Google Search

Showing posts with label student. Show all posts
Showing posts with label student. Show all posts

Wednesday, November 27, 2013

College student gets a year in the slammer for keylogging student accounts to rig election

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Vote for me. Image courtesy of ShutterstockOn the last day of the four-day 2012 election for student council, computer techs noticed that something was a bit off with one of the university's computers.

Viewing it remotely, they noted that whoever was using the computer cast vote after vote.

The techs then watched the mysteriously multi-voting user log into the account of a university official. There, he read an email from a student who complained that the system was preventing her from voting.

There were actually quite a few students who couldn't vote in that election, because their login details had been electronically pickpocketed by the same young man who was running for student council president.

That man, former California State University San Marcos student Matthew Weaver, has been found guilty of using keyloggers to steal nearly 750 student passwords, many of which he then used to log in to others' accounts and to then fraudulently cast votes for himself and four of his fraternity brothers.

On Monday Weaver was sentenced in federal court to a year in prison, according to the U-T San Diego.

Authorities said that Weaver installed keyloggers on 19 school computers, managed to steal credentials for a whopping 745 students, and cast ballots from the accounts of 630 of them.

When campus police tracked him down, Weaver was sitting at a school computer with the keyloggers.

Weaver, now 22, was a third-year business student when he cooked up the scheme to rig the March 2012 election. He started months in advance, with police finding a PowerPoint presentation he'd created earlier in the year.

The presentation proposed running for president along with four of his frat brothers, who would run as vice presidents.

Weaver's presentation noted that his intended position came with a $8,000 stipend, while the vice presidents each stood to get a $7,000 stipend, for a total of $36,000.

Police also found traces of Weaver's research into the matter, including computer searches on such phrases as "how to rig an election" and "jail time for keylogger".

Then, a month prior to the election, Weaver bought three keyloggers, in the form of small electronic devices, to surreptitiously record keystrokes.

Keyboard. Image courtesy of ShutterstockBecause landing in jail for a brief stint obviously wasn't enough to convince him that wire fraud isn't a wise course, he and a friend cooked up a business plan of action that was even worse: to attempt to deflect the blame, they created fake Facebook pages using names of real students, posted fake conversations, and tried to make it look like the students had framed him.

Those manufactured conversations were sent to reporters at a few media outlets, but none fell for it, the U-T San Diego reports.

Weaver pleaded guilty to three federal charges, including wire fraud and unauthorized access to a computer.

As the judge pointed out to the U-T San Diego, Weaver jumped from the frying pan into the fire - or, in the judge's own words, he was "on fire" for the crime, and then he went and poured gasoline on it to try to cover it up.

Don't try this at home, kids. Don't play with matches, and don't mess with keyloggers.

Follow @LisaVaas

Follow @NakedSecurity

Image of Vote For Me and keyboard courtesy of Shutterstock.


View the original article here

Friday, March 8, 2013

Computer science student first praised, then expelled for poking around

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Computer science student first praised, then expelled for poking around. Image from ShutterstockA computer science student has been expelled from Montreal's Dawson College for poking at what he calls "sloppy coding" in the college's software - sloppiness that compromised the security of more than 250,000 students' personal data.

According to the National Post, the student, 20-year-old Ahmed Al-Khabaz, had been working on a mobile app that would have allowed students easier access to their college accounts.

Al-Khabaz and a colleague - Ovidiu Mija - discovered the flaw in the college's Omnivox Portal software.

Omnivox Portal, made by Skytech Communications, is advertised as a hub for all internal communications at educational institutions.

Al-Khabaz, a member of the school's software development club, told the National Post that a security hole in the portal software allowed "anyone with a basic knowledge of computers" to gain access to all information a college has on a student, including social insurance number, home address, phone number, and class schedule.

Al-Khabaz said he felt morally obligated to report the problem, not knowing that his actions would be negatively construed:

"I saw a flaw which left the personal information of thousands of students, including myself, vulnerable... I felt I had a moral duty to bring it to the attention of the college and help to fix it, which I did. I could have easily hidden my identity behind a proxy. I chose not to because I didn’t think I was doing anything wrong."

In fact, Dawson College initially gave the pair a pat on the back for their initial code-poking.

Dawson College Director of Information Services and Technology François Paradis met with the two on October 24th, congratulating them for their work and promising that he and Skytech would fix the problem immediately.

Two days later, Al-Khabaz decided to check whether the software had in fact been fixed.

He used a web vulnerability scanner called Acunetix. Within minutes, he told the National Post, Skytech President Edouard Taza rang him up and accused him of launching a cyber attack:

"He said that this was the second time they had seen me in their logs, and what I was doing was a cyber attack. I apologized, repeatedly, and explained that I was one of the people who discovered the vulnerability earlier that week and was just testing to make sure it was fixed. He told me that I could go to jail for six to twelve months for what I had just done and if I didn't agree to meet with him and sign a non-disclosure agreement he was going to call the RCMP and have me arrested. So I signed the agreement."

Taza, while acknowledging that he mentioned police and legal consequences, denied making threats:

"All software companies, even Google or Microsoft, have bugs in their software... These two students discovered a very clever security flaw, which could be exploited. We acted immediately to fix the problem, and were able to do so before anyone could use it to access private information."

But while the initial flaw report was welcome, Taza said, subsequently using the vulnerability scanner was a no-no:

"This type of software should never be used without prior permission of the system administrator, because it can cause a system to crash. [Al-Khabaz] should have known better than to use it without permission, but it is very clear to me that there was no malicious intent. He simply made a mistake."

The college deemed it far more serious than just an honest mistake. The college's professors voted, 14 to one, to expel Al-Khabaz for what they called a "serious professional conduct issue."

