Kid attempts to hack my site, should i call up his dad?

Avatar image for expensiveham
expensiveham

394

Forum Posts

7275

Wiki Points

0

Followers

Reviews: 0

User Lists: 1

Me and my friend have spent a few weeks working on a file hosting site for a school project. Despite the site being early in development and not very secure yet we had a build up and running live online.

Yesterday we saw that someone had been uploading and attempting to run encoded files on the site with the hope of obtaining information on the server, site and eventually user data. It does not look like he has had any successes though.

We quickly banned his ip address and found out who is and where he lives. I have his full real name, address, Facebook, steam and email account. I also found his Dads phone number.

Should i call up the Dad and let him know what his son has been doing? The kid is 16 by the way.

Avatar image for musubi
musubi

17524

Forum Posts

5650

Wiki Points

0

Followers

Reviews: 8

User Lists: 17

#2  Edited By musubi

I say why not.

Avatar image for dagbiker
Dagbiker

7057

Forum Posts

1019

Wiki Points

0

Followers

Reviews: 0

User Lists: 16

No. The only reason you would call would be to get back at him, and you would only be met with resistance. My suggestion is, if you cant secure peoples information, then you need to not store it.

Avatar image for delroylindo
DelroyLindo

387

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

certainly should.

Avatar image for morningstar
morningstar

2548

Forum Posts

351

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

Send a formal letter.

Avatar image for tylea002
Tylea002

2382

Forum Posts

776

Wiki Points

0

Followers

Reviews: 4

User Lists: 6

If you're polite about it, I don't see why not.

Avatar image for expensiveham
expensiveham

394

Forum Posts

7275

Wiki Points

0

Followers

Reviews: 0

User Lists: 1

@dagbiker said:

No. The only reason you would call would be to get back at him, and you would only be met with resistance. My suggestion is, if you cant secure peoples information, then you need to not store it.

He did not get any data and even if he did sensitive data like passwords are encrypted.

Avatar image for sexytoad
SexyToad

2936

Forum Posts

3297

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

#8  Edited By SexyToad

Yes call the dad. Teach that kid who's boss!

Avatar image for the_laughing_man
The_Laughing_Man

13807

Forum Posts

7460

Wiki Points

0

Followers

Reviews: 1

User Lists: 0

@dagbiker said:

No. The only reason you would call would be to get back at him, and you would only be met with resistance. My suggestion is, if you cant secure peoples information, then you need to not store it.

He did not get any data and even if he did sensitive data like passwords are encrypted.

Dag is still right. Its your job to make sure this does not happen. I mean..this happens to every other hosting site. I doubt they call up the parents of the hackers and report them. Its part of the job dude.

Avatar image for psylah
psylah

2362

Forum Posts

100

Wiki Points

0

Followers

Reviews: 0

User Lists: 2

No, for the kid to be 16 and to be a script kiddie, he's got a hobby that will hopefully lead to him going into a decent career path. If his dad takes away his computer, he'll be forced to go outside and play football, he'll join the team at school, and when he graduates he'll be pumping gas for minimum wage.

You'll ruin his life.

Avatar image for musubi
musubi

17524

Forum Posts

5650

Wiki Points

0

Followers

Reviews: 8

User Lists: 17

@expensiveham said:

@dagbiker said:

No. The only reason you would call would be to get back at him, and you would only be met with resistance. My suggestion is, if you cant secure peoples information, then you need to not store it.

He did not get any data and even if he did sensitive data like passwords are encrypted.

Dag is still right. Its your job to make sure this does not happen. I mean..this happens to every other hosting site. I doubt they call up the parents of the hackers and report them. Its part of the job dude.

Even the biggest networks in the world with the best security gets breached from time to time. This shit happens and nothing is secure. What matters is that you figure out how to minimize damage when this DOES happen which it sounds like that is exactly what happened.

Avatar image for tobbrobb
TobbRobb

6616

Forum Posts

49

Wiki Points

0

Followers

Reviews: 0

User Lists: 13

As long as you are polite, go for it. It's the parents job to make sure he doesn't pull shit like that in the first place.

Avatar image for expensiveham
expensiveham

394

Forum Posts

7275

Wiki Points

0

Followers

Reviews: 0

User Lists: 1

@demoskinos said:

@the_laughing_man said:

@expensiveham said:

@dagbiker said:

No. The only reason you would call would be to get back at him, and you would only be met with resistance. My suggestion is, if you cant secure peoples information, then you need to not store it.

He did not get any data and even if he did sensitive data like passwords are encrypted.

