Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Application Security //

Database Security

4/24/2013
01:10 PM
Connect Directly
LinkedIn
Google+
Twitter
RSS
E-Mail
50%
50%

Hacking Higher Education

The cybersecurity challenge on college campuses lies as much with the students as with malicious outsiders.

InformationWeek Green -  Mar. 4, 2013 InformationWeek Green
Download the entire May 2013 issue of InformationWeek Education, distributed in an all-digital format (registration required).


Hacking Higher Education When a faculty member at Miami University in Oxford, Ohio, logged in to the university's grade book last fall, she realized something was wrong: The grades in the online system didn't match her paper records. She was alert enough to see this was no mere glitch.

In March, after months of investigation, police charged two students with hacking the system to inflate grades. Police maintain that Beckley Parker, 21, of Weston, Conn., had changed his own grades for 17 classes since the spring of 2011, and also changed grades for 50 other students, according to the Dayton Daily News. David Callahan, 22, of Cambridge, Mass., reportedly changed his own grade once and two other students' grades. Although the facts are subject to interpretation, it seems the two were either trying to help fraternity brothers or other friends at the same time they were improving their own grades, or they may have been trying to cover their tracks by changing more than one grade in each case.

All it took for them to make the changes was an inexpensive keylogger device, inserted between the keyboard and the computer it was attached to, which allowed them to record the actions of teachers entering their passwords for the grading system. They were then able to access the system at will.

After cooperating with investigators, the students avoided being charged with a felony, instead accepting dismissal from the university and pleading guilty to multiple counts of "attempted unauthorized use of property," a misdemeanor.

Miami University's information security officer, Joe Bazeley, says an attack on the university's learning and grading systems is actually worse than the sort of attacks, namely information theft and exposure, that used to keep him up at night before the keylogger incident. "We produce knowledge and identify that via grades and a diploma," Bazeley says. The grade book hack "challenges the integrity of those grades and diplomas," he says.

Learn From The Hacks

Report Cover
Schools Do More With Less

Technology advances are providing new tools for learning. The challenge is how to take advantage of the opportunities when resources are stretched thin. Our report is free with registration.
Get This And All Our Reports

Unfortunately, examples abound in higher education of the other kind of security breach.

An undergraduate at the University of Nebraska last year was able to break into a database associated with the university's PeopleSoft system, exposing Social Security numbers and other sensitive information on about 654,000 students, alumni and employees. According to our sister website Dark Reading, the university was lucky enough to detect the breach and shut it down quickly. An IT staffer picked up on an error message that seemed like evidence of something amiss, and a recently installed security information and event management system helped network managers sort through system logs and collect enough evidence to allow police to get a warrant to confiscate the computer of the student believed to have been behind the attack.

In March, Salem State University in Massachusetts alerted 25,000 current and former students and staff that their Social Security numbers may have been compromised in a database breach. If the pattern of the last few years repeats itself, expect higher education institutions to experience another half dozen major security breaches by the end of 2013.

To read the rest of the article,
download the May 2013 issue of InformationWeek Education.

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Page 1 / 9   >   >>
multan@112
50%
50%
[email protected],
User Rank: Apprentice
12/4/2019 | 4:34:57 AM
The wellness kafe
Lots of awesome resources! Thanks for taking the time to share these. This page will definitely be bookmarked for future reference and I will be sharing with my entrepreneur friends!!
<a href="https://thewellnesskafe.com">The Wellness Kafe</a>
joshgay
50%
50%
joshgay,
User Rank: Apprentice
11/30/2019 | 6:11:55 AM
Re: Agree with your topic
thanks for sharing this info with us I found it so amazingly glad to be here
HolyFrolic
50%
50%
HolyFrolic,
User Rank: Apprentice
10/31/2019 | 2:55:12 PM
Thanks
im just amazed. This is a great blog posting and very useful

 
dmflows
50%
50%
dmflows,
User Rank: Apprentice
10/11/2019 | 6:31:39 AM
onlineshoppingsaless.com
This Was A Very Helpful Post and Unique Information It Contained As Well. Thank you very much for giving this awesome post, it is a great way to fully enjoy it.

 
leo5121472313
50%
50%
leo5121472313,
User Rank: Apprentice
9/26/2019 | 3:06:03 AM
leo

Your blog is filled with unique good articles! I was impressed how well you express your thoughts.

