Harvard Site Hacked and Leaked on BitTorrent

Written by enigmax on February 18, 2008 

The Harvard Graduate School of Arts and Sciences website appears to have been the subject of a major security breach, as server backups, site databases and contact databases are leaked to BitTorrent. The 125MB file is currently being tracked by The Pirate Bay.

Early reports indicate that a Harvard University website has become the victim of a major security breach. A torrent currently tracked by The Pirate Bay which links to a 125mb .zip file, claims to be the backup from the Harvard Graduate School of Arts and Sciences website.

The backup -seeded from a Harvard IP address (and others)- carries many files, passwords and what appears to be a full directory structure for the site. Three other major database files are mentioned specifically, details as follows:

1. joomla.sql - claims to be the database for the Harvard site

2. contacts.sql - claims to be a database of contacts

3. hgs.sql - stated as ‘other minor thing’

The .NFO file included with the release says in broken English: “Maybe you don’t like it but this is to demonstrate that persons like tgatton(admin of the server) in they don’t know how to secure a website.”

A file included with the release labeled password.txt carries a message:

Thomas gatton….stupid people, you don’t use a secure password

username: Password:

tgatton *removed by TF*

jmartinez *removed by TF*

This appears to be a reference to Thomas Gatton, Systems Administrator and User Support Specialist at Harvard.

This is not the first time Harvard has been hacked. In 2005, a man using the name ‘Brookbond’ helped applicants to several universities get access to admissions records on their websites, an action described by the school as a “serious breach of trust”.

These files certainly appear to be ‘the real deal’. More on this breaking news story as we get it.

Update: The website in question seems to be down now. They are most likely trying to fix the security breach.

Previously: We’re Back…

Next: Yahoo! Filters Pirate Bay From Search Results

69 Responses (Add yours or TrackBack)

1 Feb 18, 2008 at 12:44 by fiftyone.area

lol

2 Feb 18, 2008 at 12:53 by Fuck TPB

i hope tbp gets taken down real soon for having shit like this on their trackers

tpb deserves to die, soon hopefully

3 Feb 18, 2008 at 13:35 by King

heh.
Hire new server personal maybe :P

4 Feb 18, 2008 at 13:47 by TonInter

@2
Blow TPB’s …., son.

5 Feb 18, 2008 at 13:58 by plagio

@2 yeah right. That is not going to happen.

you deserve to die, soon hopefully

6 Feb 18, 2008 at 14:00 by .

TPB is not to blame. If it wasn’t there it would’ve been available somewhere else.

7 Feb 18, 2008 at 14:03 by Mr. Dr. PhD

[quote comment="292152"]i hope tbp gets taken down real soon for having shit like this on their trackers

tpb deserves to die, soon hopefully[/quote]

ROFL *slap*

and about the article, ROFL!

8 Feb 18, 2008 at 14:13 by Reacto

[quote comment="292152"]i hope tbp gets taken down real soon for having shit like this on their trackers

tpb deserves to die, soon hopefully[/quote]

Kindly Go fuck yourself :)

9 Feb 18, 2008 at 14:14 by Simpad

“The backup -seeded from a Harvard IP address”
I’m not using µTorrent so I don’t know if I’m reading this right, but it appears the harvard.edu IP only has 3.4 % of the file, hence is not a seeder.

10 Feb 18, 2008 at 14:14 by chris

TPB is the best they have to control what goes on their trackers,unless its reported

11 Feb 18, 2008 at 14:21 by Erhan

You do read it right Simpad, that harvard ip was merely downloading it.

12 Feb 18, 2008 at 16:12 by Mr.IceMan

Dear TorrentFreak team can we please get the IP form the 2nd comment poster to ban his IP range on our networks ? :)

13 Feb 18, 2008 at 16:15 by crimson

yea give us the ip, needs to be put on some blocklists …

14 Feb 18, 2008 at 16:20 by hecklerx

well i think torrents really are the best choice for a global world because i live in europe and was born in the states and i like to see some tv programs from the states and i have the most expensive and most chanels my country offers but i still cant get what i want unless i download it…so screw all you goody 2 shoes who are aginst global share…

P.S. i’ll preach global share till i die…

15 Feb 18, 2008 at 16:39 by Daniel

lol, but what do you expect from a site running joomla.

