Cyber Attackers Crash Muni Computer System Across SF
sanfrancisco.cbslocal.com
sanfrancisco.cbslocal.com
Since people are asking...
The ticket kiosks run Win2k, the subway display screens run Flash (on Win2k I imagine), and the SFMuniCentral display is DOS under OS/2. For the latter, it might be running Linux now. The subway system is in the middle of a major modernization project since SF is going to open a new subway line with new cars in the next 18 months.
100% secure systems I understand are pipe dreams but at least the mitigation and response in case of failures and hacks should not be so long.
Are you going to stomach a fare hike or increased taxes for a computer system swap over to do an emergency computer replacement for the whole system (if it was even possible)?
You really expect MUNI to handle a breach better and faster than tech savvy organizations like Yahoo, LinkedIn, etc (in comparison to MUNI) who had breaches and didn't even let us know for months or years.
Sony, for example, had PSN down for almost 2 MONTHS while they determined the extent of the hack and fixed it back in 2011.
Also sounds like it's back up so I call myself impressed.
Internally, the SFMTA staff will do whatever their immediate work is to fix the hack.
Socialism. Not Swedish post capitalism, but the Soviet style, intolerant to dissent. Do you know that San Francisco has 10 billion dollar budget and over 30,000 city employees? And they want more.
http://www.sfchronicle.com/news/article/Muni-back-to-normal-...
That being said, some of the newer SFMTA projects do have a data stream to at least scrape, like road construction schedules, Muni Forward, and Vision Zero collision data. There is a whole lot more data available, most of it released quarterly, I could help get access too as well.
[1] http://www.sfmunicentral.com/sfmunicentral_Snapshot_Objects/...
[1] http://www.sfmunicentral.com/sfmunicentral_Snapshot_Objects/...
Looks like it tinkered with the MBR, but I'm very curious as to why it's also saying "Missing operating system" under the message. Maybe the string is part of the replaced MBR for added effect?
Also, dupe thread with more comments: https://news.ycombinator.com/item?id=13050262 - maybe those comments could be moved over here.
Does anyone know what the SFMTA runs on their kiosks?
Making life worse through technology, welcome to the future!
“You Hacked, ALL Data Encrypted. Contact For Key(cryptom27@yandex.com)ID:681 ,Enter.”
1. He's not Russian.
2. This a good hacker but an amateur at OPSEC.
Take it for what you will.
There's very little indicating the author is Russian, but considering that's legitimately how most eastern European and Russian hackers type it wouldn't be much of a stretch.
However I can't see how that leads to the conclusion that the author is trying to pretend to be Russian, as opposed to just being from Ukraine, Romania or Russia.
And unless I'm missing something, there's even less information about his OPSEC practices.
1. Yandex is an email provider that is almost exclusively to the new Russian sphere of influence.
This is a the first thing that would jump out to an attribution analyst. Combined with the non-native language mistakes, a first pass analysis would indicate Russia.
But the name of the game is deception.
2. The "mistakes" in the text are not those which a Russian-speaker would make. The most obvious signal is leading space before the comma.
[1] - https://www.cvedetails.com/cve/CVE-2013-3175/
[2] - https://www.cvedetails.com/cve/CVE-2012-1852/
[3] - https://www.cvedetails.com/cve/CVE-2012-0173/
[4] - https://www.cvedetails.com/cve/CVE-2012-0002/
(Those were just the ones I quickly found that allow RCE on XP SP2 (the oldest thing that they still provided patches for, so most likely to be shared code with Win2k) without requiring active interaction on the target's behalf, e.g. not including "convince target to open X malformed file, receive payload")
It's starting to bother me that the PA election officials keep saying that the voting machines aren't connected networked together, and that one would need 4,500 cards to compromise an election. It's just flatly false, since every county feeds into a central system such as Unity or GEMS, which themselves are provably insecure, and can be infected via the compact flash cards when they're collected. You would only need a few people in key counties to swing an entire election.
What I would give for the days of hanging chads...
http://www.sfexaminer.com/hacked-appears-muni-stations-fare-...