Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- Rutgers Central Services - Re: Data Breach (self.rutgers)
- submitted 6 hours ago * by HypocriticalRutgers
- Yes there is an issue. No, it is not a hack.
- 80 commentsshare
- all 80 comments
- sorted by: best
- [-]enduhroo2 points
- am i hearing this right? so some nerd got pissed at the buses and decided to fuck the rest of us because of it? what a goddamn pussy.
- permalink
- [-]sportsfan1019902 points
- Assuming the guy was telling the truth yeah. According to the OP of this thread the guy just started the issue, they figured it out but it opened up a whole nother can of worms which is what they're trying to fix now.
- permalink
- [-]forbiddenone1 point
- Wait what?
- What exactly was his issue with the busses, what do you mean by 'started the issue', and what is the "whole nother can of worms' that they are trying to fix now?
- permalink
- [-]ButtClenching1 point
- I don't know, but I have issues with the REXL sometimes.
- permalink
- [-]forbiddenone1 point
- What issues? Too crowded? Not showing up? Bus driving pulling away as you frantically pound on the doors?
- permalink
- [-]Darth_drizzt_425 points
- okay i'm just seeing this post and none of OP's replies are showing up.
- permalink
- [-]sportsfan1019906 points
- Earlier in the day OP said he was affiliated with RU but was keeping anonymous. He called out the guy that was posting on here taking credit fro the ddos saying he pretty much didn't really do anything. A few hours later I looked at this thread and OP changes his post saying his best guess would be noon tomorrow. All of his replies were changed to "no." now they're all blank. Idk if OP was even affiliated with RU, if he got shut down for posting this and told to change his answers by his hire ups, or if it was something else altogether, maybe another troll.
- permalink
- [-]slightly_anon1 point [original unedited comment restored by uneddit.com]
- That has happened in the past. Student employeescan/do get fired for posting comments containing non-public informaton.
- permalink
- [-]dodobrains1 point
- I can't see them either
- permalink
- [-]TodayILearnedAThing3 points
- Can anyone summarize the details? OP? All of your comments are editted out
- permalink
- [-]ohhiiiiii8 points
- He deleted them all. They didn't really clarify anything and personally I think he was BSing everyone.
- permalink
- [-]HypocriticalRutgers-2 points
- As the title says, yes there was an issue. No there was not a hack. Full disclosure is done by the university. Not by me.
- permalink
- [-]Daniel_Yusim3 points
- As the title says, yes there was an issue. No there was not a hack. Full disclosure is done by the university. Not by me.
- People should quote the OP by highlighting his comments before hitting reply to keep him from deleting them and being a total sketch.
- permalink
- [-]wildemu4 points
- That would be some Se7en type shit if OP was the hacker. All these deletions really weren't necessary. And if you're worried about your internship job, you shouldn't have been here posting then. Now there's just more confusion on what happened.
- permalink
- [-]HypocriticalRutgers0 points [original unedited comment restored by uneddit.com]
- I'm not worried about my job (Not an internship btw) Haha in all honesty, I just got tired of my phone going off. Systems will be back online soon.
- permalink
- [-]forbiddenone1 point
- Can you explain to me why SERC only has the mysterious "LAWN" network for internet access when it's... well... SERC?
- I mean, is it on purpose (so that people who bring laptops and such will have a harder time goofing off during class- at least they'll have to use their cell phones as hotspots), or is it an oversight, or what?
- Just curious.
- permalink
- [-]forbiddenone1 point
- I knew it! Macs are the source of all evil!
- Just take a look at those podiums with their evil Apple software with their evil hidden icons and obfuscation of how to do what you want to do!
- permalink
- [-]agiantwaffle3 points
- If the guy was smart enough to bring your department down for this longass period of time, I'm pretty sure he's not dumb enough to DDOS you without hiding his original MAC address and information.
- Not to mention he's also taunting you..
- permalink
- [-]HypocriticalRutgers-2 points [original unedited comment restored by uneddit.com]
- I leave with this final comment: If he was smart, he would have not brought about attention to himself.
- permalink
- [-]gaypolarbear6 points
- And why are you now removing all of your replies, and trimmed your OP down to a mere sentence...?
- permalink
- [-]HypocriticalRutgers-2 points [original unedited comment restored by uneddit.com]
- Situation has been resolved.
- permalink
- [-]gaypolarbear4 points
- Not quite sure, but if this is what RU OIT calls a resolution then I need to get a job over there.
- permalink
- [-]HypocriticalRutgers0 points [original unedited comment restored by uneddit.com]
- Like the main post states, my eta until systems are back up are at 12noon tomorrow.
- permalink
- [-]gaypolarbear3 points
- And do you, as a representation of your department, feel this is an adequate response/resolution window since the time of the attacks?
