Harvard Site Hacked and Leaked on BitTorrent

Written by enigmax on February 18, 2008 

The Harvard Graduate School of Arts and Sciences website appears to have been the subject of a major security breach, as server backups, site databases and contact databases are leaked to BitTorrent. The 125MB file is currently being tracked by The Pirate Bay.

Early reports indicate that a Harvard University website has become the victim of a major security breach. A torrent currently tracked by The Pirate Bay which links to a 125mb .zip file, claims to be the backup from the Harvard Graduate School of Arts and Sciences website.

The backup -seeded from a Harvard IP address (and others)- carries many files, passwords and what appears to be a full directory structure for the site. Three other major database files are mentioned specifically, details as follows:

1. joomla.sql - claims to be the database for the Harvard site

2. contacts.sql - claims to be a database of contacts

3. hgs.sql - stated as ‘other minor thing’

The .NFO file included with the release says in broken English: “Maybe you don’t like it but this is to demonstrate that persons like tgatton(admin of the server) in they don’t know how to secure a website.”

A file included with the release labeled password.txt carries a message:

Thomas gatton….stupid people, you don’t use a secure password

username: Password:

tgatton *removed by TF*

jmartinez *removed by TF*

This appears to be a reference to Thomas Gatton, Systems Administrator and User Support Specialist at Harvard.

This is not the first time Harvard has been hacked. In 2005, a man using the name ‘Brookbond’ helped applicants to several universities get access to admissions records on their websites, an action described by the school as a “serious breach of trust”.

These files certainly appear to be ‘the real deal’. More on this breaking news story as we get it.

Update: The website in question seems to be down now. They are most likely trying to fix the security breach.

Previously: We’re Back…

Next: Yahoo! Filters Pirate Bay From Search Results

69 Responses (Add yours or TrackBack)

Pages: « 1 2 [3] Show All

51 Feb 19, 2008 at 20:52 by destinity

I found one comment posted by “hacker” in the page of the leaked where there is a link of the passwd and shadow files:

http://www.turboupload.com/download/K203LacSHw0g/harvard_password_shadow.zip

52 Feb 19, 2008 at 21:17 by Craig

I saw this on GlobalGrind.com, so it had to be good. I can’t believe that it’s so easy to hack a school like Harvard.

53 Feb 19, 2008 at 22:33 by Pernilla Andersson

[quote comment="292863"]seriously, why is TPB tracking this? This has nothing to do with freedom of intellectual property whatsoever.

What is in the files? personal information of students and teachers? Only spam bastards could use this data to their advantage, I’d say take it offline tpb, this is a bridge too far(and no, I’m not on Harvard).[/quote]

I can’t wait for Internet2, so you can go police them.

I’m sure Harvard is mature enough to write TPB a nice email request, if they so desire.

54 Feb 20, 2008 at 04:23 by w00t

@2 Don’t you dare insult TPB. As far as Harvard’s site.. good thing records of the rich bastards in their graduate school became public :) I doubt there was any really sensitive information. it’s not like he gave away password to the proxy to access their administrative records. It’s just a loser website, that wasn’t even secure. And you my fellow internet user are in deep shit, and I hope the place where YOU work dies and you go jobless and then taste what you wish for others yourself.

55 Feb 20, 2008 at 08:16 by JoeRodge

there are credit card numbers in the leaked shit

56 Feb 20, 2008 at 18:58 by SURE

[quote comment="292152"]i hope tbp gets taken down real soon for having shit like this on their trackers

tpb deserves to die, soon hopefully[/quote]

well it’s still the biggest so fuck off :D

57 Feb 20, 2008 at 21:11 by uh

[quote comment="293435"][quote comment="292863"]seriously, why is TPB tracking this? This has nothing to do with freedom of intellectual property whatsoever.

What is in the files? personal information of students and teachers? Only spam bastards could use this data to their advantage, I’d say take it offline tpb, this is a bridge too far(and no, I’m not on Harvard).[/quote]

I can’t wait for Internet2, so you can go police them.

I’m sure Harvard is mature enough to write TPB a nice email request, if they so desire.[/quote]
Why would I want to “go police them”? And what does that have to do with internet2 or anything for that matter?

58 Feb 22, 2008 at 23:33 by Terry

Harvard = Owned

59 Mar 02, 2008 at 07:49 by BretS

Hacking computers just because you can is pretty screwed up, but I don’t know if there were other reasons. If they obtained library material it wouldn’t be so bad, as knowledge should be free anyway. It’s places like that which keep it hidden and profit from it.

60 Mar 02, 2008 at 07:54 by BretS

This could have been done by the RIAA to put the blame on “pirates” to try and get public sympathy and support.

Then they can gloat, “Look how bad they are. They don’t care who they harm, even an educational institution”

61 Mar 04, 2008 at 13:19 by =]

pile of shit > Harvard

62 Mar 10, 2008 at 18:31 by Anonymous

[quote comment="292152"]i hope tbp gets taken down real soon for having shit like this on their trackers

tpb deserves to die, soon hopefully[/quote]

asshole

63 Mar 13, 2008 at 21:33 by duhuhuhuhuh

dude, the Grad School of arts and sciences doesn’t have the rich kids. You’re thinking of the country club on the other side of the river known as the business school. These kids are the ones that are going to be paying back school loans and eating ramen for the rest of their lives so they can study obscure stuff from antiquity, or maybe physics or something. Not the same thing. Play your class warfare game, but remember that the B-school is the side with the man servants and the hot toddies. The schools are kept totally separate there; they don’t share funding or anything else. Great job, hax0rz: you just hacked the kids that were already screwed.

64 Mar 14, 2008 at 08:31 by Jim Eliott

Can you imagine how Thomas Gatton (the admin) is feeling right now, because he’s a Systems Administrator and User Support Specialist at Harvard?

Looks like any idiot can get a job as a ’security specialist’.

[and, what's the deal with the message that I'm posting to quickly? this is my ONLY post to this site]

65 Mar 14, 2008 at 13:37 by Lolled

Only good site from Harvard ive seen was on movie How High..which i dld from TPB ..KEKmAO

66 Mar 14, 2008 at 13:38 by Lolled

[quote comment="311242"]Only good site from Harvard ive seen was on movie How High..which i dld from TPB ..KEKmAO[/quote]
Side*

67 Mar 20, 2008 at 09:08 by Anonymous

Fuck, now I need to withdraw all my money from the bank and keep it under my pillow since now ANYONE can see my SSN and withdraw money from my bank account.

Whoever hacked the harvard server needs to be shot.

68 Apr 12, 2008 at 08:17 by ricecrispies

“Fuck TPB”

listen up everyone…this dude is 12 years old…
why mention that there are a million proxies if he was going to buy everthing….hhhhmmmmmm…

so ignore him…like he is talking to himself

Pages: « 1 2 [3] Show All

Add your response

It takes approximately 1 minute for your comment to appear on TorrentFreak after it's posted.