Dag is still right. Its your job to make sure this does not happen. I mean..this happens to every other hosting site. I doubt they call up the parents of the hackers and report them. Its part of the job dude.

Even the biggest networks in the world with the best security gets breached from time to time. This shit happens and nothing is secure. What matters is that you figure out how to minimize damage when this DOES happen which it sounds like that is exactly what happened.

In case it was not clear, he accomplished nothing and failed at what he was doing. But it is obvious that he has a malicious intent even if he just is a script kiddie. And the information in the database (that he did not get access to) is useless anyway as it is encrypted and contains just a few test accounts me and my friends have made. We only made the site to improve and use our skills in php, sql, css and javascript and its not like we have a large userbase. We have a total of 8 accounts on the site.

Avatar image for soap
Soap

3774

Forum Posts

1811

Wiki Points

0

Followers

Reviews: 9

User Lists: 29

@psylah said:

No, for the kid to be 16 and to be a script kiddie, he's got a hobby that will hopefully lead to him going into a decent career path. If his dad takes away his computer, he'll be forced to go outside and play football, he'll join the team at school, and when he graduates he'll be pumping gas for minimum wage.

You'll ruin his life.

.....do it.

Avatar image for sergio
Sergio

3663

Forum Posts

0

Wiki Points

0

Followers

Reviews: 0

User Lists: 13

#15  Edited By Sergio

Yes. People are correct that it's your responsibility to maintain security of the site. However, under normal circumstances, these types of breaches would also be prosecuted. Just because a web site is responsible for the security of user information, it doesn't mean they ignore information regarding hackers once known. You're doing the kid a favor by informing his dad. The kid could get in more serious trouble if he tries this with someone else.

Avatar image for the_laughing_man
The_Laughing_Man

13807

Forum Posts

7460

Wiki Points

0

Followers

Reviews: 1

User Lists: 0

@demoskinos said:

@the_laughing_man said:

@expensiveham said:

@dagbiker said:

No. The only reason you would call would be to get back at him, and you would only be met with resistance. My suggestion is, if you cant secure peoples information, then you need to not store it.

He did not get any data and even if he did sensitive data like passwords are encrypted.

Dag is still right. Its your job to make sure this does not happen. I mean..this happens to every other hosting site. I doubt they call up the parents of the hackers and report them. Its part of the job dude.

Even the biggest networks in the world with the best security gets breached from time to time. This shit happens and nothing is secure. What matters is that you figure out how to minimize damage when this DOES happen which it sounds like that is exactly what happened.

In case it was not clear, he accomplished nothing and failed at what he was doing. But it is obvious that he has a malicious intent even if he just is a script kiddie. And the information in the database (that he did not get access to) is useless anyway as it is encrypted and contains just a few test accounts me and my friends have made. We only made the site to improve and use our skills in php, sql, css and javascript and its not like we have a large userbase. We have a total of 8 accounts on the site.

Then use this to also improve your security.

Avatar image for jams
Jams

3043

Forum Posts

131

Wiki Points

0

Followers

Reviews: 0

User Lists: 5

@expensiveham:

@soap said:

@psylah said:

No, for the kid to be 16 and to be a script kiddie, he's got a hobby that will hopefully lead to him going into a decent career path. If his dad takes away his computer, he'll be forced to go outside and play football, he'll join the team at school, and when he graduates he'll be pumping gas for minimum wage.

You'll ruin his life.

.....do it.

Yup, do it. Put the scare in the kid early that he can easily be found out by fucking around. More than likely he wont be so arrogant to think he'll be more sneaky next time and leave that shit alone. Maybe tell his dad to not take the computer away but warn that he can be put in jail and fined for what he did and that he should concentrate on contributing to society instead of fucking it up.

Then have the dad whip his ass with a belt.

Avatar image for expensiveham
expensiveham

394

Forum Posts

7275

Wiki Points

0

Followers

Reviews: 0

User Lists: 1

#18  Edited By expensiveham

@the_laughing_man said:

Then use this to also improve your security.

I have already made changes to stop it from happening again.

@psylah said:

No, for the kid to be 16 and to be a script kiddie, he's got a hobby that will hopefully lead to him going into a decent career path. If his dad takes away his computer, he'll be forced to go outside and play football, he'll join the team at school, and when he graduates he'll be pumping gas for minimum wage.

You'll ruin his life.

I am not doing this to fuck with him and try to get him in trouble. From what i've learned looking him up he seems like a smart kid (he has a game up on google play for example) and i think his technical interest is something that should be encouraged but using security exploits to fuck with someones site and try to get server information is not the right way.

