Gambit Posted April 17, 2007 Posted April 17, 2007 One of our highschools were hacked. 2 kids finally found a way around our network. apperantly, the had full access to the ENTIRE domain, had a few virsus ready. The school tech caught them, but not sure how much damage was done before they were caught. Now I have the luxury of the principal at my school asking me to try to figure out how they got access to our entire domain. I dont even know where to start.
Norphy Posted April 17, 2007 Posted April 17, 2007 Interogation of the culprits would be the first step. Read them the riot act, quote the Computer Misuse Act etc etc. I hope that those caught are being suitably punished.
Oops_my_bad Posted April 17, 2007 Posted April 17, 2007 holy sh!t! Wonder if they've got hold of priviledged account details somehow What network was this? NT? 2000? 2003!? :!:
Gambit Posted April 17, 2007 Author Posted April 17, 2007 The details are pretty sketchy. From what I have been told, The one kid somehow got admin level rights, then gave his friend the same level of rights, and away they went. We just went to 2003 server roughly last year. The cops were call yesterday, so they're being charged, but thats about all the info I know. As of right now, all the techs are being left in the dark about this whole situtation. I dont even think that many techs know about this. I only know because the principal here is friends with the principal at the school that it happened. So only know of what he has told me.
benIT Posted April 17, 2007 Posted April 17, 2007 You dont wish it on anyone, its one of the worse things that can happen! I read somewhere majority of hacking is caused by people leaving machines logged on!! or someone knowing credentials of admin account. I always try and check my admin groups members every so often, as if they go undetected could simply use to gain infromation rather than damage. From the damage done you can normally track back to specific times etc, perhaps look at when files were deleted then you can tell how login was acheived from event logs etc. I take it you share the domain accross multiple sites ? Or have i miss understood? If so may be worth looking at creating sub domains and keep trusts between them, may limit damage. good luck!
GrumbleDook Posted April 17, 2007 Posted April 17, 2007 First things to do depend on whether you want to contain any possible problem or search for the entry point. If you want to contain any problem and ock things down then what you need to do is to check any group with admin level access ... change passwords of all admin accounts on a machine known to be clean of viruses, trojans and so on. Then start looking at machines known to be logged on to by staff with admin level access. Check for key logging software. Ensure all your AV software is up to date. Get a trial of enterprise level anti-spyware software to run a clean of all machines. I know of one school that was worried about similar after a former tech left under a cloud and they had a few strange things happening. They asked Securus for a 2 week trial and put the old admin password (and a few other bit) in the monitor list to see if anyone was trying to log on with admin level accounts. They caught a few students, who had been given information by a friend of the former tech, trying to change a number of things ... and then they didn't bother with Securus after that, but it did the job :-) If the students have been charged then it is likely that the police (and someone at the school) has information about what was being done. Even if it means the Techies find out that they drop a ball somewhere it is important to get the information and clean house.
mattx Posted April 17, 2007 Posted April 17, 2007 The cops were call yesterday, so they're being charged, With what ? [ just out of interest ] How old were the kids ?
Gatt Posted April 17, 2007 Posted April 17, 2007 I would hope with violating the Computer Misuse Act.
mrcrazy04 Posted April 17, 2007 Posted April 17, 2007 Yeah, if I read the Computer Misuse Act right, they could get up to 15 years . up to 5 for attempting to get access up to 5 for unauthorised modification of data up to 5 for setting it up so they can get further access. For each time they got in!!
GrumbleDook Posted April 17, 2007 Posted April 17, 2007 Articles under the same act tend to run consecutively for offences that carry up to 5 years or £3000 fines ... it is up to the sentencing judge and depending on the age this is very unlikely. Shame really ...
localzuk Posted April 17, 2007 Posted April 17, 2007 They will more likely just get a slap on the rist, aka. an official caution. Unless they have a preior criminal record that is.
