• Our new ticketing site is now live! Using either this or the original site (both powered by TrainSplit) helps support the running of the forum with every ticket purchase! Find out more and ask any questions/give us feedback in this thread!

Cyber attack at 19 major railway stations - WiFi hacked

Status
Not open for further replies.

Prime586

Member
Joined
26 May 2023
Messages
300
Location
Knowsley
Seems like a classic bit of hacktivism (aka "idiot ruins his life because he thinks he's saving the world"). Questions will be asked of Telent about why they didn't have a change control process in place to prevent exactly this.
From what I understand it's nothing to do with Telent, they are the system integrator for NR (their main role is to supply the network infrastructure, CCTV and SCADA-based station control systems). The public wifi rides over the hardware they supply and is subcontracted to Globalreach. It was Globareach's wifi logon page that was hacked, to display islamophobic messages about terrorism.
 
Sponsor Post - registered members do not see these adverts; click here to register, or click here to log in
R

RailUK Forums

Couru

Member
Joined
28 Feb 2023
Messages
66
Location
Basingstoke
By definition an admin account will have the permissions to change stuff.

There are various ways of controlling updates, such as independent code reviews which can be set as rules in any decent configuration/content management system, however those rules are set by an Admin account: they necessarily have to exist.
Admins still have to go through change controls, but I suppose you're right - if they're disgruntled and intending to break the law, they're not exactly gonna follow proper process. Still surprised they don't require dual confirmation for something as vital as the landing page though.

From what I understand it's nothing to do with Telent, they are the system integrator for NR (their main role is to supply the network infrastructure, CCTV and SCADA-based station control systems). The public wifi rides over the hardware they supply and is subcontracted to Globalreach. It was Globareach's wifi logon page that was hacked, to display islamophobic messages about terrorism.
Yes, my apologies. Questions will be asked of GlobalReach and their processes - surely admin access to national infrastructure would require a security check? - but I'm well aware that complacency is rife in my industry and the laws aren't keeping up.
 

Peter Mugridge

Veteran Member
Joined
8 Apr 2010
Messages
17,855
Location
Oakham
By definition an admin account will have the permissions to change stuff.

There are various ways of controlling updates, such as independent code reviews which can be set as rules in any decent configuration/content management system, however those rules are set by an Admin account: they necessarily have to exist.

Which leads to the question of how the admin account credentials came to be used maliciously: either a disgruntled (possibly former) employee or they have been compromised. And whether any second factor authentication (2FA) was in use: the sort of thing that sends you an email to confirm your identity. (Often the root admin account doesn't have 2FA as it may be needed to fix the 2FA!)

Will be interesting where this one goes. IMHO, more interesting than if it was a straight up hack.
It said on the BBC yesterday that the person they arrested worked for the information system provider; that at least answers the access questions.
 

Recessio

Established Member
Joined
4 Aug 2019
Messages
1,541
Location
London
SWR's station WiFi is unaffected at Guildford. Which is good, because despite the fact you can see at least signal masts from the station, and often have full signal, the 4G/5G never actually seems to work. So I'm glad SWR are there as a backup!
 

Joe Paxton

Established Member
Joined
12 Jan 2017
Messages
2,959
I take that to mean we should expect TfL issues to continue for another month and a bit at least)

I have no privileged information here, but it doesn't look very promising from what is in the public domain. No commitment to any sort of date for service restoration

Better not to promise something which many not be achievable.

My guess is that in time we'll learn significantly more details about the hack.
 

Baxenden Bank

Established Member
Joined
23 Oct 2013
Messages
4,759
I can't speak for IT systems but in other industries, a senior person with the right to access 'stuff' (and responsibility for that access if abused) will often give those log-in details to an underling to actually enter and retrieve stuff. Think bosses and their Personal Assistants for example.
 

JKF

Established Member
Joined
29 May 2019
Messages
1,329
I may be wrong but since we're all speculating ;) - the content of the message (basically conspiratorial great replacement right wing loony stuff) wasn't really something I'd think yer typical IT guy would either be stupid enough to do or indeed hold such views.

Base on that, I suspect more likely his or her credentials were breached. Still as I said I may be wrong about that!
tech nerds are all over far right conspiracy nonsense unfortunately - see Elon Musk as a prominent example. Young men and the terminally online are being radicalised. While the boots on the ground attacking mosques and refugees in hotels mostly comprise an assortment of thickos, the messages curated to get them to do this are provided by intelligent and well-off agitators.
 

Egg Centric

Established Member
Joined
6 Oct 2018
Messages
2,912
Location
Land of the Prince Bishops
tech nerds are all over far right conspiracy nonsense unfortunately - see Elon Musk as a prominent example. Young men and the terminally online are being radicalised. While the boots on the ground attacking mosques and refugees in hotels mostly comprise an assortment of thickos, the messages curated to get them to do this are provided by intelligent and well-off agitators.

Yah but you have to have an intersection between holding those beliefs, having this access, and being stupid enough to do this, pretty much guaranteeing imprisonment for no gain.

Being careless with security procedures / credentials / what have you on the other hand requires only being a daftie, and maybe not even that.

It'll come out in the wash anyway! Neither explanation would surprise me, I just think latter more likely
 

stwales

Member
Joined
25 Jun 2020
Messages
7
Location
wales
I think the query was less why it's being investigated per se, than why it's BTP doing the investigtion. Apart from anything else, I wouldn't have thought they'd have the officers with the specific knowledge needed to investigate this.
BTP had at least one officer who was totally capable of carrying out any digital forensic investigation required. Although this was back in 2009. I imagine his skills have advanced since then.
Do not assume people do not have other skills than that required by their job.

== Doublepost prevention - post automatically merged: ==

isn't it simply because it is railway infrastructure. I would assume they can call on the NCSC/GCHQ and other orgs just as the territorial police or NCA can.
do not assume the organisations named above are the best available, they may be good at providing someone for school prizegiving, or an interview for the bbc, but the best will remain discreet. i now of at least two government funded places that are better than those named above.
 
Last edited:

infobleep

On Moderation
Joined
27 Feb 2011
Messages
13,453
SWR's station WiFi is unaffected at Guildford. Which is good, because despite the fact you can see at least signal masts from the station, and often have full signal, the 4G/5G never actually seems to work. So I'm glad SWR are there as a backup!
I didn't know there was two WiFis at Guildford. Seems overkill.
 
Joined
21 May 2014
Messages
985
BTP had at least one officer who was totally capable of carrying out any digital forensic investigation required. Although this was back in 2009. I imagine his skills have advanced since then.
Do not assume people do not have other skills than that required by their job.

In addition, note that police forces employ the services of contractors to do Digital Forensic work, either in place of or in addition to their own capability. There are several very well established companies that can assist with this type of investigation.
 
Status
Not open for further replies.

Top