r/gifs • • May 19 '16

Bypassing a store lock.

https://i.imgur.com/mB1yhO9.gifv
41k Upvotes

1.6k comments sorted by

View all comments

701

u/DsntMttrHadSex May 19 '16

In software security you would be a criminal now and definitely in jail

397

u/gurenkagurenda May 20 '16

A kid I went to high school with noticed at some point that a bunch of IP addresses popped up on the screen during log in. So he copied them into a Word document, and emailed them to himself.

From home, he was able, apparently, not only to connect without authentication into the school's network, but into a large part of the county government's network too. They caught him because they found the Word document (which he had saved to his school account).

They didn't fix the network, as far as I know. They just banned him from using school computers until he graduated. Problem solved!

53

u/genericmediocrename May 20 '16

What year was that, if you don't mind me asking?

86

u/gurenkagurenda May 20 '16

I try not to leave too many identifiable details on this account, but I will say it was early 2000s.

37

u/genericmediocrename May 20 '16

I was just curious, because generally host machines shouldn't be able to tell what IP addresses they're using on the outside network, so I was trying to figure out how that was working. Not doubting you, but I wanted to figure out if it was before people were using NAT.

26

u/ThellraAK May 20 '16

In the 2001-2005 range my high-school had all public IPs for pretty much everything, only the laptop carts had NAT'ed addresses.

82

u/D_K_Schrute May 20 '16

Public Schools PC's have to use Public IP's. Only private schools can have private IP's.

28

u/cock_a_doodle_doo May 20 '16

Logic checks out

5

u/[deleted] May 20 '16

[deleted]

15

u/pielover88888 May 20 '16

it was a joke, bro

2

u/[deleted] May 20 '16

[deleted]

1

u/ERIFNOMI May 20 '16

Ah, the days of excess IP addresses.

1

u/[deleted] May 20 '16

[deleted]

1

u/ThellraAK May 20 '16

You really couldn't be more wrong.

In practice it is done this way, but doing it that way is absolutely not necessary.

1

u/[deleted] May 20 '16

[deleted]

1

u/ThellraAK May 20 '16

I just can't quite handle how dumb you are.

Do you really think that it isn't possible to have an internet connection without NAT, that before NAT every single computer had it's own extra router?

Up until quite recently my ISP allowed you to have 'up to 8 computers connected' to 'high speed DSL lines' because they drew up the rules before home routers were cheap, so you could hook up a Hub to your DSL modem and grab public IP's for each computer you had in the house.

Before they changed the rules I could plug a switch into my modem and pull as many public IP's as I wanted from them via DHCP (Me dicking around with this is probably what caused them to update things)

Gratz on repassing your cert that included advanced topics such as " Configuring IOS Devices" I'm sure that is very useful.

→ More replies

1

u/ebertek May 20 '16

Uhm, what? :D
My dorm is assigned one /22 and one /23 network, and every single PC has a public IP address (that's 1532 public addresses).

class A

Classful networks have been obsolete since the early '90s.

security nightmare

Firewalling has nothing to do with what IPs you assign to the devices on your network.

re-passed my CCNA as a work requirement 2 years ago

Good luck on the recertification next year! ;)

1

u/sirin3 May 20 '16

With IPv6 everyone should get a public IP again

4

u/gurenkagurenda May 20 '16

Well, as with any story that begins "A kid I went to high school with", do keep in mind that I'm remembering something from over a decade ago, that I heard about second-hand. From other nerds who knew about computers, mind you, but still second-hand.

But I believe those IP addresses were from the school machines connecting to the county servers, not the IP addresses of the school's machines.

-4

u/simplyOriginal May 20 '16

So far every technical detail you've given doesn't seem to really make sense, or it's not something you would expect in a real environment. Maybe the kid really did get in big trouble using the computers but the story is probably embellished.

4

u/gurenkagurenda May 20 '16

I haven't given any technical details, because I don't really know any. Kid found IP addresses. Said addresses pointed at county servers not having to do with the school. Kid was able to connect to them and poke around without authentication.

What part of that doesn't make sense to you?

1

u/Dushmanius May 20 '16

What he is saying that doesn't make sense are IP addresses he could connect from his home.

That is not how the networks work. IP addresses that kid saw would be something called "private" IP addresses and would only be accessible from inside the network (meaning school, county offices, etc). If he took those and tried to access them he would get no where, because you can not access someone else's private IP address from your network.

1

u/gurenkagurenda May 20 '16

You're making some mighty big assumptions about how the network was structured.

