Packettracer.nl is a Dutch e-learning platform that has supported thousands of networking students over the past ten years. With 9,208 registered student accounts, 172,768 completed assignments, and an 80.9% active participation rate, the platform plays a meaningful role in practical IT education across the Netherlands.
The Challenge
A platform of this scale — with years of accumulated student data, automated result processing, and a high degree of trust from both educators and institutions — carries significant responsibility. The core question was not whether the platform worked, but whether it could be abused. Could the integrity of results be guaranteed? Could a student gain an unfair advantage through technical means? And what would happen to the reliability of ten years of educational data if those questions went unanswered?
The Approach
We conducted a technical analysis of the platform's application logic and data processing flows. Rather than focusing solely on traditional security vulnerabilities, we examined how the system handled trust: how results were submitted, validated, and stored. We mapped out scenarios in which the integrity of student outcomes could be undermined — not through brute force, but through a deeper understanding of how the application was designed to behave.
The Result
The analysis surfaced a number of scenarios that could affect the reliability and integrity of student results. These findings were responsibly disclosed to the platform owner, along with concrete recommendations to harden the underlying logic. The goal: ensuring that a decade's worth of educational data continues to mean what it's supposed to mean.
