Jump to content

Recommended Posts

Posted

We have a kid here who was banned totally from using any ICT equipment in school by my predecessor. Today, one teacher allowed him to use a computer in class for work. He got a hard drive out of his bag, plugged it in and rebooted the PC.

 

The hard disk contains a bootable linux distro - Back|Track 3. Looks like a hackers favourite, all the tools there - spoofing, password attacks, forensic tools, etc, etc, etc.

 

Now I need to look in to why USB boot is enabled and what's being used as a BIOS password. That issue aside, I'm wondering what the general wisdom here is with such kids.

 

He's encouraging his mates to do similar thing. This week we've found RDP icons in peoples home drives, a selection of .bat files to do things like display pointless messages endlessly or make the user think their work has been deleted.

 

I can't help thinking that banning them from the network is not a solution to the problem? Is there anything you guys have done/do do with these kids - clubs/activities/punishment/research/lunchtime work - to combat this problem and channel their curiosity?

Posted (edited)
Had one before that we (I, tech staff and the head) banned from being within three feet of IT kit on pain of death and mutilation, and a few weeks later I found him logged into a backdoor. Phoned his fiery italian dad and explained that we were about to ask for police advice regarding a criminal prosecution, dad turned up and took him away to do eight hours enforced revision a day for the rest of the year :D Edited by powdarrmonkey
i've had no coffee this afternoon
Posted

Backtrack 3 is one of the best penetration testing tools out there. Free download as well.

 

Unfortunately anything you might do to try and channel this interest would also probably be giving them skills they'd misuse. Might be worth creating a very heavily locked down GPO for their particular accounts and dropping known troublemakers into it. Work on least-privilege. Take away abilities to do everything except what they actually need. Allow specific programs to be run, and set all others to be denied by default and so on.

 

The other thing that might be worth doing would be getting in touch with your local police and seeing if they have anyone who could come in and give the kids a lecture about electronic crime. Or even see if there's a penetration tester who might be willing to come in.

 

Disallowing .bat files and RDP might be a start as well.

Posted

Mmm, that's the root I'm trying to avoid. I know why these kids do it, heck if networks/pc where half as advanced as this when I was at school I'd have been trying the same. Instead I had to make do writing BBC Basic programs :(

 

This particular kid may just end up going down the whole - let's threaten to get the police involved, criminal conviction, et al - route. But I can't shake the feeling that there is a more practical solution.

 

Just stumped at what exactly to suggest!

Posted
The other thing that might be worth doing would be getting in touch with your local police and seeing if they have anyone who could come in and give the kids a lecture about electronic crime. Or even see if there's a penetration tester who might be willing to come in.

 

Depending where you are, I'd leap at the opportunity :)

Posted
Give him a job! :evil_twisted:

 

Actually, that's the type of thing I'm thinking off. But what! I don't mind them learning these skills. Could earn them a lot of money - good luck to them. They need to know when it's appropriate though - and my network is not their play ground (regardless of the holes I haven't filled in yet!) :stampsfeet:

Posted

As another thought then why not give them a playground? See if someone'll approve VMWare or VirtualPC or something similar, put a linux install in it and set them some challenges.

 

Either that or see if you have some older PCs around due for the scrapheap, put Linux on them, or Windows if you have the licenses, and give them a mini-network to play with. But I would say you want them to know the possible consequences should they try to use their 'skills' outside the playground, that's why it'd be worth getting the police and so on in as well.

  • Thanks 1
Posted

We had a child do a similar thing, and back in my day I was well versed at cracking networks, so I got him to show me where the holes were in my network and I fixed it. As such my network is much more secure.

 

If it were not for these blighters my network would be no where near as secure. As for the boot options, go into your BIOS, disable USB Boot and CD Boot, and then password the BIOS so the options cant be changed, and on the profiles, set a super mandatory profile to enforce that no USB devices get used apart from approved ones. That way only you and the staff can use USB devices.

Posted

If there so/ hes so computer literate, see if your school is willing to offer him simple course's like A+ and networking +, and giving him a job is probs bad idea because he may be competent but there is a maturity aspect, and it sound as if he would violate most rules regarding privacy given half the chance.

I like the VM idea, might also suggest getting him to see careers advisor see if they can make a more beneficial action plan, get him more interested in the maintanace of security.

Posted

Just had another thought, extending the VM thing and a little more ambitious. If you can set up a network in VM, even just a single DC and one client computer (on a decent workstation you'll be able to run both of these at a low-spec), then get them all to try and harden their own mini-domains.

 

After that, they swap domains and try to break in. Challenge is to be the first one to manage to get escalated priviliges.

 

Just if you're going to do that make sure you watch exactly what they're doing, and harden your own network against it.

Posted

Now that I like, a lot.

 

You got me thinking along the lines of grabbing a few old PC's and an old switch. Throwing them on a table with a few OS install disks (XP Pro, Win2k3, Linux), and saying there you go, build a working, secure network.

 

Maybe setting it up in VM's could be interesting - each VM as access to the sandbox network - but not the school network. Would need to look at the security on VMWare Server. Wouldn't want them to create/delete VM's but not have access to the networking settings. I know this is possible under ESX, but not sure on plan VMWare Server.

 

Maybe as an after school activity. Anyone caught hacking the network is thrown off the course, banned, threatened with police.