mattx Posted April 17, 2007 Posted April 17, 2007 What sort of punishment will fall on the manager who is overall responsible for the network to start with..... ? Of course - said Tongue In Cheek.... :-)
_Bat_ Posted April 17, 2007 Posted April 17, 2007 Meh. I had access to the admin account when I was at school. And my friend did. We didn't have an ICT Technician at the time, the network was run by the ICT Teacher/Head of ICT and he never found out that we knew the password. It was an RM network and the admin account had some cool controls such as remote control of other networked PCs which we used reguarly to scare people (we used to randomly eject their CD drives and laugh in the corner as they became highly confused). We never attempted to damage the network in any way though. I wasn't -that- immature. The only reason we knew the password was because on the RM network they had installed, there was two admin accounts (administrator and admin2). The head of ICT used the administrator account with his own password, but even though he knew about the admin2 account, he never changed it from its default password, which, ironically was "removed". My friend and I of course found out about it and we had full admin rights for over two years. The head of ICT obviously believed in security though obscurity. [ password removed - just in case, plus used in a few things - tarquel ]
Midget Posted April 17, 2007 Posted April 17, 2007 so it's a standard thing from RM to have "removed" then? Successmaker has it as default as well [ edited for the reason above - tarquel ]
Grommit Posted April 17, 2007 Posted April 17, 2007 One of our highschools were hacked. 2 kids finally found a way around our network. apperantly, the had full access to the ENTIRE domain, had a few virsus ready. The school tech caught them, but not sure how much damage was done before they were caught. Now I have the luxury of the principal at my school asking me to try to figure out how they got access to our entire domain. I dont even know where to start. I pay the students for information.. an couple of pound here and there goes a long way... They grass up hackers, hacker tricks and rogue teacher passwords :-)
webman Posted April 17, 2007 Posted April 17, 2007 so it's a standard thing from RM to have "removed" then? Yes. But there's no excuse for people ignoring RM's advice and common sense of changing these ASAP
eejit Posted April 17, 2007 Posted April 17, 2007 Guys, probably not a good idea to list those default passwords here.
tosca925 Posted April 17, 2007 Posted April 17, 2007 Guys, probably not a good idea to list those default passwords here Probably not a good idea if you have these default passwords still any how.
Netwacky87 Posted April 17, 2007 Posted April 17, 2007 Well i must admit, i used to "PLAY AROUND" with the network we had at school, and i must admit the techys we had always used to know it was me (and another friend), We NEVER did and i personally never would do anything malicous to the network that was never my intention it was basically find the loopholes in the network and stop other users doing the same, which the techy's appreciated! Must admit though paying the students a few quid to grass on there mates is a brilliant idea!
fooby Posted April 17, 2007 Posted April 17, 2007 I think it might be an idea to set passwords to words that people really wouldnt want as passwords, im thinking passwords such as bad swear words etc. I would think that people might want to change these. Or default passwords such as "vCF&£g45n" that might wind ppl up enough to change. Or potentially secure enough to leave (as long as its undocumented) fooby
phreak Posted April 18, 2007 Posted April 18, 2007 Sorry to hear about it Gambit. It's horrible when that sort of thing happens. And you would have thought that a password that is telling your to change it would make some people think to change it but thats not always the case. I think RM should put some sort of "Force change of password after a few logons" rule for their admin passwords, but alas that would not help you now. As well as doing all those other things the guys have suggested I would actually recommend running a couple of anti-spyware and virus programs as just one of each does not always cut it. Use some of the freeware ones like Spybot and Avast. Also, if you think there may still be backdoors in the system then maybe try setting up a honeypot trap to see if anyone goes for it. I would use something like Helix Linux boot disk to do this. Alternatively if the server is severly comprimised then it might be quicker to just start again from scratch with it. Still.. better you than me. Oh, and you might want to take a copy of some of the more relevent logfiles if you haven't already done so before they start to overwrite themselves with newer logs.
Geoff Posted April 18, 2007 Posted April 18, 2007 If the police are involved, they will probably take the DC as evidence. Therefore, you need a full backup from prior to the incident and some spare hardware to restore to. While were here, I'd like to remind everyone of the Enterprise best practises security guides available on Technet. http://www.microsoft.com/technet/security/secnews/articles/enterprisesecbp.mspx Further help and assistance can be had in the Security forum for anyone who wants it.
tarquel Posted April 18, 2007 Posted April 18, 2007 Guys, probably not a good idea to list those default passwords here. Quite right. done Whether people should change default passwords or not, it's one I've seen in alot of things, and people are imperfect so accidentally leaving a default password can happen. Nath.
_Bat_ Posted April 18, 2007 Posted April 18, 2007 I can understand the point of removing the passwords, but personally I am not sure if it is worth it. I imagined myself in a position of a malicious student trying to hack into my school network and my immediate reaction was to to do a google search using terms related to the above discussion. Guess what? The very first result gave away all . If I can do that within 10 seconds, I'm sure other people can as well .
Geoff Posted April 18, 2007 Posted April 18, 2007 I could mention something about 'Security' and 'Obscurity' at this point. But I'm getting bored of repeating myself.
Recommended Posts
Create an account or sign in to comment
You need to be a member in order to leave a comment
Create an account
Sign up for a new account in our community. It's easy!
Register a new accountSign in
Already have an account? Sign in here.
Sign In Now