Login Register


Highschool student hacks 150k IoT printers filter_list
Author
Message
RE: Highschool student hacks 150k IoT printers #11
I'm glad there are people like this. I mean he could seriously fuck up a lot of the companies their financials by printing random tickets or something but he didn't. He litterally warned all of them, I wouldn't know why this would fuck up his career, it should give it a boost.
~~ Might be back? ~~

Reply

RE: Highschool student hacks 150k IoT printers #12
(02-14-2017, 11:12 AM)Bish0pQ Wrote: I'm glad there are people like this. I mean he could seriously fuck up a lot of the companies their financials by printing random tickets or something but he didn't. He litterally warned all of them, I wouldn't know why this would fuck up his career, it should give it a boost.

You're spot on here.

The sad thing Is, rather than seeing this as a good thing (bringing the security Issue to the attention of others), people see It as an act of malicious Intent- mainly due to the fact that he "hacked" the printers. The term "hacker" Is perceived (by a lot) as someone who gains access for personal/financial gain and acts of unlawful conduct. Would they rather he disclose all personal credentials? Evidently not, but they don't see It from that perspective.
[Image: AD83g1A.png]

Reply

RE: Highschool student hacks 150k IoT printers #13
(02-14-2017, 11:31 AM)mothered Wrote:
(02-14-2017, 11:12 AM)Bish0pQ Wrote: I'm glad there are people like this. I mean he could seriously fuck up a lot of the companies their financials by printing random tickets or something but he didn't. He litterally warned all of them, I wouldn't know why this would fuck up his career, it should give it a boost.

You're spot on here.

The sad thing Is, rather than seeing this as a good thing (bringing the security Issue to the attention of others), people see It as an act of malicious Intent- mainly due to the fact that he "hacked" the printers. The term "hacker" Is perceived (by a lot) as someone who gains access for personal/financial gain and acts of unlawful conduct. Would they rather he disclose all personal credentials? Evidently not, but they don't see It from that perspective.

I know mate, and I couldn't agree more. I once saw a SQLi vulnerability in a pretty big site (it was a site containing all details of all youth clubs in belgium, like scouts and that sort of things.)

I had tons of plaintext login details, when I warned them they threatened me that they would sue me or take legal action against me. I was so confused, I mean I understand they saw me as a "Hacker" but people who aren't into IT don't know that there are different types of hackers. I was mad because they didn't do anything and still didn't fix the issue untill now. They didn't even change passwords, I mean sites like that deserve to be hacked or defaced.

The way I see it they just put over 30k accounts public to everyone. There might be a hacker that wouldn't be as friendly as I am and use all their accounts. Without hackers IT wouldn't be as far today as it would be. There aren't enough hackers to cover all devices made nowadays. Think about it, smart watches, smartphones, microwaves, tv's, internet, home pc's, laptop's, hell even the central heating can be hacked. They need people like us, they just don't realize it.


Sorry @OP for offthread posting.
~~ Might be back? ~~

Reply

RE: Highschool student hacks 150k IoT printers #14
Wow, this is insane, you gotta start somewhere right???? LOL This kid is very brave!
[Image: ezgif_com_gif_maker.gif]
#yellowheartsforsarah

Reply

RE: Highschool student hacks 150k IoT printers #15
(02-14-2017, 11:05 AM)mothered Wrote:
(02-13-2017, 06:47 AM)Jiggly Wrote:
(02-13-2017, 05:41 AM)mothered Wrote: Absolutely.

A device Is only as secure as the person who operates It. Users need to be cautious with the "Task" they're performing.
T= Training.
A= Awareness.
S= Skill set.
K= Know-how.

And In a corporate environment,  a lot of the above comes from the lack of company policies to educate their employees.

Holy crap, I didn't even realise this was a possibility. It seems obvious now but I'm sure I've made these mistakes somewhere along the line.

Ironically I have to create a policy brief for a class project, it would be amusing to see if I could use this as a suggestion for mine xD

The T.A.S.K (as elaborated above) Is something I formulated, mainly for the purpose of an "easy-to-remember" approach when educating others on cyber security, prevention of social engineering etc.

I didn't plagiarize It from anyone. You can well and truly use It. Simply add your policies and/or recommendations to each category.

T.A.S.K is pretty well thought of. I'll be keeping it in mind for the future.
[Image: 4GNsK67.png]

[+] 1 user Likes Jiggly's post
Reply

RE: Highschool student hacks 150k IoT printers #16
(02-22-2017, 07:52 AM)Jiggly Wrote: T.A.S.K is pretty well thought of. I'll be keeping it in mind for the future.

The ambiguity behind It's name and abbreviation (as stated above), makes It easy to remember.

I've applied this many times during my security recommendations, and It seems to work quite well.
[Image: AD83g1A.png]

Reply







Users browsing this thread: 1 Guest(s)