On December 31, a self-described teenage hacker from Australia who calls himself “Abdilo” claimed to have hacked into dozens of education entities by exploiting SQLi vulnerabilities. Metropolitan State University acknowledged they were breached, but what is going on with the other educational entities that were allegedly hacked, too?

Abdilo claims that he started attacking .edu sites back in August, and by October had 80 .edu sites compromised.  He also claims to have numerous .gov, .mil, and business companies, but this post is only focusing on the education sector attacks, as we haven’t seen any public disclosure from most of them. Do they even know they were allegedly hacked?

Abdilo claims to have hacked public and private educational entities in the U.S. and elsewhere. His list, below, is edited  to only include the .edu entities he claims to have hacked, with his comments:

Here are some of the sites i messed with:
every *.k12 site is vuln to sql injection. broke into you cause i like 22 jump street, thanks for the 22k ssns) reason) steven hawkings) school my ass) guy found a sqli in you then i found a better one… fuck you) easy) a challange but they are dumb) for the 6k sqlis loved it LOL) sqlied you 4 times while obnoxious called you up on the phone to troll you and tell you, then we decided to fuck with you by dumping your database 4 times then asking for booty pix else we release it) Catholics? lol I have no reason I just did it for the hell of it) I has all ur records) are all christian schools vuln to sqli besides MERCY FOR YOU)…. I have nothing funny to say lol) another chirstian school) alexa rank) are yuky) you have a shit alexa rank) was watching dexter and wanted to get into your police station… this was close enough for me) fixed it don’t worry, twas funny having a sqli in a 1.5k alexa rank site) the law) facts are really messed up ;)) idea why I attacked you lol your name is a bitch to type) university of oregon… you mad?) ;))****** ;)) thought you were a news agency) have no alexa rank.. at all) 2,063,219…….) domain, that is all) you tiny) were worth the time and effort) U DUMB AS FUCK) easy)

And that, allegedly, is just some of the .edu sites attacked. Abdilo writes:

I cannot remember the majority of edu/gov i have sqlied, i didnt keep a good enough record and one of my hdds is now… melted and destoryed.

Note that the University of Kentucky was recently mentioned on this blog in the context of a post about hacks mentioned on #TeamCarbonic’s web site by @MarxistAttorney. And although they informed this blog that they were investigating those claims, they never got back to with any statement as to whether they had found confirmation of a breach – by anyone.  Berkeley was also mentioned recently on this blog, but without exploring the data dump, it is not known to me whether this is the same hack as Abdilo claimed.

Abdilo claims that he wanted to see what would happen, and notes that despite all his attacks on .edu, .gov, and .mil, “no cops came calling.”

One would think they would.

In the interim, if anyone is aware that any of Abdilo’s other targets have subsequently acknowledged being hacked, please use the Comments section below to let me know.

  1. Zer0DayDan - January 19, 2015

    Abdilo appears to hail from Australia and you can follow his rants on Twitter @abdilo_.

    A reverse WHOIS lookup on the email address used to register LizardStresser (9ajjs[at]zmail[dot]ru) shows this email has been used to register a number of domains tied to cyber-crime, including sites selling stolen credit card data and access to hacked PCs.

    A more nuanced lookup at using some of this information turns up additional domains tied to Abdilo, including bkcn[dot]ru and abdilo[dot]ru. Another domain that abdilo registered — http://x6b-x72-x65-x62-x73-x6f-x6e-x73-x65-x63-x75-x72-x69-x74-x79-x0[dot]com — is hexadecimal encoding for “krebsonsecurity.”

