会员登录 - 用户注册 - 设为首页 - 加入收藏 - 网站地图 Teenager finds educational software exposed millions of student records!

Teenager finds educational software exposed millions of student records

时间:2024-09-22 09:59:33 来源:摩登家庭人人影视网 作者:行业动态 阅读:763次

Teenager Bill Demirkapi had been ghosted. Hard. "It didn’t feel good," he explained to the large crowd gathered to hear him speak. "It hurt my feelings.”

But Demirkapi, despite his status as a recent high-school graduate, wasn't lamenting the traditional spurned-love problems typical of his cohort. Far from it. Instead, he was speaking at the famous DEF CON hacker conference in Las Vegas, and the ghoster-in-question was educational software maker Blackboard.

Demirkapi had reported numerous vulnerabilities in Blackboard's software to the company; after initially being in communication with him, the company stopped responding to his emails. But Demirkapi, who found he could access a host of student data — including family military status, weighted GPAs, and special education status — through vulnerabilities in Blackboard's system, was undeterred.

In fact, he was just getting started. And Blackboard wasn't his only target.

Mashable ImageHaving walked the walk, he now talks the talk.Credit: jack morse / mashable

Over the course of his high school career, Demirkapi — a budding security researcher — also investigated K-through-12 software maker Follett. In doing so, he determined the company left millions of student and teacher records exposed to anyone who bothered to look.

Specifically, he explained, there were more than 5 million student and teacher records in the system that covered over 5,000 schools. Left exposed were students' immunization history, attendance data, school photos, birthdays, and more.

Mashable Light SpeedWant more out-of-this world tech, space and science stories?Sign up for Mashable's weekly Light Speed newsletter.By signing up you agree to our Terms of Use and Privacy Policy.Thanks for signing up!

"It was my data too in there," he told the audience of decidedly not teenage hackers. "This was pretty crazy stuff."

He tried to do the right thing and notified both his high school and the software manufacturers of his discoveries. Using a flaw in the system to alert students and teachers to its vulnerabilities, however, earned him a two-day suspension.

"Two days off of school," he said of the punishment. "I think it’s a pretty big win-win."

SEE ALSO:Remotely hacking elevator phones shouldn't be this easy

Eventually, Follett and Blackboard did listen — and many of the vulnerabilities he reported were patched at the end of July.

"Blackboard is always working hard to improve both the security of our products as well as the process and procedures we leverage in support of security," read a statement the company provided Demirkapi and he shared with DEF CON.

Asked by a member of the crowd what he's going to do next, Demirkapi gave an answer that elicited raucous applause from the hacker crowd: "Start college, maybe break their software."

Never give up on your dreams, Bill. The privacy of millions of students and teachers is counting on it.


Featured Video For You
From ATMs to printers, hackers prove you can play 'Doom' on anything

(责任编辑:产品中心)

相关内容
  • Number of COVID
  • 党员是一面旗帜 要为群众办实事
  • 肉质鲜美!泰农黑猪邀您品鉴优质猪肉
  • 实地走访 查漏补缺 市政协常委会视察文明创建工作
  • Update your BIOS: Utilities from Top Motherboard Makers
  • 雅安民歌:从山旮旯飞向首都北京
  • 三天一查 七天一报 抓住有利时机围歼稻瘟病
  • 暴雨来袭 石棉汉源多处道路再迎考验
推荐内容
  • Where to pre
  • “都来看电影啰!”——走进电影周影片放映点
  • 车祸女孩遭截肢 家乡人捐款一万元
  • 石棉县9月开始评选“石棉好人”
  • 'Please find her': Man dies amid 25
  • “温氏·绿美杯”羽毛球赛向全省发出倡议:以乡村体育助力“绿美广东”