WHID 2009-5: School data hacked, grades altered

Updated: 
17 January 2009
Attack Information
WHID ID: 
2009-5
Date Occured: 
15 Jan 2009
Attack Method: 
Outcome Information
Outcome: 
Target Information
Attacked Entity Field: 
Education
Attacked Entity Geography: 
USA

This story about student hacking a Pottsville, PA school online system and changing grades demonstrated again that password stealing is by far the most common method in which web sites are hacked.

While it is usually not considered a vulnerability in the application itself, I think that application that expose administrative or high privileges interface to the web should include authentication beyond a simple password. A school grading system is one example. The Twitter administrative interface hacked last week is another example.