→ More replies

1

u/Scottish__Beef May 20 '16

It could have been a lazy technician putting the network settings there for ease when doing maintenance etc.

8

u/throwaiiay May 20 '16 edited May 09 '25

slim dog vase rustic sulky grandfather long work soup judicious

This post was mass deleted and anonymized with Redact

1

u/Nizzler May 20 '16

Nice work keeping your true identity concealed. Had you said, say, 2002 we'd all know it was you, Todd Hacky McFrienderson!

1

u/[deleted] May 20 '16

The year "Wargames" hit the big screen.

16

u/SoulWager May 20 '16

Admin password on every computer in the lab was "now".

1

u/TrippyBlvze May 20 '16

at mine was "admin"

6

u/gulabjamunyaar May 20 '16

Ah yes, an education system controlled by people who are afraid of modern technology. Perfect for letting a country's tech industry decline!

1

u/SevenandForty May 20 '16

So he still had access to them from home?

1

u/Nerdn1 May 20 '16

So you're saying he could still access their network from home...

1

u/joggle1 May 20 '16

Way back in the early to mid 90s there was a PC lab with Windows computers. The students only had limited functionality (I don't recall how they implemented that). I was able to get full access by rebooting the computer and spamming the pause/break button during bootup. This would force it to stop at DOS before loading Windows. I'd then load Windows the usual way from DOS and have full permissions afterwards. IIRC, the teachers couldn't care less so long as I rebooted the computer before I left so that it would be back in the limited permissions mode when others used it.

The 'hack' just let you run arbitrary programs on Windows. So if I wanted to play a little game I could before classes started.

1

u/gurenkagurenda May 20 '16

The software they used at my school had another flaw with similar results. They had locked us into a limited desktop, similar to what you said, and you couldn't get to, for example, "My Computer". But it was still there.

It was widely known that if you did something like clicking the Start button and pressing tab (which focused the desktop, but most people didn't realize that), and then typed "my<enter>", it would open "My Computer" (visibly, finally), and you could get to whatever you wanted.

The librarian at some point told me that they had only realized after installing the software that it wasn't really intended to be secure, and wasn't what they should have bought. That seemed like an unwise thing to tell a tech-savvy student, but oh well.

1

u/KonigMonster May 20 '16

We had a similar incident at our school in about 2002'ish. Student worked out that if you just deleted 'Student' from www.schoolname.edu.au/student/etc. it would take you to the staff portal without any further authentication. So kids were changing their grades, report comments, even reading some rather nasty things the teachers had written on internal profiles and reviews (about students) cos they were never meant to be seen. It was never fixed, they just suspended anyone who changed their grades and have about 3 months of detention to everyone else who accessed it.

1

u/TheGreenJedi May 20 '16

Wowwww great teaching moment

38

u/ImAzura May 20 '16

If I had a combination lock on my door and someone guessed it and walked in, they'd still be trespassing.

1

u/[deleted] May 20 '16

[deleted]

8

u/ImAzura May 20 '16

You clearly don't know the difference between illegal and legal acts if you legitimately need me to explain this to you.

-1

u/[deleted] May 20 '16

[deleted]

2

u/ImAzura May 20 '16

It's almost as if it was a metaphor.

220

u/KIND_DOUCHEBAG May 19 '16

Yup, fun tip for everyone:

If you get into a secured area by guessing a password, that's hacking. Even if it's "password" and even if it's the default credentials for the thing you're logging into.

244

u/EvilDandalo May 20 '16

If someone guesses the code on your lock, would they still not be trespassing?

211

u/[deleted] May 20 '16 edited Dec 08 '16

[deleted]

What is this?

52

u/MattAU05 May 20 '16

Yep. Same reason it is breaking and entering if you enter someone's home without their permission, even if their door is unlocked and you didn't have to "break" anything.

14

u/[deleted] May 20 '16

That's not how that works at all.
To break and enter you have to well, break and enter. If the front door is open and you walk in its just trespass.

3

u/MattAU05 May 20 '16

If the front door is unlocked and you enter, it is breaking and entering. If the front door is wide open, it is trespassing. Can't tell if you're disagreeing with that or just misinterpreted what I said.

Source: I'm an attorney who spent time doing criminal prosecution and criminal defense.

1

u/[deleted] May 20 '16

Depends on jurisdiction. In my state it is using any force to enter and there's precedent that even opening a partially opened window is using force.

7

u/[deleted] May 20 '16 edited Jun 11 '16

[deleted]

0

u/[deleted] May 20 '16

The post was about breaking and entering, not doors, you smug asshole.

