Harvard Site Hacked and Leaked on BitTorrent

Written by enigmax on February 18, 2008 

The Harvard Graduate School of Arts and Sciences website appears to have been the subject of a major security breach, as server backups, site databases and contact databases are leaked to BitTorrent. The 125MB file is currently being tracked by The Pirate Bay.

Early reports indicate that a Harvard University website has become the victim of a major security breach. A torrent currently tracked by The Pirate Bay which links to a 125mb .zip file, claims to be the backup from the Harvard Graduate School of Arts and Sciences website.

The backup -seeded from a Harvard IP address (and others)- carries many files, passwords and what appears to be a full directory structure for the site. Three other major database files are mentioned specifically, details as follows:

1. joomla.sql - claims to be the database for the Harvard site

2. contacts.sql - claims to be a database of contacts

3. hgs.sql - stated as ‘other minor thing’

The .NFO file included with the release says in broken English: “Maybe you don’t like it but this is to demonstrate that persons like tgatton(admin of the server) in they don’t know how to secure a website.”

A file included with the release labeled password.txt carries a message:

Thomas gatton….stupid people, you don’t use a secure password

username: Password:

tgatton *removed by TF*

jmartinez *removed by TF*

This appears to be a reference to Thomas Gatton, Systems Administrator and User Support Specialist at Harvard.

This is not the first time Harvard has been hacked. In 2005, a man using the name ‘Brookbond’ helped applicants to several universities get access to admissions records on their websites, an action described by the school as a “serious breach of trust”.

These files certainly appear to be ‘the real deal’. More on this breaking news story as we get it.

Update: The website in question seems to be down now. They are most likely trying to fix the security breach.

Previously: We’re Back…

Next: Yahoo! Filters Pirate Bay From Search Results

69 Responses (Add yours or TrackBack)

Pages: « 1 [2] 3 » Show All

26 Feb 18, 2008 at 18:44 by Alex

Harward is using Wind0ze ^^

TPB-owners rulz. Their “Juridisk korrespondens” rulz too :D

27 Feb 18, 2008 at 19:45 by Almo

На новость все равно. Но для общего развития сойдет

28 Feb 18, 2008 at 20:34 by Anonymous

first rule of the internet: dont feed the troll.

ontopic: one of the major schools in the world has been haxed?? shit happens…

29 Feb 18, 2008 at 20:35 by just another one

first rule of the internet: dont feed the troll.

ontopic: one of the major schools in the world has been haxed?? shit happens…

30 Feb 18, 2008 at 21:08 by ChaosBlade

well, just ignore these ass whores like …fuck tpb….. :), that’ll be down right to the point then, yeah, can’t believe harvard got haxor3d, hilarious

31 Feb 18, 2008 at 21:25 by random

fuck tpb…

has money….

but he has to use the 100000+ proxies to hide behind ;)

32 Feb 18, 2008 at 21:48 by Anonymous

God Damn. Badass pirates. Kudos to the hackers who took down Harvard’s GSAS site. I don’t believe that it should have been released, but that was a personal choice of theirs.

Never too late to show the big boys that their system still sucks.

33 Feb 18, 2008 at 21:54 by ST

“The backup -seeded from a Harvard IP address (and others)- carries many files, passwords and what appears to be a full directory structure for the site”

Anyone else think that they are downloading to find out what passwords etc. have been breached and what needs to be changed?

34 Feb 18, 2008 at 22:58 by billy bob

that’ll teach them to leave their backups accessible to the internet_

Shouldn’t backups be offline? Makes more sense_

35 Feb 19, 2008 at 00:28 by Xan

Hahahaha.

They got what they deserved. Hopefully i can still download it before if it’s ever removed.

36 Feb 19, 2008 at 01:45 by Ronald the Pirate

OOh Arrr, I’m a pirate

37 Feb 19, 2008 at 01:46 by stefan24

tpb whatever next

38 Feb 19, 2008 at 03:11 by Anon

Anyone got the time to explain how to get a human-readable table or something from those .sql files?

39 Feb 19, 2008 at 03:12 by Demonsweat

Chics dig guys with a big ratio.

“Please, don’t feed the troll”

40 Feb 19, 2008 at 03:13 by Hash

[quote comment="292302"]lol =P

u pirates truly r a bunch of dumbass dipshits

theres like a zillion proxies, how u gonna stop me?

tpb is shit, and deserves to die[/quote]

You use a proxy to post a comment to a news section about torrents. Wow, I didn’t realise people were still this retarded.

[quote comment="292414"]first rule of the internet: dont feed the troll.[/quote]

He’s not a troll, he’s just another fucktard that likes to talk a big game sat behind a monitor with his mouse in one hand and another fingering his ass.

41 Feb 19, 2008 at 06:36 by sinistroN

lulz.

42 Feb 19, 2008 at 06:38 by Anonymous

Is there anything in the file worth downloading? Like pictures of sexy college girls? I know you have to judge them on the Yale scale but still…

43 Feb 19, 2008 at 07:35 by Anonymous

[quote comment="292152"]i hope tbp gets taken down real soon for having shit like this on their trackers

tpb deserves to die, soon hopefully[/quote]

Kid, if you don’t stop posting this shit, I won’t let you have your mother back.

44 Feb 19, 2008 at 07:49 by Brick

its highly probably that the student was either an electrical engineer (EE) or computer science (CS) major. Backed up by the fact that the ip reads eecs.harvard.edu

45 Feb 19, 2008 at 09:33 by uh

seriously, why is TPB tracking this? This has nothing to do with freedom of intellectual property whatsoever.

What is in the files? personal information of students and teachers? Only spam bastards could use this data to their advantage, I’d say take it offline tpb, this is a bridge too far(and no, I’m not on Harvard).

46 Feb 19, 2008 at 15:40 by oneplusone

Theres nothing in it.
Just unviersity phone lists and their sql code. There’s nothing particularly juicy at all. And their robots.

47 Feb 19, 2008 at 18:24 by DarkMindZ

http://www.darkmindz.com/forum/view.dmz?id=1612

Owned another section…

48 Feb 19, 2008 at 19:29 by d00der

I lol’d

Pages: « 1 [2] 3 » Show All

Add your response

It takes approximately 1 minute for your comment to appear on TorrentFreak after it's posted.