- permalink
- [-]gaypolarbear1 point
- He'd only bring attention to himself if he was confident he covered enough significant backdoors that could trace back to him. Seems he is.
- permalink
- [-]HypocriticalRutgers-4 points [original unedited comment restored by uneddit.com]
- It isn't my job to go after would be hackers. It is my job to stop them. And I have.
- permalink
- [-]gaypolarbear5 points
- With all due respect, and trust me, I respect your hustle and know what you're doing is hard work... with that being said, you didn't stop him. Our entire network is down. Our entire network has been compromised regardless if you feel at this very moment that it is safe. A person single-handedly brought our network infrastructure to a screeching halt, and 50,000+ students are unable to access vital information. This was not preventative. This wasn't even controlled upon the attack. The fact that the network is STILL down, over 24 hours since his assault proves how he already feels: in his twisted little mind, he won.
- permalink
- [-]HypocriticalRutgers0 points [original unedited comment restored by uneddit.com]
- He didn't create the issue.
- permalink
- [-]gaypolarbear1 point
- He didn't create an issue, but earlier you stated you "stopped" him?
- I'm confused man. You seem to be doing a lot of flip flopping. And of course, i'm all for giving time to get things rolling again... but a lot of time has already passed since the attacks first happened.
- permalink
- [-]HypocriticalRutgers-2 points [original unedited comment restored by uneddit.com]
- He may taunt. The issue is resolved. Internet will be up within the weekend. Happy browsing everyone.
- permalink
- [-]someoneinsignificant2 points [original unedited comment restored by uneddit.com]
- The exfocus guy made a rebuttal stating that the mac address provided is wrong, and so is the color of the laptop. Idk is this legit?
- permalink
- [-]yy4me5002 points
- Well the internet has been up for about 45 min now so thats at least something. I think he's full of crap personally.
- permalink
- [-]ThrowAway_Rutgers1 point [original unedited comment restored by uneddit.com]
- MAC addresses are unreliable. It's actually my birthdate. I just needed to have him spinning his wheels while I fixed a few things. Internet will remain 'bleh' for a while but tomorrow expecting 100% full recovery. Happy browsing everone.
- permalink
- [-]semipellucid2 points
- Soooooo are you going to be able to catch him?
- permalink
- [-]Unspec73 points
- http://pastebin.com/HY8d7UZ9
- Created a backup since he set that one to expire in an hour. My question is, how does he know the OP is an intern who's been at OIT for 3 months? Either he's making it up, or he works/worked at OIT.
- permalink
- [-]someoneinsignificant3 points
- He could have just made that up to insult OP. I want to know why OP thinks the laptop is gray. Unless the student has been spotted in public, I don't see how that's possible. OP could have just said "you were sitting at the LSC at this time wearing this clothes with this backpack" or something like that, I don't think "gray laptop" is a clue that OP found him.
- permalink
- [-]Daniel_Yusim1 point [original unedited comment restored by uneddit.com]
- It's a very generic color for laptops, since silver and charcoal/black-ish can be seen as grey. 5/6 laptops I've owned have been "grey". (this fugly blue one that I'd prefer in grey or green being number 6)
- permalink
- [-]ChillAlterEgo4 points
- Is there any eta on this being resolved?
- permalink
- [-]HypocriticalRutgers-2 points [original unedited comment restored by uneddit.com]
- No eta, sorry. Hang tight.
- permalink
- [-]Unspec73 points
- I thought mac addresses were in hex, like 00:00?
- permalink
- [-]HypocriticalRutgers2 points [original unedited comment restored by uneddit.com]
- It's an inside message to him. He will figure it out.
- permalink
- [-]coairrob7777 points [original unedited comment restored by uneddit.com]
- An inside message? This is starting to sound like Catch Me if you Can: Rutgers edition.
- permalink
- [-]HypocriticalRutgers2 points [original unedited comment restored by uneddit.com]
- This was an inside message to see there was any validity to statements made. The user in question is not a threat.
- permalink
- [-]yy4me5002 points
- Rekt.
- permalink
- [-]MutatedSpleen4 points
- One question for you:
- What many users are experiences is a failure in accessing SECURE portions of the Rutgers umbrella due to an 'allergic' type reaction among servers. All other services remain unaffected at this time.
- Would that include both Resnet and RU Wireless? People in dorms have been basically totally unable to internet now for the past two days.
- permalink
- [-]HypocriticalRutgers1 point [original unedited comment restored by uneddit.com]
- In a word yes. When you access RU wireless, you are authenticated when you login. Resnet has a similar authentication. Be patient. Many professors are aware and will grant extensions on homework.
