Information security specialist Alexey Sopov discovered a vulnerability in the Russian Railways network that allows access to the company’s cameras and electronic displays. about this He spoke on the Habr portal.
Sopov claims that he found an open proxy server on the Internet and decided to check where it was installed. The author points out that usually an open router is either a hacked device, or the owner forgot to disable this function.
Having discovered the vulnerability, Sopov decided to find the owner of the router to warn him. After scanning the VPN , according to the specialist, he discovered more than 20 thousand cameras. “There are a huge number of devices with factory passwords,” the author emphasizes.
Using footage from surveillance cameras, Sopov managed to find out that the owner of the network is Russian Railways. According to the specialist, using the vulnerability, he was able to gain access to cameras in the company’s offices and on platforms throughout Russia, to “something similar” to a monitoring system for the condition of building support systems, an air conditioning and ventilation control system, control systems for boards on platforms and other network equipment.
The author suggested that the vulnerability could have appeared due to an “initially bad team”: “The test was carried out by the same department that designed or maintains the system. By denying the problem, they either keep their jobs or pursue other goals.” Sopov added that the audit could have been carried out by an incompetent employee, or Russian Railways knows about the vulnerability, but does not want to admit it.
The specialist clarified that he is probably not the first to discover the vulnerability, since “there are a lot of signs that someone is ‘living’ on this network.”
Russian Railways announced that an investigation had been launched due to the publication. “We inform you that there was no leak of personal data of the holding’s clients, there is no threat to traffic safety,” the company assured.