong>administrative-level password<\/strong> without\u00a0permission.<\/p>\n<p>A spokesman for the <a title=\"Pasco County Sheriff's Office\" href=\"http:\/\/www.pascosheriff.com\/\" target=\"_blank\" rel=\"homepage nofollow noopener noreferrer\">Pasco County Sheriff&#8217;s Office<\/a> told <em><a title=\"Network World\" href=\"http:\/\/en.wikipedia.org\/wiki\/Network_World\" target=\"_blank\" rel=\"wikipedia nofollow noopener noreferrer\">Network World<\/a><\/em> that the student was not detained. Rather, he was questioned at the school before being released to his mother. His sentence remains to be seen, But at this point, it&#8217;s looking like the boy isn&#8217;t going to suffer much more than a <strong>10-day school suspension.\u00a0<\/strong>Sheriff&#8217;s detective Anthony Bossone says is likely to be &#8220;pretrial intervention&#8221; by a judge with regards to the felony charge, the <em>Tampa Bay Times<\/em> reports. Naked Security says this is the <strong>student\u2019s\u00a0second offense<\/strong>.<\/p>\n<p><a href=\"http:\/\/www.chinadaily.com.cn\/china\/2010-05\/24\/content_9882404.htm\" target=\"_blank\" rel=\"noopener noreferrer\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" class=\"alignright wp-image-104827\" title=\"Old school security\" src=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/NETWORK_SECURITY_OLD_SCHOOL.jpg?resize=100%2C135&#038;ssl=1\" alt=\"Old school security\" width=\"100\" height=\"135\" srcset=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/NETWORK_SECURITY_OLD_SCHOOL.jpg?resize=111%2C150&amp;ssl=1 111w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/NETWORK_SECURITY_OLD_SCHOOL.jpg?resize=55%2C75&amp;ssl=1 55w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/NETWORK_SECURITY_OLD_SCHOOL.jpg?w=442&amp;ssl=1 442w\" sizes=\"auto, (max-width: 100px) 100vw, 100px\" \/><\/a>When the newspaper interviewed the student, he said that he&#8217;s not the only one who uses that password. <strong>Other students commonly log into the administrative account<\/strong> to screen-share with their friends, he said. It&#8217;s a well-known trick, the student said. He claimed the password was a snap to remember, it&#8217;s just the teacher&#8217;s last name, which the boy says he learned by watching the teacher type it in.<\/p>\n<p>The sheriff says that the student didn&#8217;t just access the teacher&#8217;s computer to pull his wallpaper prank. He also reportedly accessed a computer with sensitive data &#8211; <strong>the state&#8217;s <a title=\"Standardized test\" href=\"http:\/\/en.wikipedia.org\/wiki\/Standardized_test\" target=\"_blank\" rel=\"wikipedia nofollow noopener noreferrer\">standardized tests<\/a> &#8211;<\/strong>\u00a0(<em>now we know why he is in trouble &#8211; <strong>NCLB! &#8211; Common Core!!<\/strong>)\u00a0<\/em>while logged in as an administrator. Those are files he well could have\u00a0viewed or tampered with, though he denies having done so. Sheriff Nocco says that&#8217;s the reason\u00a0why this can&#8217;t be dismissed as being just a bit of fun. Even though some might say this is just a teenage prank, who knows what\u00a0this teenager might have done.<\/p>\n<p style=\"text-align: justify; padding-left: 30px;\"><em>I logged out of that computer and logged into a different one and I logged\u00a0into a teacher&#8217;s computer who I didn&#8217;t like and tried putting inappropriate pictures onto his computer to annoy him<\/em>.<\/p>\n<p>in typical HS-er logic, he told the newspaper:<\/p>\n<p style=\"text-align: justify; padding-left: 30px;\"><em>If they&#8217;d have notified me it was illegal, I wouldn&#8217;t have done it in the\u00a0first place. But all they said was &#8216;You shouldn&#8217;t be doing that.