16 Feb 18, 2008 at 16:44 by Fuck TPB

like i care for getting banned u bunch of dipshits lol =P

i hope the swedish court rules u fuckers r guilty of piracy

then u’ll be forced to take down ur shit on swedish servers, and soon disappear

fuck ur polluted trackers, u assholes cant even keep it clean, so u might as well completely disappear

fuck u morons

17 Feb 18, 2008 at 16:45 by Fuck TPB

i have money to buy my shit, i dont need to pirate, bunch of poor fuckers lol =P

18 Feb 18, 2008 at 16:48 by R2

At least they will improve security…
No system is safe “there’s always a way in”, and involve people makes it weak.
Trust your hardware, not your service support.

About the ip of the stupid guy, we must keep anonymous, turn his ip public would be the end…
But of course, i agree with a ban :) or a ‘mute’.
I’m for the “No IP retention” !

19 Feb 18, 2008 at 16:53 by Fuck TPB

lol =P

u pirates truly r a bunch of dumbass dipshits

theres like a zillion proxies, how u gonna stop me?

tpb is shit, and deserves to die

20 Feb 18, 2008 at 16:58 by Yatti

Yikes, sounds like real pirates scurrying around..

21 Feb 18, 2008 at 17:04 by Downeh

Bored a little ‘Fuck TPB’?

And I’m glad to hear you have the money to buy the things you wish instead of downloading….truly I am glad…

//reminisces at how many times that has been said in the past by people just like this chap.

22 Feb 18, 2008 at 17:21 by durzagon

@ Fuck TPB

too bad your money is not enough to get yourself a real girl.

hope wanking to pirate bay is satisfactory for you poor nerd :)

23 Feb 18, 2008 at 17:31 by bRPp

“Fuck TPB”
ya maw said she hates you last nite, she said she was thinking of jumping off a cliff so people stop associating her with you, so do the right thing first and you jump ! :D

24 Feb 18, 2008 at 17:48 by thenotsojollyroger

i would bet anyone of us could beat that cat up.
sounds like he is ten.
he considers piracy as a ‘dirty’ thing.
sounds a bit like Thomas Gatton to me lol

25 Feb 18, 2008 at 18:21 by Gissa

“Fuck TPB”
Is that you Cary Sherman?
Or you Dan Glickman?
You sound too stupid to even be John Giacobbi so am a bit confused….

26 Feb 18, 2008 at 18:44 by Alex

Harward is using Wind0ze ^^

TPB-owners rulz. Their “Juridisk korrespondens” rulz too :D

27 Feb 18, 2008 at 19:45 by Almo

На новость все равно. Но для общего развития сойдет

28 Feb 18, 2008 at 20:34 by Anonymous

first rule of the internet: dont feed the troll.

ontopic: one of the major schools in the world has been haxed?? shit happens…

29 Feb 18, 2008 at 20:35 by just another one

first rule of the internet: dont feed the troll.

ontopic: one of the major schools in the world has been haxed?? shit happens…

30 Feb 18, 2008 at 21:08 by ChaosBlade

well, just ignore these ass whores like …fuck tpb….. :), that’ll be down right to the point then, yeah, can’t believe harvard got haxor3d, hilarious

31 Feb 18, 2008 at 21:25 by random

fuck tpb…

has money….

but he has to use the 100000+ proxies to hide behind ;)

32 Feb 18, 2008 at 21:48 by Anonymous

God Damn. Badass pirates. Kudos to the hackers who took down Harvard’s GSAS site. I don’t believe that it should have been released, but that was a personal choice of theirs.

Never too late to show the big boys that their system still sucks.

33 Feb 18, 2008 at 21:54 by ST

“The backup -seeded from a Harvard IP address (and others)- carries many files, passwords and what appears to be a full directory structure for the site”

Anyone else think that they are downloading to find out what passwords etc. have been breached and what needs to be changed?

