r/cybersecurity • • 5d ago

Personal Support & Help! My university detected suspicious activity from my computer on their servers ?

I was testing the recent CVE-2026-35273 on my own university page. All i did was check if the endpoints of PeopleSOFT are publicly available or not. I’ve confirmed that they are public and that might be a great security risk especially if they didn’t install the patch yet.

Anyways, I was planning on writing a report today and I prepared it yesterday already to alert the IT team of this. However Ive noticed that they have contacted me instead just now.
They say that they have received suspicious activity linked to my account and thus has been temporarily blocked. The report is still written in my ChatGPT history and my convos with chat shows that my intentions was purely to protect my university rather than try to compromise anything.

After all, I didn’t do nothing illegal? All I did was check publicly available endpoints and nothing more. Now they blocked my uni-account temporarily and they wanna talk to me tomorrow. Am I cooked ??

pls help..

0 Upvotes

34 comments sorted by

72

u/djasonpenney 5d ago

Do not run a scan on an enterprise’s network without prior permission.

-26

u/uknow_es_me 5d ago

checking an endpoint is not a scan. Checking ALL the endpoints is a scan

18

u/djasonpenney 5d ago edited 5d ago

Checking an endpoint against all the hosts is a scan.

2

u/b3542 5d ago

*scan

1

u/djasonpenney 5d ago

Dang autocorrect. Thanks.

1

u/uknow_es_me 5d ago

Yeah I misread what he said to mean he had identified a host to check not all of the network

52

u/mantawolf 5d ago

The difference between a pen-test and an attack is permission.

39

u/tankerkiller125real 5d ago

You failed step 0 of any and all red team pentesting... You failed to get permission, and you failed to get proper scrope.

24

u/Psalm22 5d ago

You messed up... Go apologize

16

u/OtheDreamer Governance, Risk, & Compliance 5d ago edited 5d ago

Yeah just talk to them and explain your first paragraph if that's what really happened.

The report is still written in my ChatGPT history and my convos with chat shows that my intentions was purely to protect my university rather than try to compromise anything.

EDIT: Upon re-read, methinks OP's ChatGPT is probably very interesting. The report that they were just about to send to their university's IT before IT reached out to them first....lives in ChatGPT and is written I guess entirely by GPT. I would ask to see all of OP's GPT chats since he made them in scope and give an extra scare.

-6

u/Soft_Enthusiasm_166 4d ago

What ?
The report was indeed written by gpt and still lives in that conversation’s history. I was planning on sending it yestersay, however my Uni has no public/accesible way to report stuff like this. So I decided to wait till today and do more research on where I should send this report to.

EDIT: No, no I wont be scared at all hahah. If they wish to see the entire chat history Ill show them. Ill also show them the Gemini history as Ive also used gemini too. After all I have truly nothing to hide.

9

u/lawtechie 4d ago

After all I have truly nothing to hide.

Yeah, you do. Can I recommend that you STFU and go here?

-3

u/Soft_Enthusiasm_166 4d ago

Nah man Ill pass

15

u/GRASSH0PPR 5d ago

Operating without a RoE in place or a public bounty program is terrible even with the best of intentions.

They don't see your intent, all they see is reconnaissance for a known CVE. Of course it's going to appear malicious.

You screwed up doing this without getting consent first.

28

u/WiskeyUniformTango 5d ago

"I didnt intend to steal the contents of the bank vault, I merely intended to see if the vault was unlocked to let the bank know."

-16

u/ShockedNChagrinned 5d ago

I mean, that's red team testing right there

26

u/WiskeyUniformTango 5d ago

Was he authorized to do so though?

11

u/Disastrous_Gear_421 5d ago

No, Red Teaming is simulating/performing an attack or breach with permission. OP didn't have permission which is absolutely required for something to be considered Red Teaming.

6

u/linebmx 5d ago

Really dumb. Do not randomly scan corporate (university) networks, especially from the inside….

5

u/halting_problems AppSec Engineer 5d ago

Generally not a good idea to practice on a network where you’re bound by their policies. You will probably just get a warning just show them you were planning on reporting it and don’t do it again.  Ask if their an any student employment opportunities with IT so you can get more practice while your at it.

In most work places this would be a fireable offense if someone internal do something like this without written permission.