- permalink
- [-]TheShadyTurtle1 point
- Question: heard in the office that the Rutgers network was doing something with their security certificates, and that RCS was going to be spotty. Is this related to what this guy is claiming? note: very limited to no computer knowledge.
- permalink
- [-]HypocriticalRutgers16 points [original unedited comment restored by uneddit.com]
- I can't tell you what the repercussions are and if the university wishes to pursue a legal matter. His information is on my bosses desk. It is out of my hands at this time. Personally he did no damage in my opinion. The bug was already there, and he was just the one to uncover it in my opinion. I just wanted to calm fears among students.
- Using external DNS resolvers will help you connect back to the network.
- The internet will shift from active to active as routers reset and the network adjusts.
- permalink
- [-]4amchocolatepudding2 points
- So what did he do exactly? He said a ddos attack as well as something about social security numbers(which is probably b.s)
- permalink
- [-]HypocriticalRutgers7 points [original unedited comment restored by uneddit.com]
- Social security numbers are not stored AT ALL at Rutgers. This is mandated by New Jersey law. Federal Servers manage that data. If he accessed federal servers, he's stupid.
- permalink
- [-]monjan620142 points
- I just entered my SSN (it prompted me) when I requested my RU transcripts. What's that all about then?
- permalink
- [-]4amchocolatepudding2 points
- ah ok. Thanks for the post
- permalink
- [-]knaik00undefined points [deleted comment restored by uneddit.com]
- hey, I am a student, so all of this is speculation from my end, I am actually a bio major lol, i have been thinking about turning to CS, anyway, he basically use botnets to spam the servers, like what what we all accidentally do during registration XD lol , the botnets aren't real people, it's all just one computer pretending to be that many but sakai can't tell they aren't real
- permalink
- [-]HiHaplo2 points
- Thank you for clearing this up.
- permalink
- [-]4amchocolatepudding2 points
- He was banned from the subreddit so he won't see this. Judging by his twitter he doesn't seem likely to stop on his own
- permalink
- [-]wildemu2 points
- You can also use a VPN to make another account and post again. If he really wanted to post here again, he would.
- permalink
- [-]4amchocolatepudding1 point
- He was boasting that he was using a vpn yesterday
- permalink
- [-]bobsbitchtitz1 point
- he can see this he just cant post
- permalink
- [-]RelentlessKid3 points
- Can't he just make a new reddit account? Also as to the original post, I was wondering when someone would say something although it's a big risk if they find out who you are OP.
- permalink
- [-]HypocriticalRutgers2 points [original unedited comment restored by uneddit.com]
- Rest assured I'm doing alright. I've had authorization from by boss to post. He has not had authorization from his boss (go figure, he's on vacation) however which is why this was released "hush hush"
- permalink
- [-]wildemu3 points
- He seems quite confident on his twitter that he will get away with this. But he's really fucked right?
- permalink
- [-]knaik00undefined points [deleted comment restored by uneddit.com]
- I would think he is, but either way I would be careful about logging into sakai and related things without the SSL (the https:// in front)... this could be him "luring" people to sakai, who knows
- permalink
- [-]wildemu1 point [original unedited comment restored by uneddit.com]
- luring in the sense that he can take your information, or the fact that our traffic helps him?
- permalink
- [-]knaik00undefined points [deleted comment restored by uneddit.com]
- on a twitter he was bragging that he has a 0day exploit, which honestly isn't very likely, but it's not bad to be safe. 0day basically means he has an exploit that the developers of sakai don't know yet, but with sakai being open source that's not likely and also probably time consuming. Although we probably won't know for sure, my guess is he is using http://www.akamai.com/html/about/press/releases/2015/press-022515-2.html which i found by literally googling "sakai ddos 2015" because i rememebered it happened last year
- permalink
- [-]HypocriticalRutgers2 points [original unedited comment restored by uneddit.com]
- Technically the bug he uncovered wasn't Sakai based. (Or it was and it just tripped some internal alarms) We have a slightly polished version ported with a few extras.
- permalink
- [-]HypocriticalRutgers5 points [original unedited comment restored by uneddit.com]
- Upvoted. Do not connect to any Rutgers secure services without HTTPS://. The only exception are the RU Financial and OPDocs for professors as they have internal security measures.
- permalink
- [-]MongolianDynamite2 points
- O balls I used sakai last night to submit a paper is that ok?
- permalink
- [-]HypocriticalRutgers1 point [original unedited comment restored by uneddit.com]
- I can't check if your paper was properly received, however the issue is with the network and not with Sakai so more than likely your paper was received successfully.
- permalink
- [-]thephenom211 point [original unedited comment restored by uneddit.com]
- Internet is back for me right now!
- permalink
Advertisement
Add Comment
Please, Sign In to add comment