Live data from Hacker News

Cyber Attackers Crash Muni Computer System Across SF

sanfrancisco.cbslocal.com

31–40 of 43 posts

Re: Cyber Attackers Crash Muni Computer System Across SF

#31
post #12

I am on the Citizen's Advisory Council for the SFMTA. I also happen to be specialize in computer security! I have asked SFMTA staff to have this item put on a committee agenda so we can get a full post mortem of what happened. It will likely be a few months before we get any real details. Since people are asking... The ticket kiosks run Win2k, the subway display screens run Flash (on Win2k I imagine), and the SFMuniC…

As another random fact, the screens in BART stations showing upcoming departures are ASP.Net websites. I once saw the generic error config page (At least I hope I am remembering correctly that it was the generic user facing error page).

[deleted]

Re: Cyber Attackers Crash Muni Computer System Across SF

#33
post #23
post #13

Earlier quoted context omitted.

Just because you think the message looks like it suggestions a Russian hacker doesn't mean that it isn't in fact Russian. Sometimes a cigar is just a cigar.

This is a personal opinion based on experience, speaking for myself alone, made with access only to public information. Take it for what you will.

I'm not sure how you could legitimately come to those conclusions based on on the publicly available information.

There's very little indicating the author is Russian, but considering that's legitimately how most eastern European and Russian hackers type it wouldn't be much of a stretch.

However I can't see how that leads to the conclusion that the author is trying to pretend to be Russian, as opposed to just being from Ukraine, Romania or Russia.

And unless I'm missing something, there's even less information about his OPSEC practices.

Re: Cyber Attackers Crash Muni Computer System Across SF

#34
post #7
post #3

Message is: “You Hacked, ALL Data Encrypted. Contact For Key(cryptom27@yandex.com)ID:681 ,Enter.”

From the text, it is pretty clear he wants people to think he's from Russia. From this I conclude two things: 1. He's not Russian. 2. This a good hacker but an amateur at OPSEC.

Googling the email address shows a few hits with other IDs, so at the very least this has gotten around a bit. (I haven't chased down the search hits, there may/may not be some leads as to what it is out there)

Re: Cyber Attackers Crash Muni Computer System Across SF

#35
Did a bit of quick digging, this article shows an actual (potato) photo: http://www.sfexaminer.com/hacked-appears-muni-stations-fare-...

Looks like it tinkered with the MBR, but I'm very curious as to why it's also saying "Missing operating system" under the message. Maybe the string is part of the replaced MBR for added effect?

Also, dupe thread with more comments: https://news.ycombinator.com/item?id=13050262 - maybe those comments could be moved over here.

Re: Cyber Attackers Crash Muni Computer System Across SF

#36

Earlier quoted context omitted.

Why is the response so slow? I mean why can't they just replace everything in the ticket kiosks and then restore the central system from a backup on new machines? 100% secure systems I understand are pipe dreams but at least the mitigation and response in case of failures and hacks should not be so long.

It's been what, 2 days, over a holiday weekend? Where do they get that many new computers and what does it cost, is that in the budget? Are they insured? Do they have the staff on hand to fix it? Do they even know what the fix actually is? If they rolled out a bunch of new hardware how would they know it wouldn't just get re-infected? Are you going to stomach a fare hike or increased taxes for a computer system swap…

Yes, I don't see why you equate MUNI with less technical competence than Yahoo, LinkedIn, etc. Yahoo and friends are not critical infrastructure. I expect more from critical infrastructure in terms of preparedness and response times to such failure modes.

Re: Cyber Attackers Crash Muni Computer System Across SF

#37

Earlier quoted context omitted.

he may not be so good. they could be using very old operating systems. I believe the NY subway is running OS2 and win xp.

[1] says Windows 2000, and whatever version of Flash ran on there, so...shooting fish in a barrel? [1] - https://news.ycombinator.com/item?id=13051310

The most secure voting machine certified in my county runs Android Jelly Bean from 2012. It's fish in barrels all the way down...

Re: Cyber Attackers Crash Muni Computer System Across SF

#38
post #37

Earlier quoted context omitted.

[1] says Windows 2000, and whatever version of Flash ran on there, so...shooting fish in a barrel? [1] - https://news.ycombinator.com/item?id=13051310

The most secure voting machine certified in my county runs Android Jelly Bean from 2012. It's fish in barrels all the way down...

As much fun as Android is, I don't _think_ there's any public RCEs that recent, while I can think of a couple of recent Windows XP+ RCEs that are probably also doable-but-unpatched on Win2k:

[1] - https://www.cvedetails.com/cve/CVE-2013-3175/

[2] - https://www.cvedetails.com/cve/CVE-2012-1852/

[3] - https://www.cvedetails.com/cve/CVE-2012-0173/

[4] - https://www.cvedetails.com/cve/CVE-2012-0002/

(Those were just the ones I quickly found that allow RCE on XP SP2 (the oldest thing that they still provided patches for, so most likely to be shared code with Win2k) without requiring active interaction on the target's behalf, e.g. not including "convince target to open X malformed file, receive payload")

Re: Cyber Attackers Crash Muni Computer System Across SF

#39
post #33
post #23

Earlier quoted context omitted.

This is a personal opinion based on experience, speaking for myself alone, made with access only to public information. Take it for what you will.

I'm not sure how you could legitimately come to those conclusions based on on the publicly available information. There's very little indicating the author is Russian, but considering that's legitimately how most eastern European and Russian hackers type it wouldn't be much of a stretch. However I can't see how that leads to the conclusion that the author is trying to pretend to be Russian, as opposed to just being f…

A few hints that tickle my spider sense:

1. Yandex is an email provider that is almost exclusively to the new Russian sphere of influence.

This is a the first thing that would jump out to an attribution analyst. Combined with the non-native language mistakes, a first pass analysis would indicate Russia.

But the name of the game is deception.

2. The "mistakes" in the text are not those which a Russian-speaker would make. The most obvious signal is leading space before the comma.

Re: Cyber Attackers Crash Muni Computer System Across SF

#40

Earlier quoted context omitted.

It's been what, 2 days, over a holiday weekend? Where do they get that many new computers and what does it cost, is that in the budget? Are they insured? Do they have the staff on hand to fix it? Do they even know what the fix actually is? If they rolled out a bunch of new hardware how would they know it wouldn't just get re-infected? Are you going to stomach a fare hike or increased taxes for a computer system swap…

Yes, I don't see why you equate MUNI with less technical competence than Yahoo, LinkedIn, etc. Yahoo and friends are not critical infrastructure. I expect more from critical infrastructure in terms of preparedness and response times to such failure modes.

I'm actually making no statement of technical competence but playing into the assumption of the GP. If he thinks muni is incompetent then they should take way longer than Y/L. In fact e's expecting them to be faster. In general GP wanted more than just about anyone who had expected this type of failure and had an active response with required 1-day SLA would be able to provide.
Post reply on HN