"Breaking into" thousands of school board accounts

One thing we're all taught from a young age is to be safe online. Keep good passwords, don't reveal personal information, etc. And who loves to teach us those lessons? Our schools. So why do they fail so horribly at internet safety?

Our school made recent changes to the system to set all of our usernames as our Student Identification Numbers (SINs). Each SIN is a unique number tied to all of our grades and accounts within the board. We used to have a slightly more secure system which involved your full name and the last three digits of your SIN, but that was scrapped in favor of just your SIN due to "security risks".

The biggest failing of this change is that SINs are assigned sequentially. The bigger the number, the newer the account. Why is this bad? Well, all new accounts are assigned with the password of "12345678". In fact, all accounts up to grade 2 or so are "12345678", so with that one password any any number within a certain range, you can log into any new account. Finding new accounts is as simple as finding the usernames with the biggest numbers*.

Do you know how many accounts are open like this? Thousands. Yes, you heard me right, thousands. Can you imagine how much of an impact that would be if someone locked out all those accounts? If someone created a little botnet? If someone even just gave away the classroom codes and personal data stored on every single one of those accounts**?

I realize that only younger students suffer from these vulnerable logins, and they don't have any permissions, but we should really be setting a good example by giving them at least somewhat secure passwords. What right do you have to tell us about why we need to be safe online when you can't even manage simple login? This system is frankly stupid and the school board should be ashamed.

*this can be done through the organization directory on google.

**not that google doesn't give personal info out anyways... no harm done there I suppose.


Logging into a random account:
I didn't go past the account setup screen, but I do realize that this is still wrong. I'm sorry for that. Hopefully I can contact my school board with this information and make up for my poor actions.

image(5).png

Searching for new accounts to log into:
Most accounts from 701000000 - 701010100 are open. 10000 potentially open accounts... jesus. I haven't even gone down all the way, and who knows how many early accounts were created but never accessed (students leaving the board, name changes, mistake accounts, etc).
I find accounts with lower numbers more often use different passwords as parents sometimes are smart and take matters into their own hands, changing to more secure passwords. Kudos to those parents. You're doing great, and your child is gonna thank you when they don't get hacked because of this!

account list.png

Comments

This is hilarious. What the fuck were they thinking?
Botnet, locking a bunch of accounts, give away personal data...or just save a bunch of Rule 34 and other explicit material on a 5-year-old's account - so many possibilities.

So incredibly short-sighted. You need to school the school on this topic.
 
I remember doing something kind of similar to this, though entirely different at the same time.
Y'know those people who sell games via account sharing? Like, you pay 5 bucks and they share their account with you and you can play said game.
Well, I bought some games from a seller who did this, and looked at the email itself. Something like (gamename)@(companyname). They put the password (but not the email) for all of the accounts on their website. So, I tried doing something to bypass this. I put a game that was one of the ones they sold in (gamename) and just used the password.
And it worked.
I did this for like 15-20 games, deadass.
I'm not complaining.
 
  • Like
Reactions: SylverReZ and rvtr
I've hacked into my school's GMail account once, knowing their password well cuz they left it on a piece of paper for everyone to see. :D
 

Blog entry information

Author
rvtr
Views
902
Comments
10
Last update

More entries in Personal Blogs

More entries from rvtr

Share this entry

General chit-chat
Help Users
  • Sicklyboy @ Sicklyboy:
    I used to drink alcohol fairly often. Never to the point of it being a problem, but like 2-3 beers with dinner each night, or a few cocktails or glasses of Scotch or something. Started smoking/vaping weed a lot a few years back which killed 90% of my interest in booze. Now I stopped smoking/vaping weed as much and just deal with life the boring way most of the time
    +1
  • Xdqwerty @ Xdqwerty:
    I only drank alcohol once and it was by accident
  • Xdqwerty @ Xdqwerty:
    I didnt know it was beer, it was on a juice bottle
  • SylverReZ @ SylverReZ:
    Yeah, I'm addicted to smoking, sadly. It's very addictive but I wish I didn't start.
  • K3Nv2 @ K3Nv2:
    May just order a 5700g for a nas/emulation set up tbh
  • Xdqwerty @ Xdqwerty:
    @SylverReZ, atleast you were asleep on 4/20
    +1
  • Xdqwerty @ Xdqwerty:
    @SylverReZ, you played that Mario flash game called Mario 63?
  • SylverReZ @ SylverReZ:
    @Xdqwerty, No, but I've seen it on Vinesauce's stream.
  • Xdqwerty @ Xdqwerty:
    @SylverReZ, that game is one of the reasons i met newgrounds bc the full versión of it is in that site
  • Xdqwerty @ Xdqwerty:
    Also somebody is remaking it
  • Xdqwerty @ Xdqwerty:
    @SylverReZ, the other game where I found newgrounds is new york shark
    +1
  • SylverReZ @ SylverReZ:
    Spoke to Tom Fulp the other day, if he can find his old Newgrounds site content like the mini Flash animations from the 2000's that played on the portal.
  • SylverReZ @ SylverReZ:
    So far no response, but he did say that he'll find them. Wayback Machine doesn't have em.
  • Xdqwerty @ Xdqwerty:
    @SylverReZ, atleast the 1999 versión of pico's school is avaliable (the difference between it, the 2006 versión and the 2016 versión is that the speed of the game depends of the speed of your computer and that it had the og soundtrack)
  • SylverReZ @ SylverReZ:
    @Xdqwerty, Another being Pico VS Bear, the original 1999 version before Jim Henson filed a DMCA takedown.
    +1
  • Xdqwerty @ Xdqwerty:
    The 2006 versión was made when the flash portal was made
  • SylverReZ @ SylverReZ:
    Many people thought it was lost, but was discovered that he hid it on the same page.
  • Xdqwerty @ Xdqwerty:
    @SylverReZ, although the "secrets" system where the game was has been removed. Also pico vs uberkids had a netplay versión that was shutdown, although the swf file has been found
  • SylverReZ @ SylverReZ:
    @Xdqwerty, Nope. There are two download buttons on the same page, where you can download the original under a file called "bear.exe". "bear2.exe", however, is the updated game in a Flash projector. P.s. this was on the archived Pico page from 2000.
  • SylverReZ @ SylverReZ:
    @Xdqwerty, That's been there for a long time, too. People who search for lost media don't look hard enough lmao.
    +1
  • Xdqwerty @ Xdqwerty:
    @SylverReZ, also the pico 2 demos used to be only for the newgrounds patrons but they are on internet archive too (https://archive.org/download/picos_school_2)
    +1
  • Xdqwerty @ Xdqwerty:
    Iirc the demos were removed from newgrounds in 2022
    Xdqwerty @ Xdqwerty: Iirc the demos were removed from newgrounds in 2022