Inklings has uncovered a security vulnerability in the Staples y-drive system. Any student can hack into another student’s y-drive equipped with that student’s ID number – bypassing password protection.
A simple process allows anyone connected to the Staples Wi-Fi network to access another student’s Y-Drive to read, edit and, or delete files stored on the user’s account. Although Inklings just uncovered the shortcut, it is unclear for how long it has existed.
A student could acquire the number easily, for example, by observing a student logging into a school computer or buying lunch. In addition, some teachers post grades anonymously, using a broadly-publicized class list of student numbers.
At this time Inklings has contacted several people involved in the school district’s Information Technology staff and the Administration. As of press time, network administrators have disabled any remote access to the network.
Cam Newton • Dec 1, 2011 at 7:20 pm
Really? Thanks for telling everyone how to hack into it! You should’ve waited until it was fixed to report this. But, who uses the y-drive anyway?