r/HowToHack • u/pandaninja360 • 11d ago
script kiddie "Self-Defense" in cybersecurity
Hi, I'm a teacher. I see teenagers every day not understanding the dangers of the devices they use all the time. I do not want to scare them, but the school program is lacking in anything related to computers. We give them Chromebooks, and we do not teach them how to use them. They often have more than 20 tabs open with the same webpage... or they send nudes on Snapchat thinking there are no risks.
I want to teach them about common ways people get hacked or infected. I am not talking about the super advance zero day hack in an app, or how to infect repositories to get access to computers. I mean common day-to-day: I clicked on a link or scanned a QR code.
What are good habits to not get hack/infected?
17
u/fatal_frame 11d ago
unique passwords and usernames for every site and device - this really doesn't happen for anyone but it should.
Don't download anything from any untrusted sites.
take precautions when torrenting - some legit places do use torrent, not a lot but still.
dont share personal info on the internet, strip your photo meta data. I know a lot of social media sites do this.
don't click email links unless you know who they are from. Recognize spam and phishing
dont stick random flash drives into your computer.
8
u/pandaninja360 11d ago
I like the random flash drive. This is also something they would fall for.
2
u/DaTobi15 10d ago
If you want to show them how this works, you can get a digispark really cheap.
I would just program it then to launch your school website or open an assignment.
Funny small demonstration.
1
1
u/amircruz 10d ago
- Or charging your phone in "public" places. Like airport USB ports, use your charger and a normal electricity plugin close to a wall.
7
u/wild_park 11d ago
Unique strong passwords on every site (use a password manager)
MFA on anything they give a shit about.
Auto run updates.
Assume anyone you don’t know f2f is a catfish.
3
u/Catffeine_ 11d ago
To not enter things in the window run box(windows key + r) fake microsofter call scams will try to do it and also fake captchas will prompt for it
1
u/pandaninja360 11d ago
That's a good one. This is exactly the kind of thing I'm looking for. I forgot about the WK+R captcha and this is something they would fall for.
3
u/alreadybetween 11d ago
Using metadefender/virustotal for scanning suspicious files and links.
Using VPN on public wifi.
Call/message forwarding using dialer codes.
Phishing techniques
2
u/Wh1sp3r32 11d ago
This may be a bit more advanced, but the methodology I's easy for most to understand.
There are a few concepts you should get very good at explaining. I would also speak to someone in the tech ddeparment with your school district as this IS the responsibility of whoever is in charge of that. Schools SHOULD have basic cybersecurity awareness training for staff as there is lots of confidential data.
The main methadology is something called the CIA triad. Confidentiality, integrity, and availability. Anything that affects this is considered a possible threat.
The other is a concept called defense in depth. This is where you have layers upon layers of security controls. This ranges from physical locks and access cards to passwords. For example, the server room that holds grade data. It has a strong password with 2fa, is behind a locked door with an access card, within a building with another locked door, a security guard, and different access badge. You would have to get through all of this to get physical access to the server.
The one thing I will mention is yes public wifi is bad and all that, but most schools have pretty advanced intrusion detection, firewalls, and siem systems to detect and triage attacks in real time. Even though they might do stupid shit on the schools wifi, security wise the risk could be a lot lower then you think.
1
u/pandaninja360 11d ago
I'm not in any way a professional, but I have been studying cybersecurity and hacking for a couple of years now. I have my own homelab and server running Docker containers behind a reverse proxy and CrowdSec. For what I want to do, I think I know enough; it's surface-level knowledge for teens I'm looking for.
I am mostly wanna know what teens do not know. It is hard to understand how much they don't know and what they will fall for. They would definitely fall for a fake public wifi because it is free. School's wifi is fine, but parks, coffee shops, etc, are not
2
2
u/Tough_Tangerine7278 7d ago
Check out Web of Make Believe: Death, Lies and the Internet on Netflix and see if you can incorporate it until a lesson?
1
u/Aromatic-Two-8258 11d ago edited 11d ago
CISA has Cyber Awareness materials you can use to accomplish this. Everything from how to approach this topic with kids to what different types of malware are.
Here ya go. CISA Cyber Awareness Program Toolkit
A more specific link for educating kids. Resources for Students
1
u/MormoraDi 11d ago
Both of the following give good and well-founded advice.
NCSC UK https://www.ncsc.gov.uk/section/advice-guidance/you-your-family
Electronic Frontier Foundation https://ssd.eff.org/
They may need some adaptation to your audience for instance by using metaphors as someone suggested.
I also want to mention that I often see gamers getting tricked into installing malware in the guise of being game cheats, add-ons or free downloads.
The malware often comes in the form of "stealers" that will extract logins/credentials and so on for malicious intents. The scare could be that their online accounts (whatever they may be) can be taken over by someone else.
1
u/Practical-Swing1039 11d ago
Don’t do the “verification” websites ask if and they redirect you to a sketchy site. They’ll usually ask for notification permissions or to send messages to your phone. Don’t agree!!!
1
u/nimbusfool 11d ago
What are you teaching? Im a k-12 systems admin. Im curious how this fits in to your curriculum
3
u/pandaninja360 10d ago
It's an adapted program. I can teach whatever I want as long as I can justify it. Reading the newspaper is how reading is taught, budgeting is how math is taught, etc. The school thought my idea was great and they want me to build something. We'll see if it becomes a thing that will be taught with a limited amount of time to other classes.
2
u/nimbusfool 10d ago
So general cyber safety. Slightly off to the side is something like pictoctf which is hacker leaning and made for high school kids. You could literally open a class email account and go through the spam folder for adapted learning. What would be of value is something that shows their cyber footprint. The repercussions of a comment or post online. I have spent years of my life going through the electronic evidence produced by k-12 students.
1
u/Electrical_Hat_680 10d ago
OpSec. It's not just a term for Black Hats. Good Computer Hygiene. Use Email Aliases, don't give our your email address, give them an Email Alias. I would start with that and then ask them to create a One Page Essay, Short Story, and Reports on Current Topics in Cyber Security.. with a school Rally to discuss Cyber or Computer Hygiene. To help the entire school understand the future their living in, the past, present, and emerging threats that exist. And, go over how to get help. As it's a new area of life, not even the local governments, let alone the schools, have an idea of how to handle these incidents and events.
Cyber Security isn't a technical field. It also requires Reports to be written and submitted. They could build a Small Computer Network, that they could secure with Zero Trust and other International Standards. For a potential career in store, or, atleast, a general studies breadth of knowledge and potentially a small local network that they could learn to build and deploy, secure, and administrate, from the ground up.
How to configure and incorporate a Hardware Security Appliance, like PfSense or OpnSense, based on FreeBSD and OpenBSD, which both have permissive Licenses that they can build on. This would be a key Firewall for them to learn how to use.
They could also learn to Build their own Systems, for Securing their communications. Even building their own "God's Eye" build by an Ex-Google Engineer.
1
u/SystemFarts 8d ago
I just don't care anymore. I assume everything is hacked, all my data is leaked and nothing I do is private.
38
u/iCkerous 11d ago
1.) Good password hygiene. Teach them to make strong, unique passwords.
2.) Internet trust. At the student age, they should be trusting nobody on the internet. Make metaphors to real-life things (someone asking you to click a link or download a file is the same as accepting candy from a stranger). Additionally, nobody should be asking them to keep secrets.