Campus Cards, College and University Identification and Security
CBORD: Securing buildings, transactions, and the bottom line. www.cbord.com

Carleton University not exactly hacked

Wednesday, October 15, 2008

Carleton University made headlines last month because a student hacked the campus card system and was able to collect some students’ personal information. But this wasn’t the whole story, says Kathleen Kelly, campus card coordinator at the Ottawa, Ontario university.

“I would use the term ‘hacked’ loosely,” says Kelly, also president and chair of the Corporate Relations Committee at the National Association of Campus Card Users. The student was able to access students’ personal information, but he didn’t break into the campus card system.

The student installed software on a print station in a computer lab at Carleton and was able to capture information off the magnetic stripe of some student IDs, Kelly says. In the university’s computer labs there are print stations equipped with magnetic stripe readers. After a student prints out a job, he goes to the stations, logs-in with user ID and password, swipes his ID and authorizes the job to print.


On another PC in the computer lab the hacker installed key-logging software to capture the students’ login and password information. From there the student was able to connect the login information with the data from the mag stripe, Kelly says.

After collecting the student information he sent a report to university officials with the names and data of the 32 students whose information he collected, Kelly says. From that report, university officials were able to figure out what the students had in common and where the information came from. Nothing illicit was done with the stolen student information.

The mag stripe on the campus card can be used to pay for laundry, printing and small purchases at the university, Kelly says. There is a $12 daily spend limit on the card for vending machine or unattended purchases. The card is also used for physical access to two of the residence halls.

The 32 students impacted had new cards issued and had to change their user names and passwords, Kelly says. Also, because of the incident the university has locked down all print stations preventing new software from being installed on the machines.

The student, Mansour Moufid, sent the information to university officials under a false name, according to news reports. He was charged with mischief to data and unauthorized use of a computer. The penalties for the charges range from fines to jail time. The student also voluntarily left Carleton. [end] 

An UConn computer with the names and Social Security Numbers of more than 10,000 university applicants was stolen, according to a local news report.

The computer, stolen from an IT storage cabinet at university’s West Hartford campus, had applicant files ranging from 2004 through July 30. UConn officials are still investigating the theft, which was discovered on Aug. 3.

read more »

The CBORD Group announced that its customer, Carleton University was honored with two awards at the National Association of Campus Card Users conference last month - one awarded to the university as a whole, and one to its Campus Card Manager, Kathleen Kelly.

read more »

H Security reports that Kobil’s smart card readers have been hacked with a Windows tool and unsigned firmware, granting thieves access to PINs and other secure data.

read more »

Loyola University, Chicago, is offering more buying power for its students through the campus card program, allowing them for the first time to take the card off-campus at local dining establishments. The program will start small, focusing on a handful of restaurants.

read more »

University Business Magazine and Higher One are honoring seven colleges and universities in their summer 2010 Models of Efficiency program, to honor institutions of higher learning that meet the education business and technology challenges of today’s campuses.

read more »

Three Auburn University students aren’t thrilled with the school’s mandatory meal plan. They’re so “not thrilled” that they’ve filed suit against the university, claiming the plan violates restraint of trade and Alabama law.

read more »

Cardsmith