News: 1682058729

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Thanks for fixing the computer lab. Now tell us why we shouldn’t expel you?

(2023/04/21)


On Call It’s always twelve o’clock somewhere, the saying goes, but Friday comes around but once a week and only this day does The Register offer a fresh instalment of On Call, our reader-contributed tales of tech support torture and turmoil.

This week’s contribution comes from a reader we’ll Regomize as “Hank Senior” because it concerns his son, “Hank Junior”, who he described as “an evil black hat hacker that tried to destroy his college network.”

Junior is and was no such thing. As we start this tale, he was just a kid who, one weekend, wandered into his university’s computer lab to do a spot of work but couldn’t because a domain controller had died, and nobody could log in.

[1]

“Being a helpful kind of guy he is, and a CompSci student, he jumped into troubleshooting mode,” Hank Senior told On Call.

[2]

[3]

Junior quickly found he had no network access, so tried guessing passwords to gain admin privileges.

His second guess, with the combo admin/university_name, did the job.

[4]

Let’s hope this Uni’s admins weren’t teaching CompSci in addition to running the lab!

Once Junior had admin privileges, he put his excellent education to work and logged himself and other sadly stricken students into the system. Assignments were written, work was done, and everyone was happy not to have wasted a weekend trip to the lab.

Hank Junior did worry his actions might be interpreted the wrong way, but also rationalised that such an obvious password meant it was surely intended for wide use.

[5]

But later that evening, Junior worried that his acts of spontaneous self-service sysadminnery might be taken the wrong way.

So he reported himself to the university’s administration.

“They went ballistic, and he was threatened with expulsion,” Hank Senior told On Call.

[6]Automation is great. Until it breaks and nobody gets paid

[7]Techie called out to customer ASAP, then: Do nothing

[8]Uptime guarantees don't apply when you turn a machine off, then on again, to 'fix' it

[9]Errors logged as 'nut loose on the keyboard' were – ahem – not a hardware problem

“Finally, a week or two later, he was hauled in front of some bigwig and told that he would only receive an official reprimand, and that this was his one and only pass.”

“As his father, and a professional programmer myself, I told him that I was proud of him and that this story could be used to garner points in the industry,” Hank Senior told On-Call.

We think that’s a fine analysis – what higher form of kudos is there than being the hero of an On-Call column?

If you fancy scoring that kudos for yourself, share your tales of being asked to address the absurd and emerging with accolades by [10]clicking here to send an email to On Call . ®

Get our [11]Tech Resources



[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZEJev6g8JChjewQ@u6-RBQAAAEE&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZEJev6g8JChjewQ@u6-RBQAAAEE&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZEJev6g8JChjewQ@u6-RBQAAAEE&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZEJev6g8JChjewQ@u6-RBQAAAEE&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZEJev6g8JChjewQ@u6-RBQAAAEE&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[6] https://www.theregister.com/2023/04/14/on_call/

[7] https://www.theregister.com/2023/04/07/on_call/

[8] https://www.theregister.com/2023/03/31/on_call/

[9] https://www.theregister.com/2023/03/24/on_call/

[10] mailto:oncall@theregister.com

[11] https://whitepapers.theregister.com/



Free 24x7 user support?

Anonymous Coward

Our university sysadmin had a deal whereby, if any of us found a security hole, he'd buy us a pint at the bar (as long as we told him exactly what it was, and it was a new one). We managed it several times.

However we generally kept a backdoor to root on the system so that we could fix things outside hours - usually, when some fool had submitted an oversized print job that needed cancelling, but also when we found a black hat from another university logging in overnight to try and kick our players off of Essex MUD.

Re: Free 24x7 user support?

Evil Auditor

...kept a backdoor to root...

Obviously, we had never done such evil thing nor would or could have thought of. Anyhow, the printing, with the printer standing in the vicinity of my desk, of all and even more so of oversized documents (if they were not ours) was a nuisance we could do without. First step was to connect directly to the printer to circumvent the print server's spooler and bypass its long queue - we still had the busy printer but at least without waiting ages for our printouts. Second step was that we cancelled others' jobs as soon as the printer sprang to life and securely disposed of any already printed pages. The fellow student would arrive in our room to get their printout, wondered what happened, and we would obviously answer: nothing, the printer has just been idling all the time. The discouraging effect was less than expected (reminder: do not underestimate the persistence of a student near a submission date) and clever us figured, or it was rather a disgruntled fellow student, that it looked suspicious that the printer worked just fine when no one was working (i.e. playing id Software's finest) there. The final and very effective step was to kick "our" printer out of the print server rendering it invisible to the casual network user.

