WeSearch

We Hacked Our Way to Free 4.0s and Took over a UWaterloo and UofT Grading Tool

·9 min read · 0 reactions · 0 comments · 14 views
#education#cybersecurity#vulnerabilities
We Hacked Our Way to Free 4.0s and Took over a UWaterloo and UofT Grading Tool
⚡ TL;DR · AI summary

A group of students discovered vulnerabilities in the MarkUs grading tool used at the University of Toronto and the University of Waterloo. They found that students could access other submissions and potentially exploit grades through cross-site scripting (XSS) attacks. The students responsibly disclosed these issues to the MarkUs team without using them for personal gain.

Key facts
Original article
xtra
Read full at xtra →
Opening excerpt (first ~120 words) tap to expand

First, I’ll explain what MarkUs is and why we went after it. Then I’ll walk through how a student account could view other students’ submissions, how we could get 100s on assignments/tests, and finally how we escalated to RCE. I’ll also cover a few other vulnerabilities we found along the way. Important note: We responsibly disclosed these issues to the MarkUs team and did not use them for academic or personal gain or to affect anyone’s grades. introduction what is MarkUs? MarkUs is a web app used for submitting and grading assignments. It helps students submit work, join groups, and view feedback, while TAs and instructors can grade, comment, manage groups, and release marks. It is used for almost all computer science courses at the University of Toronto and the University of Waterloo.

Excerpt limited to ~120 words for fair-use compliance. The full article is at xtra.

Anonymous · no account needed
Share 𝕏 Facebook Reddit LinkedIn Threads WhatsApp Bluesky Mastodon Email

Discussion

0 comments

More from xtra