Hacker Read top | best | new | newcomments | leaders | about | bookmarklet login

I'm a UMD student, and I had no idea this existed!

I've been hesitant about reporting holes/vulnerabilities in the school's infrastructure until now, but it's reassuring to see that there are official channels for doing so.



sort by: page size:

Most people will probably be hesitant to post it for obvious reasons here. But it was helpful to me, to find a ransomware url, during the college leak a few weeks ago (https://dorper.me/articles/unileak.aspx) to find out which colleges were impacted because tons of people I know were in it. There are plenty of good reasons to want to have it. But I understand why BBC wouldn't post it...

What surprised me the most is that the public directory of all students and staff really is completely public. Anyone on the internet can use it to get names and emails of students.

University of Toronto has a huge network of these, however after a series of tunnel exploration exploits they pretty much created a gated access system.

http://www.infiltration.org/journal-utmain.html


I always enjoy seeing the university I went to pop up on hackernews

I've been too immersed in university happenings recently. It took me clicking on the link and reading until "password reset feature" to realize that this wasn't some bizarre phishing attack involving Masters of Fine Arts degrees.

Typically those .edu sites have been hacked at some point.

Could be that they have it internally. That was the case for my university.

But I agree, very useful for press/users/internal.


[campusdata.org member here] - if you're working on something similar at your school and want to join forces, join the mailing list is at campusdata.org.


My university uses a Facebook Page for this.

The site academia.edu seems to be a big part.

It baffles me how widespread this is.


My experience at the U of MD (probably dated, but man your summary sounds familiar...): http://www.dadhacker.com/blog/?p=755

Interestingly enough this site is blocked on the university I am at network "Threat detected: Integration." No idea why.

Harvard had a similar bug - you could modify the url to find out if you had entry. They found out and revoked admission from all students who used the url on ethics violations.

One of them looks like a database from the student association. Most of their stuff is built by $9/hr work study so no big surprise it's insecure.

I randomly selected .edu websites from all over the web, including edu.az, edu.com.tr etc. 62 of 100 had those hacklinks.

I hope you would consider expanding this to cover all student organizations - it's not just hack clubs that hold events or seek donations.

God I hated this when I was at Tufts. But its far from the only university system to do this. I suspect a middleware vendor somewhere.

#nmu on csc.nmu.edu My CS department runs an unofficial server that we all SSH into and screen through IRSSI. We get a lot done that way. Makes planning our ACM/LUG meetings easier too since you can scrollback and see the previous discussions.
next

Legal | privacy