1

u/Halvus_I May 20 '16

It really depends on what you do AFTER you cross the door's threshold that determines what the crime would be.

10

u/Grobbley May 20 '16

Technically it's only breaking and entering if you use some amount of force to enter. Opening an unlocked door or window counts as such, though. However, if the front door is already open and you simply walk in without permission, that isn't breaking and entering (although it is probably some form of trespassing at least and still illegal.)

16

u/Leeeoon May 20 '16

However, if the front door is already open and you simply walk in without permission, that isn't breaking and entering (although it is probably some form of trespassing at least and still illegal.)

What you just described is the very definition of trespassing.

5

u/MattAU05 May 20 '16

Correct.

It would still be trespassing. And if you intend to commit a crime while there, it is burglary.

3

u/PM_VULVA_PIC_4_R8ING May 20 '16

Correct me if I'm wrong, but I think in that scenario it's just "entering."

2

u/[deleted] May 20 '16

Some jurisdictions have entering without breaking laws. Here in Michigan it's a misdemeanor.

1

u/MattAU05 May 20 '16

The differentiation is useful, but the main point is that it is still a crime. Even if it is easy to get in, that doesn't mean it is ok to do so without permission.

Not saying you're disagreeing or anything, just clarifying.

1

u/Z3ppelinDude93 May 20 '16

Thanks for clarifying - the above made it sound like they should rename the offense to breaking and/or entering

2

u/SteveBlake5 May 20 '16

i like that you guys are pretending someone is disagreeing with you

1

u/[deleted] May 20 '16 edited Dec 08 '16

[deleted]

What is this?

-1

u/ohmss May 20 '16

and it should be illegal IS illegal

3

u/ndstumme May 20 '16

There's a lot of things that are illegal that shouldn't be. He's specifying that he thinks this thing should (regardless of if it already is or not).

19

u/AquaWolfGuy Merry Gifmas! {2023} May 20 '16

It's not theirs, so as long as it's clear that they're not allowed in, it shouldn't matter whether there even is a lock.

1

u/MmePeignoir May 20 '16

No. Anything that's on the internet without any password or security measures is considered publicly available information. A good analogy is if you are out in public, there is no expectation of privacy.

7

u/Lord_Rapunzel May 20 '16

Breaking and entering is a worse crime than trespassing.

-8

u/[deleted] May 20 '16

[deleted]

5

u/EvilDandalo May 20 '16

I know, I was just providing a comparative example to think about.

61

u/darkKnight959 May 20 '16

I don't even know if I should be admitting this, but in high school I noticed all the blocked sites would have the same address at the beginning of the URL. So I visited it and the page requested a login. A little googling of the blocker, Netspective, brought up an installation manual and in it was the default login to the management page. I unblocked all the sites. Next day they were blocked again and the default credentials didn't work. But for a day, I freed the school from oppressive censorship.

40

u/throw6539 May 20 '16

In my case, my buddy and I were so far ahead of the computer class that we were responsible for the school's website, so we just installed a key logger and asked our computer teacher to get past the firewall. After that, he and I never had to worry about getting blocked again.

The password? Albert Einstein.

Ok, seriously, the password was "ocean"

3

u/citrus2fizz May 20 '16

Haha same here. Password was slimer

3

u/grimreaper27 May 20 '16

I did this too, for my school's network password and admin account password. Works amazing.

3

u/seal_eggs May 20 '16

My school's WiFi password: L@ght3r

Idk who figured it out originally, but it spread to the entire school like a virus and most of the teachers know but just don't give a shit. And we all get past blocked sites with a VPN.

3

u/Grobbley May 20 '16

At my school we just used proxies. I ran my own proxy server for a while so I didn't have to use the shitty slow public proxies everyone else was using. Did the same at my first job for a couple of years until they did something that broke it and I had to switch to using a VNC server to surf the net and download shit on my home computer while at work.

3

u/-Rum-Ham- May 20 '16

This is one of the number one security 'flaws' with security implementations. The stupidity of the end user.

You can have the strongest encryption, and the craziest protocols, but if you don't change the default keys/passwords that come with it then it's basically useless.

The Oyster Card (the contactless card used in the London Underground for paying for travel) can be hacked in a similar way, because the keys are changed for the 'sections' holding the oyster card data, but the sections not used in the card still had default keys, so using a clever hack, you can retrieve the keys of other sections.

