Universities Compromised

A group known as Team GhostShell has extracted a ton of student information from universities across the world. They even got to pretigious universities such as the ivy league schools in the USA. The hackers claim this was done to protest high university tuition rates. Not sure why they went after the personal information of students enrolled their though. Wouldn't you think they would target school officials or something?

Apparently the hackers used good old SQL injection to retrieve the data. Independent sources say as many as 36k student records were exposed. Some of the information was publicly available. However other data such as date of birth was also exposed. I checked out GhostShell's Twitter feed. They hit over 100 schools with their attack. I am now reminded that they shared their "findings" on PasteBin.

There is a Way

A developer called me up and asked whether I could access the database. I did a quick check. Nope. So I told him that I could not. Upon hearing that, the developer declared that there was no way to do his work. He then gave up. What? That can't be it. At the very least you got to tell someone else and have them resolve the problem.

I decided to do a little digging. The way I knew there was no database access was that I tried a "tnsping". That command checks to see if the database can be contacted. I got back an error that the target host or object does not exist. Now that might mean that the actual database was down. However I tried accessing the database from another machine and found that it was up and running.

So I dug a little deeper. We configure our workstations to use a tnsnames file to resolve database aliases. I ensured that we were using the configuration file that that DBAs set up. Then I made sure that file existed. So far so good. Finally I checked that our database alias was in that configuration file. It was.

Next I looked at the configuration data for our alias. The config file just translates the alias to a domain name and a port on that machine where the database listens. I tried a regular ping of the domain name of the server. Bamm. My machine could not resolve the domain name. Well I found out the IP address of our server. When I plugged that into a local copy of the config file, the door was opened. Full access to the database.

The problem must be some sort of Domain Name Server issue. Ping cannot resolve my well known domain name. Time to get the network guys involed. I don't even have to bother my DBA team.

Chess Cheating

Just read this story about a high school kid. He was good at chess. Then he went to some camp. After that, he started winning tournaments like a champ. He got to his state's final competition. This guy was spanking players well above his chess rating. What the heck was going on?

They interviewed one of his opponents. The opponent was some sort of kid grand master at chess. He said that when he played this high school kid, he was hanging on for dear life due to the aggressive onslaught of attacks on the chess board. How could a kid rise up in chess skill so fast. Well it turns out the boy was cheating.

The chess rules allow you to bring in a PDA to record your chess rules. You are only allowed to run a certain chess move recording program. That program has been certified as being able to take over the PDA and ensure no other programs (that might be used to cheat) are running. Turns out this kid was somehow able to get around it.

What should have been suspicious is a kid with just a good rating all of a sudden starts playing like he is Bobby Fischer. That just does not happen. They also interviewed some of this kid's previous coaches. They knew he was okay, but nothing like a Bobby Fischer. In fact, a past opponent had complained that it felt as if the dude was cheating. They just could not find any evidence of it before.

In the end, a judge was called into the state competition match, took possession of the PDA, and found a rogue program being run. Here is the funny part of the story. The kid said this was the first time he cheated. Yeah right. The moral of the story is to trust but verify.

Careful When Reverse Engineering

I was making some scheduling changes. This amounted to some crontab entry modifications. I do thing very rarely. It happens maybe once or twice a year at most. I took a look at the current settings. Needed to changes some tasks to run on Tuesday instead of Wednesday.

Now I don't know the crontab entry syntax by heart. When memorize that when you can look it up? At this point I also figured why look it up if you can reverse engineer it by looking at some entries. I saw some existing entries that run on Tuesdays. Then I saw some existing entries that run on Wednesdays. The first difference I noticed was that the Tuesday jobs started with a 0 on the crontab line, and the Wednesday jobs started with a 1.

I figured this was simple. Just change the first digit to a 1 and you move the job to Wednesdays. However I had a nagging feeling in my stomach. Why would they define Tuesday as 0? Shouldn't 0 represent the start of the week? That would make Sunday be represented by 0. Or if they were really weird, maybe Monday could be 0. But not Tuesday.

I decided to look up the cron docs. Oh snap. That first parameter is minute of the hour when the job is supposed to fire. Parameter number 5 on the line governs the day of the week when the job is kicked off. Good thing I did not rely too heavily on my weak reverse engineering skills. The moral of the story is to look stuff up unless it cannot be easily Googled.

The 10x Programmers

There is a myth that there exist some "ten times" programming. They can write code at ten times the productivity of normal programmers. They are rare. But it is said that they exist. Today I read a post that tried to debunk this myth.

Okay. Everyone is entitled to their opinion. Some guy produced an equation that looked complicated. Then he wrote a simple code snippet to solve the equation. The moral of the story was that problems that look hard are actually easy. The ten times programmer is really working on somthing easy.

I almost was fooled. Then I started reading the comments on the post. There were a lot of errors in the implementation of the code snippet to solve the problem. Oh snap. I guess this guy is not a ten times programmer. And it takes a ten times programmer to solve the tough equations. Bamm.

NSA Jobs for DEF CON People

The National Security Agency (NSA) is looking to hire some of the competant attendees of the DEF CON conference. They are particularly interested if you win any of the DEF CON competitions. I personally have never attended DEF CON. But I get the impression that you get a badge of honor if you do with a challenge. These must be some peeps with elite skills.

The NSA are doing some forward thinking here. They are trying to attract the people with th e right skills. They also understand that DEF CON hackers might have a shady past. Apparently that will not necessarily disqualify you from a job at the NSA. You just need to be a US citizin.

I would hope that having a government job at the NSA might pay higher than other government jobs. They probably do some interesting work for sure. Check out the NSA link.

Hacker School

I currently use the local community college to keep up with programming technology. But lately I have been considering alternative methods to learning. I've been keeping an eye on the so called hacker schools that seem to be popping up. Maybe it is time to try one of these out.

I was interested in the hacker school called Hacker School mostly because it is free of charge. However you need to attend in person in New York City. Don't think I can afford to be away from work for the two and a half months it takes to complete the training.

Bloc is a school that is new to me. It has the benefit of being online. I can enroll from the comfort of my own home. However the thing costs $3500 for the two month experience. In the big scheme of things, that is not a huge amount of money. But I don't think I can talk my employer into footing the bill from Bloc hacker school. LOL.

The school with the most buzz is Code Academy. It is the worst of all worlds though. You must attend in person at the Chicago campus. It also costs $6000 to attend. Those two strikes mean that I will most likely not attend. To see a tabular comparison of the different offerings, you can check out the following page on Bloc. I would take the stats with a grain of salt. It is hosted on Bloc after all. Still a good start.