Al-Khabaz deems his academic career "completely ruined."

He said:

"I was acing all of my classes, but now I have zeros across the board. I can’t get into any other college because of these grades, and my permanent record shows that I was expelled for unprofessional conduct. I really want this degree, and now I won’t be able to get it. My academic career is completely ruined. In the wrong hands, this breach could have caused a disaster. Students could have been stalked, had their identities stolen, their lockers opened and who knows what else. I found a serious problem, and tried to help fix it. For that I was expelled."

Was Al-Khabaz in the wrong to have scanned for vulnerabilities? Even if he did it without malice?

White cowboy hat. Image from ShutterstockUnfortunately, the answer is yes. Automated tools can crash systems or worse, as security researcher Jeremiah Grossman notes in this article on how vulnerability scanners can harm sites.

White-hat hacking requires authorization - otherwise, it's illegal.

Was the college overzealous in the punishment?

It depends. How well did their instructors get across the lesson that using such tools can do harm and is illegal unless authorized? Do they include it in their coursework?

If not, then college administrators should take their share of blame in this incident and include such material in the curriculum, post haste.

If tutelage in the proper use of vulnerability scanners has in fact been included in the curriculum, then Al-Khabaz's conduct was unprofessional.

Whether it was unprofessional to the point of expulsion and career-ruining, well, geez, I don't know about that.

Administrators could have, at least, allowed the student to air his side of the story - which, apparently, they did not, denying his appeal.

Commenters on coverage of the story have expressed a desire to hire the young man. Hopefully, this won't be a career-stopper for him.

Hopefully, his tale will bring attention to the nuances of using these automated tools.

Like Uncle Ben said to Peter Parker, with great power comes great responsibility. Let's hope educational venues aren't shirking their duty to teach students what that responsibility looks like.

Follow @LisaVaas
Follow @NakedSecurity

Rusty lock
and white cowboy hat images from Shutterstock.


View the original article here

Monday, February 25, 2013

Texas student appeals court order to wear "Mark of the Beast" RFID tracking badge

Over 170,000 people are part of the Sophos community on Facebook. Why not join us on Facebook to find out about the latest security threats.

Hi fellow Twitter user! Follow our team of security experts on Twitter for the latest news about internet security threats.

Already using Google+? Find us on Google+ for the latest security news.

Student badgesA Texas high school student in the US on Tuesday was ordered to wear an RFID tracking badge that she claims bears the "mark of the beast", but by Friday she had turned the case right back around, asking a federal appeals court to overturn the order to either wear a chip-less badge or change schools.

On Tuesday, a lower federal court had concluded that 15-year-old sophomore Andrea Hernandez's right of religion had not been breached by the mandated tag.

A Texas federal judge found that the school's offer to accommodate her by requiring her to wear a neutered ID badge - one stripped of RFID chip - was ample accommodation for her religious objections.

The judge said on Tuesday that Hernandez had two choices: if she wanted to stay at the John Jay High School, she'd be required to wear the badge.

Otherwise, she could pick up and transfer to a new school by January 18, the end of the semester.

In the appeal [PDF] filed on Friday, Hernandez's attorney said that Andrea objects to participating in the school district's so-called "Student Locator Project" on the basis of the Book of Revelation.

The Book of Revelation states that an individual's acceptance of a certain code identified with his or her person as a sign of submission to government authority is a form of idolatry, or submission to a false god.

The school offered to let her wear a de-chipped badge and thereby keep up the pretense of participating in the project, but that's a moot point, given that the badge itself would then be a "mark of the beast" and a tacit sign of her participation in the program, wrote her lawyer:

"By express support for the Project through wearing its visible symbol on her person, Andrea would be expressing support for a program to which she adamantly objects on the basis of her sincere religious beliefs. This, in her view, would be dishonest."

"To Andrea, this 'accommodation' is similar to allowing a religious adherent who must eat a pork-free diet to have his pork-free diet, but to require him to wear a shirt advocating pork."

A one-year pilot test of the tracking IDs was rolled out in October for two purposes: to keep tabs on students' whereabouts at all times, and to make money.

RFID, courtesy of ShutterstockThe new system costs about $500,000, but school administrators have said that they're hoping to increase attendance by tracking the students, which could help them to score up to $1.7 million from the state government.

The school district's budget, like most state-financed schools, is tied to average daily attendance.

Hernandez refused to go along with the program, showing up at the school with her father to protest in the fall.

The school tried to suspend her, but the Rutherford Institute, which advocates for civil liberties, filed a petition on Hernandez's behalf.

In November, a district court judge blocked her suspension.

As Wired has noted in its coverage of Andrea Hernandez's battle, there are multiple chipping programs now in use or proposed in schools throughout the US:

A federally funded preschool in Richmond, California, began embedding RFID chips in students' clothing in 2010.An elementary school outside of Sacramento, California, scrubbed a plan in 2005 amid a parental uproar.A Houston, Texas, school district began using the chips to monitor students on 13 campuses in 2004 for the same reasons the school district in Hernandez's case - the Northside Independent School District - implemented the program.

The first impulse of many who disagree with mandated tracking is to suggest that the badges be spun in a microwave for a bit.

That sounds gratifying, but as I've said in the past, I agree with Andrea Hernandez, her father and her legal advisors, who wouldn't be satisfied with merely nuking the tags and the chips.

Rather, they're fighting the mindset that everyone must be monitored and controlled.

Follow @LisaVaas
Follow @NakedSecurity

RFID image, courtesy of Shutterstock

Tags: Andrea Hernandez, appeal, court order, ID cards, John Jay High School, RFID, RFID chip, Rutherford Institute, school, tagging, Texas


View the original article here