34 Feb 18, 2008 at 22:58 by billy bob

that’ll teach them to leave their backups accessible to the internet_

Shouldn’t backups be offline? Makes more sense_

35 Feb 19, 2008 at 00:28 by Xan

Hahahaha.

They got what they deserved. Hopefully i can still download it before if it’s ever removed.

36 Feb 19, 2008 at 01:45 by Ronald the Pirate

OOh Arrr, I’m a pirate

37 Feb 19, 2008 at 01:46 by stefan24

tpb whatever next

38 Feb 19, 2008 at 03:11 by Anon

Anyone got the time to explain how to get a human-readable table or something from those .sql files?

39 Feb 19, 2008 at 03:12 by Demonsweat

Chics dig guys with a big ratio.

“Please, don’t feed the troll”

40 Feb 19, 2008 at 03:13 by Hash

[quote comment="292302"]lol =P

u pirates truly r a bunch of dumbass dipshits

theres like a zillion proxies, how u gonna stop me?

tpb is shit, and deserves to die[/quote]

You use a proxy to post a comment to a news section about torrents. Wow, I didn’t realise people were still this retarded.

[quote comment="292414"]first rule of the internet: dont feed the troll.[/quote]

He’s not a troll, he’s just another fucktard that likes to talk a big game sat behind a monitor with his mouse in one hand and another fingering his ass.

41 Feb 19, 2008 at 06:36 by sinistroN

lulz.

42 Feb 19, 2008 at 06:38 by Anonymous

Is there anything in the file worth downloading? Like pictures of sexy college girls? I know you have to judge them on the Yale scale but still…

43 Feb 19, 2008 at 07:35 by Anonymous

[quote comment="292152"]i hope tbp gets taken down real soon for having shit like this on their trackers

tpb deserves to die, soon hopefully[/quote]

Kid, if you don’t stop posting this shit, I won’t let you have your mother back.

44 Feb 19, 2008 at 07:49 by Brick

its highly probably that the student was either an electrical engineer (EE) or computer science (CS) major. Backed up by the fact that the ip reads eecs.harvard.edu

45 Feb 19, 2008 at 09:33 by uh

seriously, why is TPB tracking this? This has nothing to do with freedom of intellectual property whatsoever.

What is in the files? personal information of students and teachers? Only spam bastards could use this data to their advantage, I’d say take it offline tpb, this is a bridge too far(and no, I’m not on Harvard).

46 Feb 19, 2008 at 15:40 by oneplusone

Theres nothing in it.
Just unviersity phone lists and their sql code. There’s nothing particularly juicy at all. And their robots.

47 Feb 19, 2008 at 18:24 by DarkMindZ

http://www.darkmindz.com/forum/view.dmz?id=1612

Owned another section…

48 Feb 19, 2008 at 19:29 by d00der

I lol’d

49 Feb 19, 2008 at 20:52 by destinity

I found one comment posted by “hacker” in the page of the leaked where there is a link of the passwd and shadow files:

http://www.turboupload.com/download/K203LacSHw0g/harvard_password_shadow.zip

50 Feb 19, 2008 at 21:17 by Craig

I saw this on GlobalGrind.com, so it had to be good. I can’t believe that it’s so easy to hack a school like Harvard.

51 Feb 19, 2008 at 22:33 by Pernilla Andersson

[quote comment="292863"]seriously, why is TPB tracking this? This has nothing to do with freedom of intellectual property whatsoever.

What is in the files? personal information of students and teachers? Only spam bastards could use this data to their advantage, I’d say take it offline tpb, this is a bridge too far(and no, I’m not on Harvard).[/quote]

I can’t wait for Internet2, so you can go police them.

I’m sure Harvard is mature enough to write TPB a nice email request, if they so desire.

