The Panhellenic School Network SCH.GR was hacked by the Pøwerful Greek Army. During a pandemic and while the country's transition to the internet is being implemented at a rapid pace with excellent results so far, it seems that certain services of the Greek State are not prepared for such a major change. A typical example is the Panhellenic School Network SCH.GR, which to breach Greek hackers, according to anonymous information disclosed via email to SecNews.

Distance learning due to the Coronavirus is a life-saving solution for all educational institutions in Greece with the aim of not wasting this school year. Elementary schools, middle schools, high schools, universities and educational seminars have been transferred to "online classrooms" with students attending their classes via various platforms such as Zoom, Webex Cisco, Skype , etc.
The circumstances therefore require e-learning and teleworking. However, the Panhellenic School Network seems to have been unprepared for this major change. Like other Greek state online infrastructures (ed. fortunately not many), sch.gr had not done the required things regarding internet and online security.
The struggle to secure data and privacy on the internet is continuous and tiring, given that there are millions of malicious users waiting for a software weakness (bugs/exploit) to invade systems without being detected and steal sensitive personal information of users. In this specific case, as SecNews is able to know, data of teachers, students, administrators and users in general who had been registered in the sch.gr database were exposed.

The Greek hacking group called Pøwerful Greek Army contacted the editorial team of SecNews via an anonymous email where, after informing the editors about the data they have at their disposal, they stated the reasons they decided to infiltrate the Panhellenic School Network by violating the security systems, wishing to send their own message. Specifically, they told us that:

"We invaded the Panhellenic School Network to warn them! The level of online security of sch.gr is unacceptable. We are trying to point out the shortcomings and security gaps to them so that they comply and prevent any dangerous hacking attack by malicious users. Greek online systems must now erect a wall against online threats! Sensitive information of Greek citizens is at stake!"

According to EXCLUSIVE information sent by the hacking group under the name Pøwerful Greek Army, after being evaluated by the editorial team of SecNews, it was confirmed that unauthorized access was gained to sensitive serversbelongingto the infrastructure of the Panhellenic School Network of the Ministry of Education, Lifelong Learning and Religious Affairs. Pøwerful Greek Army is a group that has been involved in the past (since 2016) with its attacks as you can see [here] and [here]
It is worth noting that according to what the hackers reported, they exploited vulnerability SQL injection for the attack on SCH.GR.

The Panhellenic School Network SCH.GR
The Panhellenic School Network SCH.GR is the largest public network that interconnects all schools, teachers and a number of administrative services and supervised bodies of the Ministry. It also supports the administrative work of Education, as it provides e-government applications for the management of education, such as for example for the collection of data on student and teaching staff, for the planning and implementation of teacher recruitment and their payroll, for the distribution of books, etc.

What is SQL Injection?
SQL injection is a code injection techniqueused to attack data-driven applications in which malicious SQL commands are entered into an input field for execution. SQL injection exploits misconfiguration security vulnerabilities in an application's software. SQL injection is most commonly known as a means of attack against websites, but it can be used to attack any type of database.
SQL injection attacks allow hackers to compromise websites, stealing user and administrator credentials, to compromise existing data, to cause issues in all kinds of transactions, to allow the full disclosure of all stored data within an information system, to destroy data or make it unavailable by gaining administrator rights on the database server.

Attack Details
According to the analysis of the data provided to the editorial team of SecNews (and which we publish in redacted form to protect the infrastructure from possible attacks by other hackers), it was found that the attack was carried out using SQL Injection vulnerabilities which led to the additional extraction of data and information. The data and information extracted include personal data such as usernames, passwords, country of residence, street address, telephone number as well as other sensitive information stored in the system.SecNews, for reasons of protection of personal data that have been leaked, hides with a relevant black box data that can be exploited by malicious hackers.
Indicative photos that have been appropriately altered for privacy reasons are listed below:





The information anonymously shared with SecNews regarding the attack is available to the competent services, upon request.
Technical Details
From the analysis of the SecNews technical team: In the data sent and evaluated by our technical team, it was found that there are numerous weaknesses in multiple parameters of the websites that have not been fixed, which makes these areas of the website accessible to anyone with an average or low level of knowledge and the use of publicly available tools, which anyone can locate and use on the internet! Indeed, the data extracted is said to be many mb of data, with usernames/passwords/addresses and telephone numbers.

The responsible administrators of the Panhellenic School Network SCH.GRmust IMMEDIATELY check the websites that were targeted and take immediate action to repair and change all administrator passwords as well as repair any SQL Injection vulnerabilities that may be identified.
Furthermore, the extent to which personal data of teachers and professors of the Panhellenic School Network has been exposed must be properly investigated, since it is not clear the exact type of data that was obtained, nor the exact depth of the intrusion carried out by the hackers Pøwerful Greek Army.
Activating the relevant Web Application firewalls in combination with Intrusion Detection & Prevention Systems could perhaps be a first step in repelling such attacks.
Finally, the Personal Data Protection Authority should be immediately informed if the leak that has occurred concerns a large number of citizens, whose data was unknowingly exposed to the group of hackers.
From the SecNews Editorial Team:
We understand that there is concern among parents about whether children should continue to use the SCH.GR digital educational platform. The SecNews believes that there is no need to discontinue use of the platform, however, students should be more careful by following the following advice:
- Do not use the parent's email to use the platform but create their own personal email. Email use should always be personal whether it is done by an adult or a minor. Parents are likely to use their email for services and online banking accounts that may be at risk from careless use of email.
- Strengthen their password. As we have mentioned many times in the past, a strong password is the first line of defense against hackers. Therefore, it is necessary - especially after a hack - to change your password to a stronger one (special characters, uppercase and lowercase letters, numbers, etc.). We remind you that the same password should NOT be used on any other service. We use separate passwords for each online service.
- Do not remain logged into the online learning platform after completing the lesson. It is always necessary to log out of online accounts after using them.
- Do not share passwords with friends, especially through social networking sites (Facebook, Instagram, Twitter, etc.).
· Parents - especially of young students - should also maintain their child's access details (email and password) for security reasons.
· Parents should use parental controls at both the home network and device levels. This will help them discreetly monitor their children's activities for their safety.
We thank the anonymous Pøwerful Greek Army for the timely and accurate information.
SecNews provides objective and unbiased information to its readers. Below you will find the updates that have emerged regarding the news.
UPDATE 1 – 16.04.2020: According to a statement from a SecNews reader, it is reported that:
“In recent days, reports have been circulating on the Internet about a breach of the Panhellenic School Network (PSD) systems and the leakage of data that it maintains. We inform you that this is not the case.
From our investigation so far, it appears that the data mentioned in the publication regarding the attack does not come from the PSD user system, nor from the Databases of its services.
They come from an application of the educational community, which is hosted at the PSD, in the context of the hosting of websites provided by the PSD. The data that was leaked is old (from 2010-11).
The administrators of the application were informed about the issue so that they can act in accordance with the provisions provided.
The Panhellenic School Network assures its members that within the framework of the General Data Protection Regulation, which it applies, it follows all appropriate measures in order to safeguard the data it maintains.
On this occasion, We remind you to apply the good safety and security practices recommended by the Panhellenic School Network to its members, as listed on the page https://www.sch.gr/security"

