"Breaking into" thousands of school board accounts

One thing we're all taught from a young age is to be safe online. Keep good passwords, don't reveal personal information, etc. And who loves to teach us those lessons? Our schools. So why do they fail so horribly at internet safety?

Our school made recent changes to the system to set all of our usernames as our Student Identification Numbers (SINs). Each SIN is a unique number tied to all of our grades and accounts within the board. We used to have a slightly more secure system which involved your full name and the last three digits of your SIN, but that was scrapped in favor of just your SIN due to "security risks".

The biggest failing of this change is that SINs are assigned sequentially. The bigger the number, the newer the account. Why is this bad? Well, all new accounts are assigned with the password of "12345678". In fact, all accounts up to grade 2 or so are "12345678", so with that one password any any number within a certain range, you can log into any new account. Finding new accounts is as simple as finding the usernames with the biggest numbers*.

Do you know how many accounts are open like this? Thousands. Yes, you heard me right, thousands. Can you imagine how much of an impact that would be if someone locked out all those accounts? If someone created a little botnet? If someone even just gave away the classroom codes and personal data stored on every single one of those accounts**?

I realize that only younger students suffer from these vulnerable logins, and they don't have any permissions, but we should really be setting a good example by giving them at least somewhat secure passwords. What right do you have to tell us about why we need to be safe online when you can't even manage simple login? This system is frankly stupid and the school board should be ashamed.

*this can be done through the organization directory on google.

**not that google doesn't give personal info out anyways... no harm done there I suppose.


Logging into a random account:
I didn't go past the account setup screen, but I do realize that this is still wrong. I'm sorry for that. Hopefully I can contact my school board with this information and make up for my poor actions.

image(5).png

Searching for new accounts to log into:
Most accounts from 701000000 - 701010100 are open. 10000 potentially open accounts... jesus. I haven't even gone down all the way, and who knows how many early accounts were created but never accessed (students leaving the board, name changes, mistake accounts, etc).
I find accounts with lower numbers more often use different passwords as parents sometimes are smart and take matters into their own hands, changing to more secure passwords. Kudos to those parents. You're doing great, and your child is gonna thank you when they don't get hacked because of this!

account list.png

Comments

This is hilarious. What the fuck were they thinking?
Botnet, locking a bunch of accounts, give away personal data...or just save a bunch of Rule 34 and other explicit material on a 5-year-old's account - so many possibilities.

So incredibly short-sighted. You need to school the school on this topic.
 
I remember doing something kind of similar to this, though entirely different at the same time.
Y'know those people who sell games via account sharing? Like, you pay 5 bucks and they share their account with you and you can play said game.
Well, I bought some games from a seller who did this, and looked at the email itself. Something like (gamename)@(companyname). They put the password (but not the email) for all of the accounts on their website. So, I tried doing something to bypass this. I put a game that was one of the ones they sold in (gamename) and just used the password.
And it worked.
I did this for like 15-20 games, deadass.
I'm not complaining.
 
  • Like
Reactions: SylverReZ and rvtr
I've hacked into my school's GMail account once, knowing their password well cuz they left it on a piece of paper for everyone to see. :D
 

Blog entry information

Author
rvtr
Views
869
Comments
10
Last update

More entries in Personal Blogs

More entries from rvtr

General chit-chat
Help Users
  • No one is chatting at the moment.
  • K3Nv2 @ K3Nv2:
    Slower speeds for gen4
  • K3Nv2 @ K3Nv2:
    I'll reformat and have a 3tb raid0 m. 2 at least
    +1
  • K3Nv2 @ K3Nv2:
    Lmao that sold out fast
    +1
  • Veho @ Veho:
    Yeet the cat.
    +1
  • K3Nv2 @ K3Nv2:
    Good idea
    +1
  • The Real Jdbye @ The Real Jdbye:
    i thought everybody knew cocktails are like 75% ice
  • Veho @ Veho:
    Yeah but not like this.
  • Veho @ Veho:
    It's not like they're complaining that their Slurpee is 99% ice or something, but if the cocktail calls for "shot of vodka, shot of vermouth, shot of gin, shot of Campari, three shots of juice, squirt of lemon" and ends up being a thimbleful of booze, that's a problem.
  • The Real Jdbye @ The Real Jdbye:
    the funny thing is cocktails in norway are only allowed to have 1 20ml shot of booze
  • The Real Jdbye @ The Real Jdbye:
    so..... yeah
  • The Real Jdbye @ The Real Jdbye:
    we're used to only having a thimbleful of booze
  • Veho @ Veho:
    Booo.
  • The Real Jdbye @ The Real Jdbye:
    same thing if you want whisky on the rocks or something, you can't get a double
  • The Real Jdbye @ The Real Jdbye:
    but you could buy as many shots of whisky (or anything else) as you want and ask for a glass of ice and pour them in
  • The Real Jdbye @ The Real Jdbye:
    it's dumb
  • Veho @ Veho:
    Maybe.
  • Veho @ Veho:
    There was a comparison of the number of Ibuprofen poisonings before and after they limited the maximum dosage per box or per pill (i'll look that up). No limit on the number of boxes you can still buy as many as you want, so people argued it was pointless.
  • Veho @ Veho:
    But the number of (accidental) poisonings dropped because drinking an entire package of ibuprofen pills went from "I need a new liver" to "I need a new box of Ibuprofen".
  • Veho @ Veho:
    Here we have ketoprofen that used to be prescription-only because of the risk of toxic dosages, but then they halved the dose per pill and sell them in bottles of six pills apiece instead of twenty and it doesn't need a prescription any more. Yes you can buy more than one bottle but people simply don't.
  • Psionic Roshambo @ Psionic Roshambo:
    Usually accidentally overdose of ibuprofen here is from people taking like cold medicine then ibuprofen for a headache and the combination is over what they need
    Psionic Roshambo @ Psionic Roshambo: https://www.youtube.com/watch?v=1hp24nDVKvY