<\/em>&#8216;<\/p>\n<h3>Idaho school hacker<\/h3>\n<p><a href=\"https:\/\/www.acunetix.com\/blog\/articles\/slow-http-dos-attacks-mitigate-apache-http-server\/\" target=\"_blank\" rel=\"noopener noreferrer\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" class=\"alignright wp-image-104829 size-medium\" title=\"rented a cloud based botnet to launch a distributed denial of service\" src=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/attack_DOS.jpg?resize=150%2C79&#038;ssl=1\" alt=\"rented a cloud based botnet to launch a distributed denial of service\" width=\"150\" height=\"79\" srcset=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/attack_DOS.jpg?resize=150%2C79&amp;ssl=1 150w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/attack_DOS.jpg?resize=75%2C39&amp;ssl=1 75w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/attack_DOS.jpg?w=290&amp;ssl=1 290w\" sizes=\"auto, (max-width: 150px) 100vw, 150px\" \/><\/a>Another report from the other side of the continent comes from <em><a href=\"http:\/\/www.engadget.com\/\" target=\"_blank\" rel=\"noopener noreferrer\">Engadget<\/a>. <\/em>They\u00a0<a href=\"http:\/\/www.engadget.com\/2015\/05\/20\/teenager-idaho-ddos\/\" target=\"_blank\" rel=\"noopener noreferrer\">report<\/a> that a teenager from <a title=\"Idaho\" href=\"http:\/\/maps.google.com\/maps?ll=45.0,-114.0&amp;spn=3.0,3.0&amp;q=45.0,-114.0 (Idaho)&amp;t=h\" target=\"_blank\" rel=\"geolocation nofollow noopener noreferrer\">Idaho<\/a> took advantage of the latest trend in <strong>online criminal activity. <\/strong>He likely rented a <strong>cloud-based botnet<\/strong> to launch a <strong>distributed denial of service<\/strong> (DDos) against the largest school district in Idaho. The alleged <strong><a title=\"Denial-of-service attack\" href=\"http:\/\/en.wikipedia.org\/wiki\/Denial-of-service_attack\" target=\"_blank\" rel=\"wikipedia nofollow noopener noreferrer\">DDoS<\/a><\/strong> took down the school district&#8217;s internet access according to media reports.<\/p>\n<p>KTVB News reports that the 17-year-old student paid a third party to conduct a distributed denial-of-service attack\/ The attack forced the entire <strong>West Ada school district offline<\/strong>. The act disrupted more than 50 schools, bringing everything from payroll to <strong>standardized tests<\/strong>\u00a0(<em>More high stakes testing &#8211; <strong>NCLB! Common Core!!<\/strong><\/em>) grinding to a halt. Unfortunate students undertaking the <strong>Idaho Standard Achievement test<\/strong> had\u00a0to go through the process multiple times because the system kept losing their work and results.<\/p>\n<p><a href=\"https:\/\/web.archive.org\/web\/20190823181855\/http:\/\/ddosattackprotection.org:80\/blog\/large-scale-ddos-attacks\/\" target=\"_blank\" rel=\"noopener noreferrer\"><img data-recalc-dims=\"1\" loading=\"lazy\" decoding=\"async\" class=\"alignright wp-image-104831\" title=\"State and Federal felony charges\" src=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/ATTACK__DDOS.jpg?resize=140%2C100&#038;ssl=1\" alt=\"State and Federal felony charges\" width=\"140\" height=\"100\" srcset=\"https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/ATTACK__DDOS.jpg?resize=150%2C107&amp;ssl=1 150w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/ATTACK__DDOS.jpg?resize=75%2C54&amp;ssl=1 75w, https:\/\/i0.wp.com\/rbach.net\/wp-content\/uploads\/ATTACK__DDOS.jpg?w=600&amp;ssl=1 600w\" sizes=\"auto, (max-width: 140px) 100vw, 140px\" \/><\/a>The report goes on to say that authorities have found the <strong>Eagle High student<\/strong> from their IP address. The students could now face <strong>State and Federal felony charges<\/strong>. If found guilty, the unnamed individual is likely to serve up to 180 days in jail, as well as being expelled from school. In addition, the suspect&#8217;s <strong>parents will be asked to pay for the financial losses<\/strong> suffered as a consequence of the attack.