We had an interesting incident with the blog this week. I got home on Tuesday to a decidedly annoyed Beth who almost as soon as I walked through the door asked me to read a printout of a comment to a pretty old posting on the blog. The posting contained a couple of pictures of Beth’s classroom which she had posted so that friends in Canada could see where she worked.
The content of the posting was, shall we say, interesting, and was posted under the name of someone who Beth had taught previously. Thanks to the fact that WordPress logs the IP address for anyone who comments we knew that it had been posted from the school, as the IP address was the schools web proxy. On top of that we had a time for the posting too, putting it during the final lesson on Tuesday. However based on the content it was more than likely not going to be the kind of thing that someone would put their real name to, it seemed to be much more of a prank posting. I pretty quickly worked out how they had found the site. It turns out that if you put the name of the school into Google, the posting which was commented on comes up as seventh in the list, so what appears to have happened was that someone was looking up pages on the school, and came across ours. I pretty quickly took steps to ensure that the next time Google indexes our site, the posting should be removed, although that can take a number of days to filter through, so I’ve also put a block on any access from the school network too. The one remaining thing that I couldn’t do from home, was track down exactly who posted the comment.
As an aside, looking back to the couple of months I worked at the school a few years ago, one of the things that struck me most was really how naive some of the pupils were when it came to the computer systems. Essentially, like the systems at most organisations, the school keeps track of and filters all the e-mails sent and received, sites accessed, files downloaded and so on. Just like IT in any big organisation, the biggest risk to the systems is the users themselves, and during the time I was there we had everything from a sixth-former with a porn collection ‘hidden’ in his area on the server, to regular installs of the spyware loaded delights of the latest P2P software, plus a good few pupils who used the school broadband connection to grab the latest warez from the internet. Of course all of this stuff is logged to ensure that the school stays on the right side of the law, and keeps it’s pupils safe on the internet. Suffice to say I really don’t think that the average pupil realises that though their teacher may not have noticed what they are doing, the server always notices!
Going back to the events of this week, on Wednesday, Beth took the details of the comment up to the current IT admins, who said they would track through the relevant logs. She also talked to various of her colleagues about it, one of whom said that she had heard a group of boys, one of whom was the name on the comment, discussing ‘Mr’s Peat’s Website’ at one point earlier in the day.
Anyway, by yesterday, the IT admin pulled out the relevant bit of the logs, complete with the account name of the pupil who had posted the comment, and another who had been accessing the site, both of whom had been in an IT lesson at the time – and as expected neither of them the name on the comment. Essentially it seems like it was a prank to try and get the other student in to trouble.
Armed with a copy of the logs, and the comment, Beth went and had a chat with one of the deputy heads, who pretty near exploded having read the content of the comment, and immediately summoned both young gentlemen to his office. Needless to say neither of them had any idea that all their internet access was logged, and apparently the face of the young gentleman responsible for the comment was an absolute picture when he was faced with a copy of the comment, the time he made the posting, plus a list of all the other sites he accessed that he shouldn’t have been using. Both were suspended for the day today for ‘misuse of the Internet, and ‘vulgar behaviour towards a member of staff’, had to apologise to Beth, and of course had to face their parents with what they had done, and the content of the comment. Put it this way, I know what my mother would have done if I had written what they did…
So the moral of the story is to always remember that whatever you do, and wherever you go on the internet, someone, somewhere is logging it. Whether that be your school, your employer, your ISP, or even the websites you access (this one included), they are all collecting data about what you do, where you came from, and where you go. Just take a look at the 7000 suspects and 1200 convictions as a result of Operation Ore, or the recent debate over the search records held by Google.
For example, looking at the kind of information my ISP logs for this site, the most popular posting since the beginning of the month has been my review of the new series of Rock School, although not far behind is this blog entry about the headlight bulb on the Focus. Most people come to the site either directly, or from a Google search, and not surprisingly from the most popular pages, the top search terms include ‘Rock School’ and ‘How to change a Ford Focus Headlamp bulb’. Looking at the location of the people who read the site, the biggest group is from US commercial hosts, followed by hosts in the UK, then Canada. Looking further down the list we’ve also had visits from as far afield as Japan, Saudi Arabia, Singapore, Tonga and Venezuela! Of course all of this comes from the basic list of everybody who has accessed the site and when, which is exactly how we were able to trace the source of the comment.
Incidentally, having found the source of the comment, and received an apology, Beth has definitely reached the point of being able to see the funny side of the whole thing now.




