• Our new ticketing site is now live! Using either this or the original site (both powered by TrainSplit) helps support the running of the forum with every ticket purchase! Find out more and ask any questions/give us feedback in this thread!

18-year-old arrested for reporting bug in new Budapest e-ticket system

Status
Not open for further replies.

U-Bahnfreund

Member
Joined
6 Feb 2015
Messages
559
Location
Germany
The Budapesti Közlekedési Központ (BKK) recently introduced a new e-ticketing system, but unfortunately it is full of bugs. Passwords are stored as blank text, you can easily hack into other users’ accounts (complete with personal data etc.) by manipulating the url, the admin password for the system is ‘adminadmin’, tickets can be copied and used by multiple persons, but most alarmlingy, it is possible to change the price of a ticket through the brower’s developer tools.

A 18-year-old has found this by changing the price for a monthtly pass for BKK’s system from 9500 Ft (~ £27) to 50 Ft (~ £0.15). He didn’t use the ticket, but quickly reported the bug to BKK, but a few days later, he was arrested by the police for hacking into the system (he was released the same day).

Protest arose in Budapest, BKK’s and T-System’s (the software partner of BKK) Facebook pages have been flooded with negative ratings...

More details:
https://blog.marai.me/2017/07/24/18-year-old-arrested-bkk-tsystems-e-ticket/ (Detailed blog post)
https://www.theregister.co.uk/2017/07/25/hungarian_teenager_arrest_sparks_protests/ (one of many news reports)
 
Sponsor Post - registered members do not see these adverts; click here to register, or click here to log in
R

RailUK Forums

NSEFAN

Established Member
Joined
17 Jun 2007
Messages
3,518
Location
Southampton
What an awful way to repay someone who was being ethical and could have saved them a fortune in fraudulent tickets.

Of course, having had him arrested has now drawn media attention to the new system's faults, only encouraging dishonest people to use them and look for more problems (of which I'm sure there will be plenty, given the IT company seems to think it's okay to have passwords in plaintext! :roll:)
 
Status
Not open for further replies.

Top