<\/p>\n<p><strong><em>rb-<\/em><\/strong><\/p>\n<p><em>Many school networks have bigger pipes than the business world. Some EDU networks I have worked on have had <a title=\"10-gigabit Ethernet\" href=\"http:\/\/en.wikipedia.org\/wiki\/10-gigabit_Ethernet\" target=\"_blank\" rel=\"wikipedia nofollow noopener noreferrer\">10 GigE<\/a> for years. In the rest of the online world, these incidents would serve as a wake-up call to network managers that hey, we might be at risk too, but not schools. Oh yeah &#8211; <strong>Passwords are Evil<\/strong><\/em><\/p>\n<p><em>Rightly or wrongly schools rely on the Intertubes for their core business &#8211; instruction, and NCLB high-stakes testing. However, they do not take steps to protect themselves. Administrators fight common tactics like periodic password changes, enforcing password complexity, or blacklisting common weak passwords. None bother with an anti-DDOS strategy let alone buying a tool to fight off a denial of service attack.<\/em><\/p>\n<h6>Related articles<\/h6>\n<ul>\n<li><a href=\"https:\/\/www.itbusiness.ca\/news\/it-world-canada-fights-for-survival\/127460\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">Stop DDoS attacks, CISOs urged<\/a> (itworldcanada.com)<\/li>\n<\/ul>\n<p>&nbsp;<\/p>\n<p><em><a title=\"Ralph Bach\" href=\"https:\/\/rbach.net\/index.php\/new-resume\/\" target=\"_blank\" rel=\"noopener noreferrer\">Ralph Bach<\/a>\u00a0has been in IT long enough to know better and has blogged from his\u00a0<a title=\"Bach Seat\" href=\"https:\/\/rbach.net\/\" target=\"_blank\" rel=\"noopener noreferrer\">Bach Seat<\/a> about IT, careers, and anything else that catches his attention since 2005. You can follow him on <a class=\"broken_link\" href=\"http:\/\/www.linkedin.com\/in\/rb48334\" target=\"_blank\" rel=\"noopener noreferrer nofollow\">LinkedIn<\/a>,\u00a0<a href=\"https:\/\/www.facebook.com\/ralph.bach.14\" target=\"_blank\" rel=\"noopener noreferrer\">Facebook<\/a>,\u00a0and\u00a0<a href=\"https:\/\/twitter.com\/rbach48334\" target=\"_blank\" rel=\"noopener noreferrer\">Twitter<\/a>. Email the Bach Seat\u00a0<a href=\"mailto:\/\/bach.seat@gmail.com\" target=\"_blank\" rel=\"noopener noreferrer\">here<\/a>.<\/em><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Insider threats are nothing new at school EDU has had to defend against enemies within since they got their first Internet connection<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4],"tags":[3277,2480,1935,1933,1748,2472,67,1372,2476,2483,128,2474,209,4,2482,2481],"class_list":["post-77384","post","type-post","status-publish","format-standard","hentry","category-security","tag-3277","tag-administrative-privledge","tag-cloud","tag-common-core","tag-ddos","tag-florida","tag-hack","tag-high-school","tag-idaho","tag-insider-threat","tag-k12","tag-nclb","tag-password","tag-security","tag-shoulder-surf","tag-social-engineering"],"aioseo_notices":[],"_links":{"self":[{"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/posts\/77384","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/comments?post=77384"}],"version-history":[{"count":13,"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/posts\/77384\/revisions"}],"predecessor-version":[{"id":131788,"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/posts\/77384\/revisions\/131788"}],"wp:attachment":[{"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/media?parent=77384"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/categories?post=77384"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/rbach.net\/index.php\/wp-json\/wp\/v2\/tags?post=77384"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}