Re: Free 24x7 user support?

saxicola

For a while at university I used to be able to cancel the print queue for a printer, quickly press print and logout. By the time I'd walked to the printer at the front of the room my printout was ready. Until I couldn't any more. I was rumbled! So it was off to Staples to buy the cheapest printer they had.

To be fair, the amount of garbage the printer was spewing out, and with the "LOAD LETTER" (the printer was loaded with A4 obviously), errors constantly displayed assuaged my guilt a little as I was probably doing the other students a favour by allowing them to review their page settings before then resubmitting the print.

Anonymous Coward

The time the security team locked out the root account on their 'very secure system'.

Not being the sysadmins they thought they were, all sorts of weird and wonderful discussions were being had. Until I pointed out they had a root owned rc script in with full permissions, so let the hacking commence (me, being an actual sysadmin who happened to be there talking to someone else and overheard what was happening).

A grade hacking

trevorde

Many years ago, whilst I was at uni, one of my fellow students was failing badly due to getting involved in guild politics. So the story goes, he managed to hack into the uni's VAX system and amend his grades to a pass. He was found out but allowed to repeat the year on condition he didn't do it again. Next year, he was failing *again*, so he hacked in *again* and was found out *again*. This time they said they would let him through if he showed them how he did it. Eventually, he managed to scrape through his degree by the skin of his teeth.

The irony was that he later went on to found several tech companies and did rather well for himself.

Re: A grade hacking

Simon Harris

Did he also almost bring about the end of civilisation by playing Global Thermonuclear War?

ChoHag

Never, ever own up to fixing anything. You either get a bollocking or you have to do it again next time.

Giles C

At one place I worked I was for a while involved in the backup of the servers and hence knew the combination for the large safe the backups were stored in.

For some reason this safe used to confuse the people whose job inherited the backup process.

Every time someone couldn’t get in the safe they called me as I had the “skill” to get the door open, worst thing is I can still remember the combination even though I left the company back in 2018. If the safe is still at bgl and it can’t be opened I could be prepared to unlock it for a suitably large fee……

How secure *IS* your system

Peter Gathercole

I ran a Level 3 Acorn Econet of BBC micros (with a 10MB hard disk, no less) at a UK Polytechnic back in the early '80s, something that was never really that secure.

I had to frequently remind staff that although it was very convenient, the security was lamentable, and they should not store assessment results or upcoming assignment or exam questions on the file server. In reality there was no way of stopping the students from seeing or amending them, especially when two of the students were very good at understanding how things worked (they both were already, or went on to become well known game writers for the BBC Micro and other systems - shout out to Gary and Peter).

One of them already had experience of hacking a Level 2 fileserver before he even came to the Poly, and in many ways, I was actually following him (often as a result of "I can see what he did, but how did he do it") type situations, even though I had been using BBC micros almost from the first day they were available.

While I loved what Econet provided, it really wasn't fit for purpose as a general computing environment, at least not for completely open and unprotected systems like the BBC micro.

Anonymous Coward

I’m no sysadmin, but I run a Linux box at home. I had a job as a scientist in a small research center owned by a large multinational. Our one and only IT guy was rushed off his feet - so much so that he once left a ‘sudo vi /etc/passwd’ open on my desktop when rushing off to the next emergency. Reader, I created a user with UID 0 before closing it. The following year, he had just gone on a long and well-deserved holiday, somewhere with no phone reception, when the network mounts all disappeared. We were on our own network, and the company did not provide any cover for him - so I did what I had to. When he came back, his first words to me were, “Well done, but just so you know, the system mysteriously healed itself. And do not tell me how it did that until we are safely in the pub.”

b0llchit

As they say, no good deed goes unpunished.

wolfetone

The road to hell is paved with Windows administrator passwords.

Oh....

Anonymous Coward

We went a step beyond that in college (they ran RM networks over NT4 systems) and found the docs for said software.. Which listed all the default accounts and some small print warning about changing the defaults.

So "we" (myself and a few other friends) thought we'd do the responsible thing and double check...

We might have been told off several times as to how a network privilege ban never seemed to last longer than getting to the next break time but it was only on our last day that things were figured out. Probably because we locked the admin out their own account so they finally went looking for other defaults, along with some basic maths of putting 2+2 together....

Sometimes you do what you have to do.

jake

A couple decades ago my daughter got into trouble after getting root on a college Apple "server", so she could change a few settings to make it run more smoothly. After the so-called sysadmin found out and told management, she was going to be banned from the college network for a year ... but the sysadmin stepped up and admitted that her work fixed a couple-three major bottle-necks. She married him 5 years later ...

I came to MIT to get an education for myself and a diploma for my mother.