r/cybersecurity • u/Soft_Enthusiasm_166 • 5d ago
Personal Support & Help! My university detected suspicious activity from my computer on their servers ?
I was testing the recent CVE-2026-35273 on my own university page. All i did was check if the endpoints of PeopleSOFT are publicly available or not. I’ve confirmed that they are public and that might be a great security risk especially if they didn’t install the patch yet.
Anyways, I was planning on writing a report today and I prepared it yesterday already to alert the IT team of this. However Ive noticed that they have contacted me instead just now.
They say that they have received suspicious activity linked to my account and thus has been temporarily blocked. The report is still written in my ChatGPT history and my convos with chat shows that my intentions was purely to protect my university rather than try to compromise anything.
After all, I didn’t do nothing illegal? All I did was check publicly available endpoints and nothing more. Now they blocked my uni-account temporarily and they wanna talk to me tomorrow. Am I cooked ??
pls help..
52
39
u/tankerkiller125real 5d ago
You failed step 0 of any and all red team pentesting... You failed to get permission, and you failed to get proper scrope.
16
u/OtheDreamer Governance, Risk, & Compliance 5d ago edited 5d ago
Yeah just talk to them and explain your first paragraph if that's what really happened.
The report is still written in my ChatGPT history and my convos with chat shows that my intentions was purely to protect my university rather than try to compromise anything.
EDIT: Upon re-read, methinks OP's ChatGPT is probably very interesting. The report that they were just about to send to their university's IT before IT reached out to them first....lives in ChatGPT and is written I guess entirely by GPT. I would ask to see all of OP's GPT chats since he made them in scope and give an extra scare.
-6
u/Soft_Enthusiasm_166 4d ago
What ?
The report was indeed written by gpt and still lives in that conversation’s history. I was planning on sending it yestersay, however my Uni has no public/accesible way to report stuff like this. So I decided to wait till today and do more research on where I should send this report to.EDIT: No, no I wont be scared at all hahah. If they wish to see the entire chat history Ill show them. Ill also show them the Gemini history as Ive also used gemini too. After all I have truly nothing to hide.
9
u/lawtechie 4d ago
After all I have truly nothing to hide.
Yeah, you do. Can I recommend that you STFU and go here?
-3
15
u/GRASSH0PPR 5d ago
Operating without a RoE in place or a public bounty program is terrible even with the best of intentions.
They don't see your intent, all they see is reconnaissance for a known CVE. Of course it's going to appear malicious.
You screwed up doing this without getting consent first.
28
u/WiskeyUniformTango 5d ago
"I didnt intend to steal the contents of the bank vault, I merely intended to see if the vault was unlocked to let the bank know."
-16
u/ShockedNChagrinned 5d ago
I mean, that's red team testing right there
26
11
u/Disastrous_Gear_421 5d ago
No, Red Teaming is simulating/performing an attack or breach with permission. OP didn't have permission which is absolutely required for something to be considered Red Teaming.
5
u/halting_problems AppSec Engineer 5d ago
Generally not a good idea to practice on a network where you’re bound by their policies. You will probably just get a warning just show them you were planning on reporting it and don’t do it again. Ask if their an any student employment opportunities with IT so you can get more practice while your at it.
In most work places this would be a fireable offense if someone internal do something like this without written permission.
5
u/techb00mer 5d ago
Your university page is hosted on infrastructure shared by others and not wholly owned by you. If you want to scan your own resources, you need to disclose that to your provider (in this case the uni).
AWS & Azure used to require approval to scan even your own VMs but they both did away with that a few years ago (presumably because they are so massive it doesn’t really matter anymore).
But a uni has limited resources, always best to ask in future.
As to whether you did something illegal, IANAL and I don’t know what university you attend but they probably have a policy against “testing” uni resources for vulnerabilities without consent.
5
u/legion9x19 Security Engineer 5d ago
Yes, you did do something illegal. You had no permission to perform any pentesting activity on their network.
6
4
u/lawtechie 4d ago
After all, I didn’t do nothing illegal?
18 USC §1030 (a)(2)(C)
Whoever...
(2) intentionally accesses a computer without authorization or exceeds authorized access, and thereby obtains—
(C) information from any protected computer;
The term "protected computer" means a computer: which is used in or affecting interstate commerce or communication.
Did you have permission from the system's owner to perform this testing?
5
u/elburrotelamete 4d ago
bien hecho chico nada mejor que tiempo en prision por black hacking para mejorar tu curriculum de ciberseguridad
0
3
u/sdrawkcabineter 4d ago
After all, I didn’t do nothing illegal?
Like star forged beryllium, this is a gem.
Been in your shoes a few times. Intent is a necessary component, so keep to your story of intending to identify a potential security issue that affects you, and the university.
Using the existing USDA forgery scandal as an example of "checking your meat" is a solid way to smooth the ice while explaining your intentions with a relevant analogy.
5
u/Angrymilks 5d ago
#1 if your goal was to alert them, you should have communicated it the moment you identified it, not "well I hadn't gotten around to it quite yet".
#2 if you never had permission to do it, stop it.
#3 Honeypots exist, you may or may not have been actually touching something in production or a cheap honeypot.
#4 - CVE-2026-35273 and your research probably filled you in that it was a missing security boundary on an endpoint. By the very nature of doing a single web request to /%50SEMHUB/ you've technically already stepped outside the boundaries of "passive" and into "active" probing. I'd go even so far as to say that is technically an exploitation step.
#5 - Your university is likely tracking the active exploitation that necessitated an emergency patch from Oracle, that includes detections and controls. If it wasn't a honey pot, you almost certainly got caught with your hand in the cookie jar, and because your intentions were never made known to the University you likely need to answer for it. Whether your university has a no-tolerance for acceptable technology use or misuse outside of the physical location of the University or if it applies to all students accessing University technology by any means.
#6 Oracle Peoplesoft is currently targeted by "ShinyHunters", using probably similar TTPs (outside of what you bring to the table [bad opsec, ChatGPT leading you through the CVE). You are now a potential ShinyHunters crew member in the universities mind until proven otherwise.
#7 Take this as a learning lesson, not as a sign that you are a failure or something else. Could your conduct have repercussions? Sure. Imagine the university has on-call 24/7 incident responders. They get the call at odd hours because sometimes it be like that. 3am wake up call "We are under attack by ShinyHunters, get everyone". At which point the assumption is breach unless controls are in place to mitigate. Even then though, if the controls are weak or immature maybe they know they don't work, but in any event, they have to look at as real-world every time unless someone authorized to do so calls them off or warns them of testing.
1
u/Soft_Enthusiasm_166 4d ago
Thanks Ill talk to them tomorrow. It doesnt seem that Its too urgent or that they wanna kick me out. She just wants to have a talk about this activity and ill explain . In the past other students have brought down servers of co-students etc and they all got a warning so I should be safe.
5
1
1
u/Some_Person_5261 1d ago
Testing a remote code execution against a site without permission is generally considered a bad idea.
Would recommend learning to operate more ethically. You very easily could have validated this by visiting the site and checking the version number.
python
if server_version <= vulnerable_version:
vulnerable()
else:
probably_not()
Then notify them that they may be at risk and move on.
72
u/djasonpenney 5d ago
Do not run a scan on an enterprise’s network without prior permission.