Jumat, 22 April 2011

A Shiny Update... (Hacking @ School)

Allright, as some of you might have noticed i am semi-back on Inter|N0T.
I just thought i'd share what i did yesterday after MaXe told me that it could probably be a good share.

Right as i woke up, sleepy as hell - a sideeffect from watching a season of Family Guy & fooling around in Back|Track4 the night before - I remembered what i had forgotten for several days in a row, to bring my promised Back|Track dvd to school, as some idiots accused me of having lost all skill in computers since i started playing games again, and not focusing on the underground.

It basically seemed like the day was getting worse and worse, i remembered that i had forgotten to write my english outline for my exams, which my english teacher demanded to see as she accused me of slacking (with a a reason, apparently), my socks didnt fit, and my laptop was almost without power.

Whilst kinda panic'ing about the fact that i had an english outline to write, i found my charger, plugged it in and let the laptop charge those 20 minutes before the bus arrives, god knows i should have taken my moped instead.

Oh well, on with the story.

I threw my laptop in my backpack, along with my books n' stuff and marched off for my old school where the bus stops.

As i hopped on the bus, this girl who i have to admit is kinda attractive and has been hitting on me sat right next to me, which made it just a bit harder to make that outline.

Let's skip the boring **** for now.

I arrived at school, walked inside - said hi to everyone and sat down, class had begun.
"Late again, huh?"
So i spent the next 10 minutes trying to explain to my damn teacher that the bus was late. She ended up quitting the discussion, as i can be quite impossible to argue with, atleast if you're my teacher :P

As recess came, some idiot took the computer in class, and i had to run to the computer room if i was to make it, or atleast learn a bit about the systems.

My best mate ran over with me, supplying me with an external harddrive and my ol' trusty 8GB usb which he had had with him home.

To start out i booted into windows, to have my logon provide me all the machine info it needed in order to be able to connect the the drive i wanted to crack.

I got the info, Name, IP Adresses, Server names, Subnetmasks, dns servers, p:\ drive info & so on.

I printed the stuff out, and put it on the table next to me, took the power off of the system & rebooted.

As quickly as i could i threw the Back|Track4 disc in there, and the adventure began. I had previously attempted to crack the server with Back|Track, but the systems had not allowed me to access anything without being logged on first, due to some strange read/write flags. I had thought about messing with CMOS, but i wasnt that serious about it. As my mind started to wander, Back|Track had reached the logon phase, typing in root/toor i logged on the system, without any kind of access, i started connecting.

I simply used the default network manager, and suprisingly, by just filling out the stuff i had written down - i was in.

I had exactly the same rights, as the teacher i was immitating, but i wasnt him, only in the eyes of our dear admin.

As i attempted accessing the teachers drive, which was exactly what i was after - i was stopped.

Simply.. Stopped.
An annoying popup told me that i was not connected after all, a conflict of system names, apparently. Something didnt add up, and i didnt quite understand it at first.
What i then figured out was that i should not - i still don't know why - use the default name, but instead replace it with what i wrote down - GRAGRS098, and jackpot!

Firstly i tried simply connecting to the teachers personal drive, which worked.
I then attempted to access the main target, the teachers drive, but what a damn letdown.
Luckily i found something quite interesting on the teachers personal drive.
He had been "foolish" enough to write down the login info that every danish student & teacher in the school from year 1-10 uses to access the systems, i laughed a bit, and threw the file on my USB drive, logged off and went for class once again.

We had english, i had to turn in the crappy 10-minute outline i wrote in the bus.
She looked at it, looked back at me and said "hmm, not your usual level of dedication, but still better than the rest of the class..." - allright i guess... I didnt focus on her words, i was planning the next phase of my plan instead.

As recess came once again, i ran for the computer room, but right before entering the room, i realize that i had forgotten my USB drive in class and turned back - just as i saw my admin walk out of the room, i wonder what he had been doing in there - but i sure as hell wasnt planning on sticking around to find out.

I got back to class and our sub had arrived for biology, they are so easy to fool.
I had my best friends distract him, so i could work without being interrupted. And it worked.

I booted the windows system up again and i tried the login that i had taken from my teachers drive, it didnt work.

So what i did, was take a hint of social engineering and mix it with a bit of thinking.

I walked up the teachers computer which was off, i started asking my teacher a question - something about a website we use in biology, and i pulled the internet plug whilst he focused at my face. I then asked if he would be willing to show me the site again, as i couldnt remember how to log in on it - yeah right, why would i forget that, i love access to stuff.

As he had booted the computer up i was looking at his login information, and as he clicked the enter button, it just hung there, which was just what i wanted, to memorize it.

cars3521fd

Hmm, i knew his name was Carsten, and my login looked like this (with my real name replaced ofcourse)

oooh6703 - which lead me to belive that the four numbers were random, the four letter was the four first of the name, as my best friends login was similar, fx. roro1293 (I had to use something, rorok :P) and that the last two letters was possibly an indicator that the teachers logins had at the back of it. And basically as i thought back, ofcourse that was it - back in the day when i also did alot of **** to the old serversystems at school, my teacher had some letters which indicated that she was a teacher aswell.

so what i did, was do this "teac9999fd" - and ill be darned, it worked!

I was in!
Immediately as i was in, i started plugging in the external hd and copy **** over, for every class, math, biology, english, etc.
The teacher approached, and i went on the internet, pretending to play a game, which he apparently just ignored, atleast he didnt approach me again.

As soon as i had all the files over, i packed my **** and went home, i could and would not risk anything - should my admin have been in there because of me.

I've attended school today aswell, and talked casually with our admin - nothing.

The amount of school data i aquired is scary.
I have 10gigs of correction sheets, assignments, grades, logins etc.

Im just sitting here looking through it now, and i wonder how i pulled that off - i must have been really damn lucky.

Oh well, that was that

Be good,
Shiny.

Tidak ada komentar:

Posting Komentar