NewsMarch 21, 2011 at 1:22 pm

Some Awesome Engineer Hacked, Got Classes Cancelled

This is why we need to pay attention to Engineers more. Today, someone managed to hack into an administrator’s email account. They sent a perfectly legit-sounding message canceling all classes in Moore before noon due to an “electrical breakdown.”

Honestly, it was probably only a matter of time before an entire school of technologically-savvy people managed to do something as simple as hack into an email address, right?

It was only after a followup email from the real administrator did anyone realize something was wrong. Wrong, and awesome. Read the emails after the jump!

 

—–Original Message—–
From: “\”S. Sonya Gwak\” <”<sgwak@seas.upenn.edu>
Sender: seas-sr-bounces@lists.seas.upenn.edu
Date: Mon, 21 Mar 2011 13:21:37
To: <seas-ugrad@seas.upenn.edu>; <seas-grad@seas.upenn.edu>
Reply-To: sgwak@seas.upenn.edu
Subject: [Seas-sr] [Seas-fr] Important : Classes in Moore cancelled due to
electrical failure

Dear SEAS Community,

There has been an electrical breakdown in Moore Building due to the bursting of an A.C. Duct. This has caused an electrical failure in most of the classrooms and labs.

The facilities team are working on it and the systems will be restored soon. However all classes in Moore Building before noon have been cancelled. Classes in Towne and Skirkanich Buildings shall continue as usual.

Further information about make-up classes and exams shall be provided by the faculty for the class.

Classes after noon shall resume normally. We will keep you updated with any further developments.


S. Sonya Gwak, Ph.D.
Associate Director for Student Affairs and Advising
School of Engineering and Applied Science
Office of Academic Programs
111 Towne Building
T: 215-573-8369
F: 215-573-5577

And the followup clarification:

—–Original Message—–
From: “S. Sonya Gwak” <sgwak@seas.upenn.edu>
Sender: seas-sr-bounces@lists.seas.upenn.edu
Date: Mon, 21 Mar 2011 10:20:23
To: <seas-ugrad@seas.upenn.edu>; <seas-grad@seas.upenn.edu>
Subject: [Seas-sr] Message from Sonya Gwak

Dear all,

it seems that my email has been hacked. CETS is aware and I am getting
it fixed.

I apologized for any inconvenience this may have caused.

S. Sonya Gwak, Ph.D.
Associate Director for Student Affairs and Graduate Admissions
University of Pennsylvania, School of Engineering and Applied Science
Office of Academic Programs
220 S. 33rd Street, 111 Towne Building, Philadelphia, PA 19104
Email: sgwak@seas.upenn.edu
Tel: 215-898-7246
Fax: 215-573-5577

13 People have left comments on this post


By Sandra Rubinchik on March 21, 2011 at 1:22 pm

Maybe the overuse of the word “shall” should have clued everyone in.

By Ghfh on March 21, 2011 at 1:22 pm

Why is the time on the first email after the time on the second?

By Morgan Finkelstein on March 21, 2011 at 1:22 pm

I don’t know, acutally– that’s how the emails were forwarded to me. It’s weird because it says that the original email was sent at 1:21 pm, which would have been like 10 minutes ago instead of around 10 am when it actually happened. Maybe a result of the hacking, maybe a typo from our tipster, but I don’t think it really affects the stiuation

By SEAS student on March 21, 2011 at 1:22 pm

Original email was sent at 8:22 am. Also, another admin sent this at 10am

The email below was sent in error and classes have not been canceled in the Moore Bldg. Please feel free to email me directly with questions or concerns.

Enjoy your day!
Cindi Buoni
Associate Director
Academic Programs Office

Afterwards, there was this email at 10:36:

Dear all,

the problem has been resolved. Please don’t ignore my emails.
SEAS-Weekly and GSEG emails will be going out soon!

Thanks!

S. Sonya Gwak, Ph.D.
Associate Director for Student Affairs and Graduate Admissions University of Pennsylvania, School of Engineering and Applied Science Office of Academic Programs 220 S. 33rd Street, 111 Towne Building, Philadelphia, PA 19104
Email: sgwak@seas.upenn.edu
Tel: 215-898-7246
Fax: 215-573-5577

By Winning on March 21, 2011 at 1:22 pm

someone did it to one of my classes. No hacking was involved, just a simple php email spoofer.

By Engineering Student on March 21, 2011 at 1:22 pm

This guy did no hacking either. S/he visited a simple website that lets you type in the contents of the “From: ” field. Emails are just text files sent across the internet, so they are by no means secure by default.

By CS Student on March 21, 2011 at 1:22 pm

They weren’t even smart enough to write their own CGI mailer – If you look at the headers of the spoofed e-mail, they used the website http://www.emkei.cz. Interestingly, somewhere along the line, the e-mail was detected as being suspicious, as the note “(may be forged)” is also present in the headers, and the e-mail has a “suspicious” spam score of 1.

This is traceable from many angles, especially considering the scale of Penn’s legal team. Whoever did this could have done a much cleaner job.

By MSE Student on March 21, 2011 at 1:22 pm

I also got another hoax email from one of my engineering professors saying that the final for his class was moved to the 10th:

“Dear Students,
Due to scheduling conflicts the final exam has been postponed to the 10th of may.
If there are any questions or concerns please let me know immediately.

Prof. Peter K. Davies
Dept. Materials Science
(200 LRSM; 898-1013) ”

My professor responded three hours later saying that his final exam wasn’t postponed and that this email was a hoax. But anyways this computer hacker is jumping the gun, it’s not april fool’s day for a week and a half!

By mary on March 21, 2011 at 1:22 pm

exsqueeeeeze me but let’s not forget about the awesome april fools prank from 2009 when some whartonites were tricked into believing that they had to make up an exam due to cheating??

By seas student on March 21, 2011 at 1:22 pm

Why don’t you other engineers try and email the seas undergrad listserv right now? You need an account with permission in order to send to it…

By Marsh on March 21, 2011 at 1:22 pm

if only Morgan Finkel were as cool as this engineer maybe she could actually teach me a thing or two and help me study

By Shriram on March 21, 2011 at 1:22 pm

LOL nice idea..and nice use of emkei.cz !! but totally useless as its the easiest way to trace you back..

By h8r on March 21, 2011 at 1:22 pm

thanks for the expert witness testimony, csstudent. and why would you write your own cgi mailer? you need to have a super cool custom web app just to use postfix? a ‘cleaner job’ by similar methods would not make it any harder for gwak to realize that she wasn’t the one who sent it, nor harder for cets to realize it didn’t originate from her account.

Post a Comment