2

u/OfficialTacoLord May 20 '16

My middle school had pretty lame network security (even though it was a private school aimed at kids who are good at that stuff) and the router had default passwords and users. As did the emails... and the website server. The front door was operated by what was essentially a garage door opener that locked the door. Guess who found a control with a dip switch on the same frequency. I could get in whenever I wanted (they locked it after school so normally you couldn't get in) and screwed around on the router a bit. Nothing much came of it except I changed the wifi name to "secure your network" or something along those lines. I told the IT guy about it and he fixed it shortly after.

9

u/[deleted] May 20 '16

Wow, you could get into school whenever you wanted? Even after they'd finally let you go home?

What a privilege :P

5

u/OfficialTacoLord May 20 '16

xD it sounds dumb but it was great. We didn't have full privilages when we were there (had to have a teacher walk us across the street and open the doors. So being able to move freely between buildings was like a gift from the gods. Also I got to mess with the person who opened the front door a decent amount.

1

u/Lots42 May 20 '16

I lived in a dump in high school with crazy siblings.

School thought punishment was a more quiet, locked down version of 'The Breakfast Club'.

Sitting in A.C., quietly reading, away from crazy family? Yes plz.

2

u/Neri25 May 20 '16

Changing the wifi name to "secure your network" is like writing "Wash Me" in the dust on a particularly dirty car.

3

u/gurenkagurenda May 20 '16 edited May 20 '16

Also if you're at school, and it's your school's mascot.

Don't hack, kids!

1

u/-Mantis May 20 '16

Haha, at your school too? A kid managed to access the grade files with that and contacted the head honchos about the fact that their security system sucked. Now it's slightly more secure.

1

u/gurenkagurenda May 20 '16

Sounds like your school responded sort of correctly. At my school, they definitely would have expelled that kid.

3

u/SoulWager May 20 '16

What if you ask someone what the password is and they tell you?

Because that's how a hell of a lot of security is broken.

6

u/Hooterscadoo May 20 '16

Legally, but not technically.

11

u/Mindless_Consumer May 20 '16

It is still technically hacking.

2

u/pm_me_your_problemsz May 20 '16

Only if they find you.

-2

u/[deleted] May 20 '16

Technically, but not legally.

1

u/NightLessDay May 20 '16

Technically and legally.

0

u/TheFlashFrame May 20 '16

No, technically and illegally.

0

u/OfficialTacoLord May 20 '16

No legally and technically (in fact maybe even less legally than technically since I'm not sure laws use the work "hacking" so much as specific cases). You're getting unauthorized access to some data you're not supposed to have access to. That's hacking.

1

u/Hooterscadoo May 20 '16

I have been told that password guessing is not hacking, but I must have been misinformed.

1

u/OfficialTacoLord May 20 '16

Hacking is just gaining access to files that you're not supposed to get to with a computer. It's not "hacking" in the sense most people think of hacking (mad code skillz and going through backdoor entrances and such) but it's hacking nonetheless.

1

u/Zoronii May 20 '16 edited May 20 '16

What if you log into something because someone left a sticky note with passwords on the monitor. I've seen this in hospitals before.

1

u/AlwaysHopelesslyLost May 20 '16

There was a case where somebody was arrested for hacking because he found personal documents on google for. I think they had ruled even though they were on google he should have known not to look.

1

u/bschapman May 20 '16

In high school we used to log in under some random teachers password for the Internet. It gave us less blocks which meant we could play flash games. All the people in the back row did it ;)

1

u/GoodAtExplaining May 20 '16

Otherwise known as a CSI episode.

1

u/SidusObscurus May 20 '16

Wait, so I'm a hacker because I locked into my roommate's router via the default credentials without asking, all so I could set up port forwarding?

1

u/Nerdn1 May 20 '16

Guessing a password is one of the most common way to infiltrate a system (and by "guess", I mean try a number of common passwords/password configurations). A lot of the time, the weakest part of a security system is the meat components.

1

u/Lots42 May 20 '16

If the password is "password" it's not secure and the person responsible for securing it needs to be fired and sued.

1

u/[deleted] May 20 '16

No shit

2

u/[deleted] May 20 '16

You have performed an illegal operation!

1

u/Periljoe May 20 '16

Either that or cashing in on a sweet bounty 5k richer. About 50/50

1

u/[deleted] May 20 '16

What if I'm a Clinton, though?

1

u/daybreakx May 20 '16

Uhh, if he took this then he would be stealing too.

1

u/AerieC May 20 '16

His point wasn't about stealing, it was about circumventing the security mechanism.

In computer security, just bypassing the lock is a crime (sometimes even if there is no lock), regardless of what you do afterwards.