52 Feb 20, 2008 at 04:23 by w00t

@2 Don’t you dare insult TPB. As far as Harvard’s site.. good thing records of the rich bastards in their graduate school became public :) I doubt there was any really sensitive information. it’s not like he gave away password to the proxy to access their administrative records. It’s just a loser website, that wasn’t even secure. And you my fellow internet user are in deep shit, and I hope the place where YOU work dies and you go jobless and then taste what you wish for others yourself.

53 Feb 20, 2008 at 08:16 by JoeRodge

there are credit card numbers in the leaked shit

54 Feb 20, 2008 at 18:58 by SURE

[quote comment="292152"]i hope tbp gets taken down real soon for having shit like this on their trackers

tpb deserves to die, soon hopefully[/quote]

well it’s still the biggest so fuck off :D

55 Feb 20, 2008 at 21:11 by uh

[quote comment="293435"][quote comment="292863"]seriously, why is TPB tracking this? This has nothing to do with freedom of intellectual property whatsoever.

What is in the files? personal information of students and teachers? Only spam bastards could use this data to their advantage, I’d say take it offline tpb, this is a bridge too far(and no, I’m not on Harvard).[/quote]

I can’t wait for Internet2, so you can go police them.

I’m sure Harvard is mature enough to write TPB a nice email request, if they so desire.[/quote]
Why would I want to “go police them”? And what does that have to do with internet2 or anything for that matter?

56 Feb 22, 2008 at 23:33 by Terry

Harvard = Owned

57 Mar 02, 2008 at 07:49 by BretS

Hacking computers just because you can is pretty screwed up, but I don’t know if there were other reasons. If they obtained library material it wouldn’t be so bad, as knowledge should be free anyway. It’s places like that which keep it hidden and profit from it.

58 Mar 02, 2008 at 07:54 by BretS

This could have been done by the RIAA to put the blame on “pirates” to try and get public sympathy and support.

Then they can gloat, “Look how bad they are. They don’t care who they harm, even an educational institution”

59 Mar 04, 2008 at 13:19 by =]

pile of shit > Harvard

60 Mar 10, 2008 at 18:31 by Anonymous

[quote comment="292152"]i hope tbp gets taken down real soon for having shit like this on their trackers

tpb deserves to die, soon hopefully[/quote]

asshole

61 Mar 13, 2008 at 21:33 by duhuhuhuhuh

dude, the Grad School of arts and sciences doesn’t have the rich kids. You’re thinking of the country club on the other side of the river known as the business school. These kids are the ones that are going to be paying back school loans and eating ramen for the rest of their lives so they can study obscure stuff from antiquity, or maybe physics or something. Not the same thing. Play your class warfare game, but remember that the B-school is the side with the man servants and the hot toddies. The schools are kept totally separate there; they don’t share funding or anything else. Great job, hax0rz: you just hacked the kids that were already screwed.

62 Mar 14, 2008 at 08:31 by Jim Eliott

Can you imagine how Thomas Gatton (the admin) is feeling right now, because he’s a Systems Administrator and User Support Specialist at Harvard?

Looks like any idiot can get a job as a ’security specialist’.

[and, what's the deal with the message that I'm posting to quickly? this is my ONLY post to this site]

63 Mar 14, 2008 at 13:37 by Lolled

Only good site from Harvard ive seen was on movie How High..which i dld from TPB ..KEKmAO

64 Mar 14, 2008 at 13:38 by Lolled

[quote comment="311242"]Only good site from Harvard ive seen was on movie How High..which i dld from TPB ..KEKmAO[/quote]
Side*

65 Mar 20, 2008 at 09:08 by Anonymous

Fuck, now I need to withdraw all my money from the bank and keep it under my pillow since now ANYONE can see my SSN and withdraw money from my bank account.

Whoever hacked the harvard server needs to be shot.

66 Apr 12, 2008 at 08:17 by ricecrispies

“Fuck TPB”

listen up everyone…this dude is 12 years old…
why mention that there are a million proxies if he was going to buy everthing….hhhhmmmmmm…

so ignore him…like he is talking to himself

Add your response

It takes approximately 1 minute for your comment to appear on TorrentFreak after it's posted.