Jump to content

Recommended Posts

Posted

Locally, everyone's been obsessing with this story over the last few days.

Not being overly familiar with the technical side of things, all I really know is that they have SIMS running on an RM CC3 Network, and have just launched their Hosted SIMS Learning Gateway (which is now suspended).

 

I find it hard to believe that any pupil would manage to compromise a piece of software like SIMS, it's pretty professional software.

 

Colwyn Bay's Eirias school 'hack' claims investigated

 

Education officials say the allegations about hacking records are under investigation

 

An investigation is underway at Colwyn Bay's Eirias High School into whether computer records of pupils have been stolen.

 

It follows claims posted on the internet by someone claiming to be a pupil and having accessed the records.

 

The head teacher said no download of student data has been achieved by the alleged hacker.

 

However, Phil McTague said they are continuing to investigate the allegations in conjunction with police.

 

In internet postings to two so-called computer 'hacking' message boards, the individual stated: "Hey guys, I'm pleased to say that I have successfully hacked my school.

 

"I have downloaded everyoes (sic) reports, and am now working through a long list of revenge stuff.

 

"I'm thinking of trying to sell the information like this, any idea how to do it?

 

"Any ideas for what I can do next? Bros, you should be worshiping me!"

 

The postings also have an image of alleged records that have been downloaded.

 

In a statement from Eirias High School, staff confirmed that they had been informed of the alleged security breach.

 

"We are dealing with the issue as a matter of urgency and a team of specialists from Conwy Education Service is assisting us with our investigation," said the statement.

 

"To date we cannot confirm the allegations."

 

It is understood that North Wales Police have also been informed of the developments.

 

In January, the school was reported to the Information Commissioner over a complaint that personal information on a pupil was made public through a YouTube video.

From BBC News - Colwyn Bay's Eirias school 'hack' claims investigated

 

A quick search for the hacker's quotes leads you to the original posts on the hacking forums and their screenshots of what is definitely SIMS data and a report (and is real).

Posted
I find it hard to believe that any pupil would manage to compromise a piece of software like

 

But what about a pupil managing to compromise a teachers credentials?

Posted

Not suprising really, sims could do with a way to enforce password complexity etc when using database security rather than active directory to authenticate - no-one know's how secure each users passwords are and sims dosen't even differentiate between case so mixing case is entirely useless.

 

Also I don't know about everyone else but I find that our typical end users don't understand or care about the importance of keeping MIS data secure, when I first started here the majority of sims passwords were "password" and I'm not entirely convinced they are much more secure now despite having a policy in place requiring users to choose more secure passwords(will be moving to AD integrated soon me thinks).

Posted
Proves to me that all the effort and complexity of our county implementing 2 factor authentication is well worth it. I imagine that it isn't a hack just a login details grab (bets on a post-it note somewhere).
Posted
Well, it looks like to forum mentioned has gone offline, also my guess that this is not 'hacking', but rather either locating the aformentioned Post-It note or simply watching the teacher type in their password on several occasions and working it out piecemeal.
Posted
Well, it looks like to forum mentioned has gone offline, also my guess that this is not 'hacking', but rather either locating the aformentioned Post-It note or simply watching the teacher type in their password on several occasions and working it out piecemeal.

 

or possibly even the teacher saying it out loud as they type

Posted
Proves to me that all the effort and complexity of our county implementing 2 factor authentication is well worth it. I imagine that it isn't a hack just a login details grab (bets on a post-it note somewhere).

 

Seems like the most likely explanation to me....

Posted

All you need to know is that nothing is secure, everything can be hacked.

 

Even RSA have recently been hacked:

RSA hacked, data exposed that could 'reduce the effectiveness' of SecurID tokens -- Engadget

 

imho schools shouldn't use wireless networks and the pupil management system should be on a completely closed computer. Wireless networks are fairly easy to hack (under 20 mins using an automatic device) if they use WEP, WPA may be just as easy to hack any day soon. Once on a wireless network you use a network card that acts in promiscuous mode to intercept all network traffic, grabbing passwords, data, etc as it goes from one ip address to another.

 

Also imho, you should not buy a certain brand of router from a certain manufacturer, this is like a red flag to a bull. This particular brand is use by most military organisations, governments and banks - they are quite famous. There are IP wardiallers out they that specifically look for the charactistics of data replies for this brand. If you do use that brand, be prepared to have a member of staff looking 247 for zero day hacks.

 

Cloud networks are a very attractive 'hack' - once you take over a cloud network then you generally have access to all the data for all the customers of that cloud network. imho if you want to keep your data secure, encrypt it before it get to the cloud network or don't use one.

 

Again, all you need to know is that nothing is secure, everything can be hacked!

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...