school admin.
At our school it would be quite hard to gain admin rights, I have our network locked pretty tight :D
The easiest way to gain admin permisions would be through user error! e.g. watching one of my colleugues or myself typing usernames and passwords, finding sensitive documents left laying around (with accounts and passwords on it) etc. So I try very hard not to leave sensitive info laying around, and rarely log in in front of students, however some schools I have been to are very careless with this type of information.
I would love to change the world, but they won’t give me the source code.
CygnusH33L: Real level 3 is based on a schools system, and as you say it is generally down to user error not the technology
Yes the only system we have that has a login page (like Real 3) is our proxy, everything else is controlled through a management console that is installed onto certain PC’s, even if students gain access to these PC’s they would not be able to open the management console without our usernames and passwords (these are store in the AD) :D
I still believe the easiest way of hacking most things is user error or lazyness by admin staff.
I would love to change the world, but they won’t give me the source code.
when the time has come , I shall rise and conquer the world
Well in my school it’s enough to boot with ubuntu from USB and remove the Security Programs from AutoRun. It would even be enough if you just rename the folder of it.. Or you could rename cmd.exe to utilman.exe so that you can have system rights in cmd at the login screen. (only if the school-pc is running Win7)
haha thats cunning ColdIV. I will be disabling boot from USB and CD on our comps tomorrow now. Students wouldn’t be able to do this on ours anyway as exe, bat, jar etc are all disabled to run by default and only the files specified in the GPO are allowed to be run like iexplore.exe, chrome.exe, explorer.exe etc and any other programs we install. Come to think of it though, you would be able to replace one of these files with a portable program and rename the exe to one that is allowed to gain rights over that program only - unless its a program designed to give you rights over other areas.
Will be testing this out tomorrow, then applying the fixes, so for that thanks :D
I would love to change the world, but they won’t give me the source code.
when the time has come , I shall rise and conquer the world
EEEEE EEEEE EEEEE EEEEE EEEEE EEE
E E E E E EEE
EEE EEE EEE EEE EEE EE
E E E E E
EEEEE EEEEE EEEEE EEEEE EEEEE @
My school uses JavaScript and MD5 hashes to varify admin login. Perhaps someone could help?
[removed]
Message me if you think it is hackable? Thanks :)
Admin: What do you think we are, a hacking service? Well think again! No hacking requests, please!
~ White Shadow ~
wow @WhiteShadow410 ur admins are really cool :)
EEEEE EEEEE EEEEE EEEEE EEEEE EEE
E E E E E EEE
EEE EEE EEE EEE EEE EE
E E E E E
EEEEE EEEEE EEEEE EEEEE EEEEE @
Teach me.
I am new to hacking but I find it interesting and would like to learn more. Anyone willing to teach me? I would be very grateful
When in doubt, don’t doubt yourself.
this is a really interesting topic, perhaps my favorite. also this gives me alot of good ideas, i am actually part of a computer “safety” group at my school and i have the admin users and passwords. so i don’t really have to use a keystroke tracker or anything like that but it is always a good idea to think about those things.
i was doing a few experiments and i noticed that if i use my friends iphone4 and i scan for bluetooth things to connect to it picks up our teachers Smart Board. would i be able to connect to it and mess with it while she is teaching a class? and if i could what would i be able to do?
As I walk through the valley of the shadow of death, I will fear no evil, for I am the Evilest mother fucker in the God damn valley.
There is a hundred ways to hack the school system… I’m an admin in a school myself… First try to gain a small access and then try to become domain admin… You could use UBCD to get local admin account… then use your imagination…
You could connect to the printers network and do some dammage with snmp. You will also see that LDAP give lots of information… You can use software like Hydra to crack passwords… Nirsoft also give great tool to “recover” your password. And as web services become more popular, more security hole can be exploited.
Of course… don’t forget that we are watching you… If you are young or let’s say without experience, you have no idea what an admin can do…
Try not to break anything and study instead of trying to change you grade!
Peace
DaGr8
Just because I am paranoid doesnt mean theyre not after me…
Easily… just erase SAM file on windows… you will need more imagination for the network account… but it’s not that difficult… Just tell the IT Staff something is broke on your computer…
Just because I am paranoid doesnt mean theyre not after me…
lol… My school really sucks, we have a computer lab that is used only for Science. We never even learn anything about computers at my school… and it wants to have a programming club roflol
I have no idea what you guys are talking about except illegally hacking into a school admin’s account, which I never said to use tor or vpn when you do it so you can’t be traced, like I never said any thing like that.
“When you die I will laminate you’re skeleton and pose you in the lobby.”
Veni Vidi Vici
I think the teachers are exceeded. I could have teach the guys who gave me my first lesson about computers… But not a lot of kids seems to be interested in computer science these days… So maybe the programming club is not a bad idea ;)
Just because I am paranoid doesnt mean theyre not after me…
“When you die I will laminate you’re skeleton and pose you in the lobby.”
Veni Vidi Vici
“When you die I will laminate you’re skeleton and pose you in the lobby.”
Veni Vidi Vici
cpn1000 Lol. I am not that good at english and I ALMOST miss your irony. :) But by the way… since it’s easy to get “physical” access to the computers… this is why it’s so easy to hack it… (there is a password in the BIOS?!? Try that jumper! There is a lock? DAMNiT!)
Admin should be concerned about both internal and external threat… By the way… CyberGhost VPN is really cool… Last time I tried TOR it was so slow…
Just because I am paranoid doesnt mean theyre not after me…
cpn1000 : I can’t teach you how to hack since I’m here for the same reason as you… I’ve read this text a long time ago and found it really inspiring : http://www.catb.org/esr/faqs/hacker-howto.html
I don’t share all his opinions but no doubt he knows what he is talking about. If you want to become 1337… You must love to read, write code and you must never stop learning. Personnaly, I decided a long time ago that I would touch every aspect of computers and become great at each one… one at a time…
Now, if you wan’t to become rich… Don’t choose my path! haha!
DaGr8
Just because I am paranoid doesnt mean theyre not after me…
If the admin hasn’t disabled the CD/USB boot in BIOS and password protected it and locked the case ;) you could boot to linux, copy cmd.exe over sethc.exe in the windows\system32 directory, get to the login screen and hit shift 5 times to give you a command prompt with full privledges. The rest is your doing.
Hacking is alot like modding: Entity