 

hertavein
50%
50%
hertavein,
User Rank: Apprentice
9/24/2019 | 7:24:34 AM
Re: great post
I am truly glad to read this webpage posts which carries lots of useful information, thanks for providing these kinds of statistics. 
TanuSaha
50%
50%
TanuSaha,
User Rank: Apprentice
9/23/2019 | 9:04:58 AM
re: Hacking Higher Education
I am very impressed with your article. I love the way you write this article. Thank you for sharing this wonderful post with us. Also, you can visit here: Techpout

 
krismartin12
50%
50%
krismartin12,
User Rank: Apprentice
8/29/2019 | 2:15:32 AM
Re: Assignment Help Sydney
Bcom is the most opted course for which student have to submit the solved assignment of their respective subjects in the study center. The last date to submit the ignou bcom solved assignment 2018 19 is september 30. We offer bcom and ba solved assignment to all the Ignou students at a very nominal price. 
REISEN1955
100%
0%
REISEN1955,
User Rank: Ninja
8/2/2019 | 1:33:01 PM
re: Hacking Higher Education
Advertisement not really good here and besides the service is a disaster - and I speak as a systems professional who is in Cyber security and has done support for offices, small businesses and home-office users.  I would never go to Geek Squad. 

And all the replies seem to be the same basic idea!!!   Hmmmmmmm
geeksquad9333
0%
100%
geeksquad9333,
User Rank: Guru
8/1/2019 | 10:04:43 AM
re: Hacking Higher Education
Geek Squad Tech Support provides the best technical help and guidance. Get in touch with extensively trained tech support team for all sort of queries and issues regarding your devices. You can contact Geek Squad round the clock according to your convenience.
https://geekstechs.org/geek-squad-tech-support/
Page 1 / 9   >   >>
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: Our Endpoint Protection system is a little outdated... 
Current Issue
The Year in Security: 2019
This Tech Digest provides a wrap up and overview of the year's top cybersecurity news stories. It was a year of new twists on old threats, with fears of another WannaCry-type worm and of a possible botnet army of Wi-Fi routers. But 2019 also underscored the risk of firmware and trusted security tools harboring dangerous holes that cybercriminals and nation-state hackers could readily abuse. Read more.
Flash Poll
Rethinking Enterprise Data Defense
Rethinking Enterprise Data Defense
Frustrated with recurring intrusions and breaches, cybersecurity professionals are questioning some of the industrys conventional wisdom. Heres a look at what theyre thinking about.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-2319
PUBLISHED: 2019-12-12
HLOS could corrupt CPZ page table memory for S1 managed VMs in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wired Infrastructure and Networking in MDM9205, QCS404, QCS605, SDA845, SDM670, SDM710, SDM84...
CVE-2019-2320
PUBLISHED: 2019-12-12
Possible out of bounds write in a MT SMS/SS scenario due to improper validation of array index in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice &amp; Music, Snapdragon Wearables in APQ8009, APQ8017, APQ805...
CVE-2019-2321
PUBLISHED: 2019-12-12
Incorrect length used while validating the qsee log buffer sent from HLOS which could then lead to remap conflict in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdra...
CVE-2019-2337
PUBLISHED: 2019-12-12
While Skipping unknown IES, EMM is reading the buffer even if the no of bytes to read are more than message length which may cause device to shutdown in Snapdragon Auto, Snapdragon Compute, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wearables in APQ8053, APQ809...
CVE-2019-2338
PUBLISHED: 2019-12-12
Crafted image that has a valid signature from a non-QC entity can be loaded which can read/write memory that belongs to the secure world in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon Mobile, Snapdragon Wired Infrastruc...