dslreports logo
 
    All Forums Hot Topics Gallery
spc
uniqs
20

FFH5
Premium Member
join:2002-03-03
Tavistock NJ

FFH5 to milnoc

Premium Member

to milnoc

Re: [Serious] Dawson College expels hacking student

said by milnoc:

Dawson College is about to hold a news conference over the expulsion.

Dawson colleges comments on expulsion. BTW it stays, for now anyway. The pressure is building on them to back down.

»www.cbc.ca/news/canada/m ··· baz.html

Dawson director general Richard Filion said the school expelled Al-Khabaz based on the school's professional code of conduct.

"We're not doing this blindly, we're not doing this with happiness, but we had to consider a serious breach in these values and principles," said Filion.

The Dawson Student Union is appealing for the school to reinstate Al-Khabaz.

"Hamed is a brilliant computer science student who simply wanted to help his school," said Morgan Crockett, the union’s director of internal affairs and advocacy.

"Dawson College should be thankful for his talent and foresight. They must immediately reinstate Hamed, refund the debt he has incurred as a result of his unjust expulsion and offer him a public apology."

Filion said the school rejected the appeal and maintained its decision to expel Al-Khabaz.

"Well, if you look at the Criminal Code, it is clear that if someone is having access without authorization to any computer service, he is ... guilty in a criminal act," said Filion.

dragonfly5
join:2012-09-04

dragonfly5

Member

Oh Filion, your obsession with law and order is touching. If you're serious, you should be expelling half your students for pot possession.

hm
@videotron.ca

hm to FFH5

Anon

to FFH5
said by FFH5:

"Well, if you look at the Criminal Code, it is clear that if someone is having access without authorization to any computer service, he is ... guilty in a criminal act," said Filion.

The kid noticed that if he switched some numbers around in the URL, then he had full and unfettered access to someone elses info. SIN, D.O.B. Grades, Address, phone number, Courses taken or dropped or added, including locker number and combinations.

THIS is what he brought to their attention. A security hole the same magnitude in size and number as this: »Re: [Serious] HRSDC does it again!!! And it has even more info than that breach.

At this point he was congratulated by everyone, including Dawsons own Computer admins.

It's only once he ran this program freely downloadable program, »www.acunetix.com/vulnera ··· ownload/, to check if the hole was fixed (which he should be concerned about since his info is in it and accessible to anyone) that both the company and Dawson came down on him. The threats and intimidation to tell no one and to sign an NDA from this creep of a company, and an expulsion with support by his own faculty to step on him. Not only so, but Dawson goes to great lengths to even lie by saying he was injecting cross site XSS exploits, which he wasn't and confirmed by the company. Dawsons excuse is a lie to cover themselves. And it also goes to show how little the faculty at Dawson teaching Comp Sci even know what and XSS exploit is.

Looks bad on all of them and makes them look like total idiots.

And to top it off, let is not forget this was only *just one* exploit he found out of many. And again this is a magnitude similar to the HRDC breach.

Seems to me Dawson is just hiding from both the public and the press, as well as making crap up and the CBC more or less called them out on.

indeedy
@videotron.ca

indeedy to dragonfly5

Anon

to dragonfly5
said by dragonfly5:

Oh Filion, your obsession with law and order is touching. If you're serious, you should be expelling half your students for pot possession.

Indeed. And half the faculty who goes out to smoke pot with them, and the other half buying smokes from the students who live on the reserve.

He is one to talk.
booj
join:2011-02-07
Richmond, ON

booj to hm

Member

to hm
said by hm :

The kid noticed that if he switched some numbers around in the URL, then he had full and unfettered access to someone elses info. SIN, D.O.B. Grades, Address, phone number, Courses taken or dropped or added, including locker number and combinations.

THIS is what he brought to their attention. A security hole the same magnitude in size and number as this: »Re: [Serious] HRSDC does it again!!! And it has even more info than that breach.

I can't believe incrementing numbers in a URL gets you a felony hacking conviction in the US:

»techcrunch.com/2013/01/2 ··· ibility/

hm
@videotron.ca

hm

Anon

The Honda Canada breach was the same, but contained *lots less* info than what Dawson has.

Since I was affected I called privcom on this one and it's the same as what this Dawson kid did, Privcom said it wasn't worth dragging Honda over the coals.

Funny how the same vectors have different outcomes, eh.

But then again, Privcom has people who understand what the exploit is and what a computer is, as well as what pumpiong diff ID's do. Dawsons Computer Science faculty does not, amazingly enough. I wouldn't want to be taught by these people.
MaynardKrebs
We did it. We heaved Steve. Yipee.
Premium Member
join:2009-06-17

MaynardKrebs

Premium Member

said by hm :

The Honda Canada breach was the same, but contained *lots less* info than what Dawson has.

Since I was affected I called privcom on this one and it's the same as what this Dawson kid did, Privcom said it wasn't worth dragging Honda over the coals.

Funny how the same vectors have different outcomes, eh.

But then again, Privcom has people who understand what the exploit is and what a computer is, as well as what pumpiong diff ID's do. Dawsons Computer Science faculty does not, amazingly enough. I wouldn't want to be taught by these people.

Exactly.

Maybe all the Dawson CompSci students should sue the college for devaluing their 'degree/diploma' by the lack of understanding and antics the faculty/administration displayed over this matter. I calls into question anything the students were 'taught'.

hm
@videotron.ca

hm

Anon

Per the National Post reporter who broke the story, Dawson has had a legal waiver given to them to divulge any private information they see fit to prove what they were stating.

Dawson decided to hide since it has become clear their Comp Sci faculty dinosaurs don't know an XSS from a port scan.

Expelled Dawson student waives privacy rights, challenges College to prove he deserved expulsion
»rabble.ca/blogs/bloggers ··· llege-pr

zong
Premium Member
join:2005-07-21
Scarborough, ON

zong

Premium Member

Even more interesting is according to the reporter who broke the story in that link, the College told another CBC reporter investigating the story that the original reporter is going to be sued, and that the CBC will be sued if they keep pressing.

Amazing. Bullying a kid is one thing, covering up and threatening the press is a whole other matter. Who the hell is running that show anyway? They don't seem to be running on all cylinders.
peterboro (banned)
Avatars are for posers
join:2006-11-03
Peterborough, ON

1 recommendation

peterboro (banned)

Member

This is no surprise to anyone familiar with labour law in Ontario who the biggest wankers are in administration.

1. Universities then Colleges.

2 Hospitals.

3 Provincial ministries.

It seems there is a degree of inverse proportionality to common sense and a degree of the douche bag factor that is related to ones pay and propensity to engage in covering up anything that challenges their little fiefdoms.