I am on the Citizen's Advisory Council for the SFMTA. I also happen to be specialize in computer security! I have asked SFMTA staff to have this item put on a committee agenda so we can get a full post mortem of what happened. It will likely be a few months before we get any real details. Since people are asking... The ticket kiosks run Win2k, the subway display screens run Flash (on Win2k I imagine), and the SFMuniC…
As another random fact, the screens in BART stations showing upcoming departures are ASP.Net websites. I once saw the generic error config page (At least I hope I am remembering correctly that it was the generic user facing error page).
Cyber Attackers Crash Muni Computer System Across SF
31–40 of 43 posts
Re: Cyber Attackers Crash Muni Computer System Across SF
#32Re: Cyber Attackers Crash Muni Computer System Across SF
#33Earlier quoted context omitted.
Just because you think the message looks like it suggestions a Russian hacker doesn't mean that it isn't in fact Russian. Sometimes a cigar is just a cigar.
This is a personal opinion based on experience, speaking for myself alone, made with access only to public information. Take it for what you will.
There's very little indicating the author is Russian, but considering that's legitimately how most eastern European and Russian hackers type it wouldn't be much of a stretch.
However I can't see how that leads to the conclusion that the author is trying to pretend to be Russian, as opposed to just being from Ukraine, Romania or Russia.
And unless I'm missing something, there's even less information about his OPSEC practices.
Re: Cyber Attackers Crash Muni Computer System Across SF
#34Message is: “You Hacked, ALL Data Encrypted. Contact For Key(cryptom27@yandex.com)ID:681 ,Enter.”
From the text, it is pretty clear he wants people to think he's from Russia. From this I conclude two things: 1. He's not Russian. 2. This a good hacker but an amateur at OPSEC.
Re: Cyber Attackers Crash Muni Computer System Across SF
#35Looks like it tinkered with the MBR, but I'm very curious as to why it's also saying "Missing operating system" under the message. Maybe the string is part of the replaced MBR for added effect?
Also, dupe thread with more comments: https://news.ycombinator.com/item?id=13050262 - maybe those comments could be moved over here.
Re: Cyber Attackers Crash Muni Computer System Across SF
#36Earlier quoted context omitted.
Why is the response so slow? I mean why can't they just replace everything in the ticket kiosks and then restore the central system from a backup on new machines? 100% secure systems I understand are pipe dreams but at least the mitigation and response in case of failures and hacks should not be so long.
It's been what, 2 days, over a holiday weekend? Where do they get that many new computers and what does it cost, is that in the budget? Are they insured? Do they have the staff on hand to fix it? Do they even know what the fix actually is? If they rolled out a bunch of new hardware how would they know it wouldn't just get re-infected? Are you going to stomach a fare hike or increased taxes for a computer system swap…
Re: Cyber Attackers Crash Muni Computer System Across SF
#37Earlier quoted context omitted.
he may not be so good. they could be using very old operating systems. I believe the NY subway is running OS2 and win xp.
[1] says Windows 2000, and whatever version of Flash ran on there, so...shooting fish in a barrel? [1] - https://news.ycombinator.com/item?id=13051310
Re: Cyber Attackers Crash Muni Computer System Across SF
#38Earlier quoted context omitted.
[1] says Windows 2000, and whatever version of Flash ran on there, so...shooting fish in a barrel? [1] - https://news.ycombinator.com/item?id=13051310
The most secure voting machine certified in my county runs Android Jelly Bean from 2012. It's fish in barrels all the way down...
[1] - https://www.cvedetails.com/cve/CVE-2013-3175/
[2] - https://www.cvedetails.com/cve/CVE-2012-1852/
[3] - https://www.cvedetails.com/cve/CVE-2012-0173/
[4] - https://www.cvedetails.com/cve/CVE-2012-0002/
(Those were just the ones I quickly found that allow RCE on XP SP2 (the oldest thing that they still provided patches for, so most likely to be shared code with Win2k) without requiring active interaction on the target's behalf, e.g. not including "convince target to open X malformed file, receive payload")
Re: Cyber Attackers Crash Muni Computer System Across SF
#39Earlier quoted context omitted.
This is a personal opinion based on experience, speaking for myself alone, made with access only to public information. Take it for what you will.
I'm not sure how you could legitimately come to those conclusions based on on the publicly available information. There's very little indicating the author is Russian, but considering that's legitimately how most eastern European and Russian hackers type it wouldn't be much of a stretch. However I can't see how that leads to the conclusion that the author is trying to pretend to be Russian, as opposed to just being f…
1. Yandex is an email provider that is almost exclusively to the new Russian sphere of influence.
This is a the first thing that would jump out to an attribution analyst. Combined with the non-native language mistakes, a first pass analysis would indicate Russia.
But the name of the game is deception.
2. The "mistakes" in the text are not those which a Russian-speaker would make. The most obvious signal is leading space before the comma.
Re: Cyber Attackers Crash Muni Computer System Across SF
#40Earlier quoted context omitted.
It's been what, 2 days, over a holiday weekend? Where do they get that many new computers and what does it cost, is that in the budget? Are they insured? Do they have the staff on hand to fix it? Do they even know what the fix actually is? If they rolled out a bunch of new hardware how would they know it wouldn't just get re-infected? Are you going to stomach a fare hike or increased taxes for a computer system swap…
Yes, I don't see why you equate MUNI with less technical competence than Yahoo, LinkedIn, etc. Yahoo and friends are not critical infrastructure. I expect more from critical infrastructure in terms of preparedness and response times to such failure modes.