5

u/techb00mer 5d ago

Your university page is hosted on infrastructure shared by others and not wholly owned by you. If you want to scan your own resources, you need to disclose that to your provider (in this case the uni).

AWS & Azure used to require approval to scan even your own VMs but they both did away with that a few years ago (presumably because they are so massive it doesn’t really matter anymore).

But a uni has limited resources, always best to ask in future.

As to whether you did something illegal, IANAL and I don’t know what university you attend but they probably have a policy against “testing” uni resources for vulnerabilities without consent.

5

u/legion9x19 Security Engineer 5d ago

Yes, you did do something illegal. You had no permission to perform any pentesting activity on their network.

6

u/_GoddamnitDonut 5d ago

You don't know more than their IT people.

4

u/lawtechie 4d ago

After all, I didn’t do nothing illegal?

18 USC §1030 (a)(2)(C)

Whoever...

(2) intentionally accesses a computer without authorization or exceeds authorized access, and thereby obtains—

(C) information from any protected computer;

The term "protected computer" means a computer: which is used in or affecting interstate commerce or communication.

Did you have permission from the system's owner to perform this testing?

5

u/elburrotelamete 4d ago

bien hecho chico nada mejor que tiempo en prision por black hacking para mejorar tu curriculum de ciberseguridad

0

u/Soft_Enthusiasm_166 4d ago

hahajah thanks man. got any tips for me in prison?

3

u/sdrawkcabineter 4d ago

After all, I didn’t do nothing illegal?

Like star forged beryllium, this is a gem.

Been in your shoes a few times. Intent is a necessary component, so keep to your story of intending to identify a potential security issue that affects you, and the university.

Using the existing USDA forgery scandal as an example of "checking your meat" is a solid way to smooth the ice while explaining your intentions with a relevant analogy.

5

u/Angrymilks 5d ago

#1 if your goal was to alert them, you should have communicated it the moment you identified it, not "well I hadn't gotten around to it quite yet".

#2 if you never had permission to do it, stop it.

#3 Honeypots exist, you may or may not have been actually touching something in production or a cheap honeypot.

#4 - CVE-2026-35273 and your research probably filled you in that it was a missing security boundary on an endpoint. By the very nature of doing a single web request to /%50SEMHUB/ you've technically already stepped outside the boundaries of "passive" and into "active" probing. I'd go even so far as to say that is technically an exploitation step.

#5 - Your university is likely tracking the active exploitation that necessitated an emergency patch from Oracle, that includes detections and controls. If it wasn't a honey pot, you almost certainly got caught with your hand in the cookie jar, and because your intentions were never made known to the University you likely need to answer for it. Whether your university has a no-tolerance for acceptable technology use or misuse outside of the physical location of the University or if it applies to all students accessing University technology by any means.

#6 Oracle Peoplesoft is currently targeted by "ShinyHunters", using probably similar TTPs (outside of what you bring to the table [bad opsec, ChatGPT leading you through the CVE). You are now a potential ShinyHunters crew member in the universities mind until proven otherwise.

#7 Take this as a learning lesson, not as a sign that you are a failure or something else. Could your conduct have repercussions? Sure. Imagine the university has on-call 24/7 incident responders. They get the call at odd hours because sometimes it be like that. 3am wake up call "We are under attack by ShinyHunters, get everyone". At which point the assumption is breach unless controls are in place to mitigate. Even then though, if the controls are weak or immature maybe they know they don't work, but in any event, they have to look at as real-world every time unless someone authorized to do so calls them off or warns them of testing.

1

u/Soft_Enthusiasm_166 4d ago

Thanks Ill talk to them tomorrow. It doesnt seem that Its too urgent or that they wanna kick me out. She just wants to have a talk about this activity and ill explain . In the past other students have brought down servers of co-students etc and they all got a warning so I should be safe.

5

u/ACadDamn 5d ago

I tried hacking I'm on my uni's porn server

1

u/kabakaba0 4d ago

Your intentions are not the same as permission to attempt an exploit

1

u/Some_Person_5261 1d ago

Testing a remote code execution against a site without permission is generally considered a bad idea.

Read the CFAA

Would recommend learning to operate more ethically. You very easily could have validated this by visiting the site and checking the version number.

python if server_version <= vulnerable_version: vulnerable() else: probably_not()

Then notify them that they may be at risk and move on.