Avatar image for jrinswand
Jrinswand

1747

Forum Posts

60

Wiki Points

0

Followers

Reviews: 0

User Lists: 2

#19  Edited By Jrinswand
Avatar image for alexander
Alexander

1760

Forum Posts

731

Wiki Points

0

Followers

Reviews: 1

User Lists: 4

.

Avatar image for pr1mus
pr1mus

4158

Forum Posts

1018

Wiki Points

0

Followers

Reviews: 4

User Lists: 4

What that gif^ says.

Avatar image for sanity
Sanity

2255

Forum Posts

178

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

Bring the hammer down! (thats code for call his dad!)

Avatar image for mellotronrules
mellotronrules

3608

Forum Posts

26

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

yes- 100% do it. if he's going to behave like a child, call him out on it.

Avatar image for nux
Nux

2898

Forum Posts

130

Wiki Points

0

Followers

Reviews: 2

User Lists: 2

@psylah said:

No, for the kid to be 16 and to be a script kiddie, he's got a hobby that will hopefully lead to him going into a decent career path. If his dad takes away his computer, he'll be forced to go outside and play football, he'll join the team at school, and when he graduates he'll be pumping gas for minimum wage.

You'll ruin his life.

This sounds like a fine reason to call that boy's father.

Avatar image for mikkaq
MikkaQ

10296

Forum Posts

52

Wiki Points

0

Followers

Reviews: 0

User Lists: 2

#25  Edited By MikkaQ

Call the father, and just start making up stuff about all these laws his son broke, but since he's under 18 and using his father's internet connection, that the father is liable and will soon be contacted by a lawyer.

At the very least you can waste some of his money by scaring him into a legal consult over nothing.

Avatar image for ravenlight
Ravenlight

8057

Forum Posts

12306

Wiki Points

0

Followers

Reviews: 0

User Lists: 2

If you have his FB, maybe just make a polite post on his wall asking him to stop messing with your site. If he knows someone's onto him, he might get scared off.

If not, then call his dad.

Avatar image for louiedog
louiedog

2391

Forum Posts

227

Wiki Points

0

Followers

Reviews: 0

User Lists: 2

#27  Edited By louiedog

@psylah said:

No, for the kid to be 16 and to be a script kiddie, he's got a hobby that will hopefully lead to him going into a decent career path. If his dad takes away his computer, he'll be forced to go outside and play football, he'll join the team at school, and when he graduates he'll be pumping gas for minimum wage.

You'll ruin his life.

Alternatively, calling his dad and explaining things could help him get into a summer internship that might help him focus these interests in a more productive way before he does this to the wrong site and police get involved. You never know what this kid is looking for. Maybe he's trying to steal and sell credit card info which is going to land him in a lot more trouble than his dad taking away his computer.

Avatar image for max_cherry
Max_Cherry

1700

Forum Posts

176

Wiki Points

0

Followers

Reviews: 0

User Lists: 0

#28  Edited By Max_Cherry

His dad probably doesn't know what the internet even is.

Avatar image for bybeach
bybeach

6754

Forum Posts

1

Wiki Points

0

Followers

Reviews: 0

User Lists: 1

I would say inform daddy w/ a strong hint of his son applying his talent in a nondistructive way. If that is possible. Especially if this misguided bs of making other ppl's lives miserable can be reoriented into a job.

Avatar image for justin258
Justin258

16685

Forum Posts

26

Wiki Points

0

Followers

Reviews: 11

User Lists: 8

So how do you know the father won't call up the police on you for obtaining contact information without permission? Yes, I know the kid committed a crime, but "he's just a kid" might fly and get him off for far less or even nothing.

Avatar image for jams
Jams

3043

Forum Posts

131

Wiki Points

0

Followers

Reviews: 0

User Lists: 5

#31  Edited By Jams

@louiedog said:

@psylah said:

No, for the kid to be 16 and to be a script kiddie, he's got a hobby that will hopefully lead to him going into a decent career path. If his dad takes away his computer, he'll be forced to go outside and play football, he'll join the team at school, and when he graduates he'll be pumping gas for minimum wage.

You'll ruin his life.

Alternatively, calling his dad and explaining things could help him get into a summer internship that might help him focus these interests in a more productive way before he does this to the wrong site and police get involved. You never know what this kid is looking for. Maybe he's trying to steal and sell credit card info which is going to land him in a lot more trouble than his dad taking away his computer.

It's also a little worrisome that this kid has a game published on Google Play and is also trying to steal information. That could come back and bite him in the ass if he ever tries to make a living selling games.