Hackers get access to N.J. school data system
IDG News Service - Users of the 4chan online message board managed to get access to the online student information system used by a New Jersey school district after the school's administrative password was posted to 4chan last week.
The problem started last Tuesday, according to the Plainfield Board of Education, which serves a small school district just west of Newark. That's when somebody posted a link to the login page and the administrative username ("admin") and password ("poopnugget") of the district's Genesis Student Information System to 4chan, a popular but anarchic message board best known as the place where David Kernell posted details of his break-in of former Alaska Governor Sarah Palin's Yahoo e-mail account.
The Web-based Genesis software is used by about 160 New Jersey schools to manage their student records and communicate with students and parents.
It's not clear how much damage was caused, but 4chan members soon started posting screenshots showing how they were able to mess with the school's system. One screenshot shows school lunch prices reset to $9,000 per meal. Another post claims that "every class is now an elective, and requires only 1 credit to graduate."
In another screenshot, it appears as though the 4chan intruder could have sent a message to students and parents using the school's emergency notification system, designed to send text messages and e-mails to parents in the event of a major disaster.
It's not clear whether the message went out, but if it did, parents in Plainfield would have received a technically accurate but tedious lecture on the difference between the Linux kernel and the GNU/Linux operating system.
The district's interim superintendent, Anna Belin-Pyles, confirmed the breach in a statement posted to the district's website on Saturday. There were "unauthorized breaches of one of the District's computer systems in an attempt to vandalize electronic data and to disrupt school district operations," she said.
Although some residents are worried that student records may have been tampered with, Belin-Pyles said that any damage to the system's data was, at worst, only temporary. "There has been no permanent damage to the electronic files and steps are being taken to remedy the situation and further secure the system," she wrote. The school district didn't return calls seeking comment for this story.
Genesis fixed the problem on Wednesday after discovering the stolen password, the company said. On Friday, Genesis posted a brief note offering customers some basic password protection tips.
A criminal investigation into the incident has been opened, Belin-Pyles said.
Robert McMillan covers computer security and general technology breaking news for The IDG News Service. Follow Robert on Twitter at @bobmcmillan. Robert's e-mail address is robert_mcmillan@idg.com
- Google I/O 2013's Coolest Products and Services
- 10 Star Trek Technologies That are Almost Here
- 19 Generations of Computer Programmers
- 25 Must-Have Technologies for SMBs
- A walking tour: 33 questions to ask about your company's security
- 15 social media scams
- The 7 elements of a successful security awareness program
This IT pilot fish at a government agency gets a call from the administrative officer, who's on the verge of hysterics: Her computer is dead, she's having a total meltdown, and it's all his fault.
- IT Certification Study Tips
- Register for this Computerworld Insider Study Tip guide and gain access to hundreds of premium content articles, cheat sheets, product reviews and more.
- Federal IT Innovation Caught in a Catch-22
- Fed resources shoring up old infrastructure, holding back new technologies.
- Harness IT -- An Introduction to Business Intelligence Solutions
- Learn the key selection criteria required to provide your organization with the capability to address structured data, unstructured data and mobile demands so...
- Business Intelligence Shows its Smarts
- Today's Business Intelligence (BI) tools provide a new way to think about data with self-service capabilities and user-friendly analytics that can be used...
- Proactive Planning for Big Data
- Big data is less about the terabytes and more about the query tools and business intelligence needed to make sense of massive amounts...
- Inquiry Spotlight: Consumer-Facing Identity
- The challenges of consumer-facing identity management, access management, and authentication differ in ways subtle and dramatic from those of the employee-facing variety. All Government IT White Papers
- Becoming An Analytics Driven Organization
- Join us on Tuesday, June 18, 2013, 11:00 AM EDT and learn how your agency can create an analytics culture that will enable...
- 3 Reasons Why Sepaton is the World's Fastest Backup Solution
- Leading analyst, Storage Switzerland learns how Sepaton backs up and deduplicates massive data volumes while maintaining the industry's fastest performance - all in...
- Enterprise File Sharing: All You Need to Know
- Security. Scalability. Control. These are just some of the many benefits of enterprise cloud file-sharing that you'll discover in this KnowledgeVault, packed with...
- Bridging HTTP and FTP with FileXpress Internet Server
- What if you could take an FTP server on your internal network, and allow external users (partners or customers) to securely access it...
- MFT and FileXpress - An Overview
- Business users and applications exchange files on a regular basis. File transfer is a core part of the flow of business activity. All Government IT Webcasts