Posted (edited)

Bring him in at lunch time and ask him to "hack the network" Did that one day with one of the pupils in a school not long after I started. He told me he could access loads of things that he shoudln't have been able to. I told the head of ICT that I was having this kid in at lunch time and watched what he did. Sure enough he could get access to things they shouldn't have been able to. I (wrongly) assumed that the privaleges had been set by the person before me, but no one actually looked after the network before I started. After I saw what he did, I made changes to stop him having access to things they shouldn't. After that every time he found a way around the security he came straight to tell me. I think this was because he didn't believe me when I asked hom bypass the security in place and enjoyed the fact that I let him have a play (whilst being supervised by me)

 

Of course this depends on the type of pupil you have, and there is no way to know if they will just abuse your trust.

 

Edit: of course this is if you want to encourage them. Personally I would ban if they have been warned. Its fine to encourage people, but only if they deserve it.

Edited by penfold
Posted

As you said it does depend on each pupil. If the guy is a complete idiot and you know will breach your trust, then you shouldnt trust them but if the pupil is one that you believe you can trust then do the following.

 

Find an empty room that is not used, preferably a store room with power sockets, set up a switch, a "server", 3 machines, with with XP, 1 with ME, and 1 with MAC OS (X or leopard), and get the child to try to gain access to all 3. Depending on the skills of the child they can show you vunerabilities in your system which believe me, will help no end. If you know the vunerabilities, then you know where to improve your network.

Posted
Had one before that we (I, tech staff and the head) banned from being within three feet of IT kit on pain of death and mutilation, and a few weeks later I found him logged into a backdoor. Phoned his fiery italian dad and explained that we were about to ask for police advice regarding a criminal prosecution, dad turned up and took him away to do eight hours enforced revision a day for the rest of the year :D

 

 

Thats fantastic, thats what I call a lesson. I used to be just the same as most of these students were complaining about, I even complain about them now. I wish that I was encouraged more at school with me ICT as I used to love trying to break into schools systems, I even made a list over year 11 of all the problems and emailed it to the Network Manager at the end of the year.

 

Lets just say he wasn;t very happy, but was delighted when I left.

 

Dan

Posted

Well, the Head of Year responsible for the student is (hopefully) going to give the student in question a good scare. I've printed off the relevant sections of the Police and Justice Act 2006 and given them to him. Section 37 of Chapter 47 is the most interesting. It's an offense just to obtain the software with intent of using it on a network without permission let alone actually plug the HD in to the school network and boot it up!

 

I've got a meeting with my line manager in the next few minutes were the subject will come up. I'm still toying with the idea of some after school activity for those interested after Christmas.

 

Now for a more interesting question, are the developers of Back Track 3 in breach of section 37, chapter 48 of the Police and Justice Act 2006 for making this software available for download?

Posted
Now for a more interesting question, are the developers of Back Track 3 in breach of section 37, chapter 48 of the Police and Justice Act 2006 for making this software available for download?

 

As they are not in the UK I think they won't care if they are.

Posted
Now for a more interesting question, are the developers of Back Track 3 in breach of section 37, chapter 48 of the Police and Justice Act 2006 for making this software available for download?

 

Back Track is released as a security suite - not a hacking suite. Just because it can be used for bad things, doesn't mean it always will be...

Posted

I think that that law is suitably vague as to allow for people to use the defense of them being legitimate network security tools. For example, Nmap, Ping or even simply Windows XP could be said to fall within the remit of that law, so a judge would be forced to draw a line as to what would actually be the purpose of the law.

 

If a court case ended up causing issues, it can always end up referring back to Hansard, where the intent is clearly outlined.

Posted
Its all about the intent, otherwise they'd no longer be able to run CEH courses in this country and penetration testing would be illegal itself.
Posted
Its all about the intent, otherwise they'd no longer be able to run CEH courses in this country and penetration testing would be illegal itself.

 

'Intent' under the eyes of the law doesn't mean the same as normal usage though... Intent in law means 'knowing, or likely to know that the action could be, or would be, used for' whatever that particular law is referring to (this was told to me by various legal professionals, including a solicitor, barrister and a magistrate).

 

So, really, it is one giant grey area - as with much of the law in the UK.

Posted
Back Track is released as a security suite - not a hacking suite. Just because it can be used for bad things, doesn't mean it always will be...

 

With a url of 'remote-exploit.org' and a previous release name of 'WHAX'. I can't help get the feeling of being released under the guise of a security suite. Just because it's designed for bad things, doesn't mean it can't be used for good?

 

As they are not in the UK I think they won't care if they are.

My understanding is the penalty was set at two years so offenders could be liable for extradition? Don't know how that could play out though...

 

'Intent' under the eyes of the law doesn't mean the same as normal usage though... Intent in law means 'knowing, or likely to know that the action could be, or would be, used for' whatever that particular law is referring to

And this is why I think it's an interesting question. My reading of the law in question is that they are making this distribution freely available knowing that it could be used to commit acts under previous sections of the Act. Thus they fall fail of the law. If it is supposed to be a security package rather than a hacking tool should they not provide some kind of control as to who can download the software?

 

 

It just struck me when I was researching the law in this area, to pass the correct details to the head for this case, that it's easy for a group of individuals - such as those maintaining this release - to unwittingly commit an offense under that section of the law.

 

Could it be argued that by making the software freely available and easily downloadable from the net that authors of such software as 'ping' are now committing an offense?

Posted
Could it be argued that by making the software freely available and easily downloadable from the net that authors of such software as 'ping' are now committing an offense?

 

But where do you draw the line? Microsoft release Windows knowing it can and will be used for criminal acts. Do they fall foul of the law too?

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...