• Our new ticketing site is now live! Using either this or the original site (both powered by TrainSplit) helps support the running of the forum with every ticket purchase! Find out more and ask any questions/give us feedback in this thread!

Fake ticket scam using stolen machine

Status
Not open for further replies.

Hyphen

Member
Joined
17 Oct 2011
Messages
504
Location
Swansea (previously Nottingham/Sheffield)
I would guess that they were using the Avantix hardware but with their own software, as they won't have been able to get into the operating system they come with. This would be consistent with them buying tickets to clone the magnetic strip wholesale, rather than attempting to reverse engineer it.

I know the Windows Mobile that Avantix uses is fairly well locked down from the onboard user interface point of view (primarily done to stop guards from installing things or going into its Control Panel and messing around), but I'd be surprised if it was that heavily protected against offboard attacks, given the unlikelihood of (legitimate) users wanting to plug them into PCs.

WinMo was a great OS in its day, but like Windows XP now - the security model baked in doesn't quite cut it any more. Recalling back to my days of owning WinMo phones, the OS by default talks quite happily to any PC it finds over ActiveSync, and there's quite a lot of scope for retrieving data, installing and running applications and modifying system settings from the appropriate developer kit.

Android (I can't speak for iOS) does much the same if the correct options for USB debugging and installing unsigned software are enabled - but these are turned off by default.

That saaaaid, the above is probably well beyond the skills and knowhow of a bunch of ticket cloners.

EDIT: too slow typing, cjmillsnun beat me to it!
 
Last edited:
Sponsor Post - registered members do not see these adverts; click here to register, or click here to log in
R

RailUK Forums

Mojo

Forum Staff
Staff Member
Administrator
Joined
7 Aug 2005
Messages
21,172
Location
0035
15,000 weeklies over a twenty-one month period implies that they had hundreds of punters willing to buy these tickets - does anyone know what they were charging end-users?
Of those who admitted to paying money for them - I'd estimate 95% of people claimed to have paid £30 for them, the remaining 5% claimed to have paid £35. The 2013 1-6 Weekly was £55.60.
 

PermitToTravel

Established Member
Joined
21 Dec 2011
Messages
3,042
Location
Groningen
Sorry, slack use of terminology! By operating system I did indeed mean the kiosk the railways have installed for ticketing. It can definitely be bypassed to boot into the system very easily (and play with printers, magnetic strip programmers, chip and PIN readers, etc). I agree that the software would probably not stand up to a competent hacker, though these people were probably not, as Hyphen notes!
 

island

Veteran Member
Joined
30 Dec 2010
Messages
17,908
Location
0036
Would I be correct in saying that an Avantix-issued ticket longer than a weekly would attract suspicion? Do Avantix-issued tickets look noticeably different from those from booking offices?

Yes, the font is distinctive.
 

Flamingo

Established Member
Joined
26 Apr 2010
Messages
6,806
Although the information is out there I'm sure, can we avoid this thread becoming an "How to do it" guide for any more would-be Blue Peter types trying to make one for themselves? :D

Think before posting! :lol:
 

RichardN

Member
Joined
29 Nov 2013
Messages
430
I think it is probably time to call time on the magstripe ticket if it really is unencrypted and there is no uuid that can be tracked and cancelled if tickets are detected doing impossible things...
 

infobleep

On Moderation
Joined
27 Feb 2011
Messages
13,451
It's time will come with the smart card roll out. That takes time. Saying that South West Trains have had some smart card readers for sometime but I never hear much publicity from them about them these days. Even if I did, I find paper tickets more flexible when it comes to combining multiple tickets. With a smart card I think you have to touch out at the end and probably touch in your next ticket.

Sent from my Nexus 5 using Tapatalk
 

Tibbs

Member
Joined
22 Aug 2012
Messages
894
Location
London
It's time will come with the smart card roll out. That takes time. Saying that South West Trains have had some smart card readers for sometime but I never hear much publicity from them about them these days. Even if I did, I find paper tickets more flexible when it comes to combining multiple tickets. With a smart card I think you have to touch out at the end and probably touch in your next ticket.

Sent from my Nexus 5 using Tapatalk

There were oyster-type smart card readers at Datchet when I first moved there about 5 years ago. Never saw them in use though.
 

talltim

Established Member
Joined
17 Jan 2010
Messages
2,454
Sorry, slack use of terminology! By operating system I did indeed mean the kiosk the railways have installed for ticketing. It can definitely be bypassed to boot into the system very easily (and play with printers, magnetic strip programmers, chip and PIN readers, etc). I agree that the software would probably not stand up to a competent hacker, though these people were probably not, as Hyphen notes!

Not sure why people think they were unlikely to be competent hacker?
 

jon0844

Veteran Member
Joined
1 Feb 2009
Messages
30,865
Location
UK
I doubt you'd need to be a competent hacker, any more than a journalist could 'hack' voicemail by knowing the default PIN.

I suspect it would be pretty easy for anyone to do this, especially given someone figured you didn't need to hack any code to work out how to encode a ticket - just make multiple clones of a genuine one.

I'd say I'm surprised nobody thought of this before, but most likely they did, and have, and are.

I guess the key to sorting this (before replacing paper tickets) is to have people seeking to buy such tickets and then chucking those involved in jail. I wonder how seriously the TOCs and the authorities take it?
 

Geronimo

Member
Joined
17 Apr 2014
Messages
45
Location
north north west of Betelgeuse
I doubt you'd need to be a competent hacker, any more than a journalist could 'hack' voicemail by knowing the default PIN.

I suspect it would be pretty easy for anyone to do this, especially given someone figured you didn't need to hack any code to work out how to encode a ticket - just make multiple clones of a genuine one.

I'd say I'm surprised nobody thought of this before, but most likely they did, and have, and are.

I guess the key to sorting this (before replacing paper tickets) is to have people seeking to buy such tickets and then chucking those involved in jail. I wonder how seriously the TOCs and the authorities take it?

OK, it's probably relatively easy to modify a mag-strip reader-encoder to treat rail-tickets, whether by cloning, or by understanding the format. Fine.
Still leaves the pretty difficult problem of either procuring blank tickets, or of printing fake ones (inc. the mag stripe!). Not trivial.

Then what? Either it's done for personal travel by a band of "skilled" commuters in which case it's likely to be limited in scale, or it's done for resale by a gang of crooks, and it's bound to be detected sooner or later by standard approaches.

So it's not very serious, and I would be surprised if the TOCs did take it very seriously, law of diminishing returns and all that. Heck, revenue protection is probably making enough losses already (still, I understand the necessity to keep fare evasion below a certain threshold to prevent extra losses, non-linear effects, etc ...).
 

b0b

Established Member
Joined
25 Jan 2010
Messages
1,371
I think it is probably time to call time on the magstripe ticket if it really is unencrypted and there is no uuid that can be tracked and cancelled if tickets are detected doing impossible things...

I think thats what has prompted the '2D barcode' on the ticket redesigns out there.
 

swt_passenger

Veteran Member
Joined
7 Apr 2010
Messages
34,252
There were oyster-type smart card readers at Datchet when I first moved there about 5 years ago. Never saw them in use though.

They are 'ITSO type', not Oyster, and have been live since some time in 2008 for the small number of people with seasons valid between stations from Staines to Windsor, who are part of SWT's 'Smart' trial. There are other trial areas, such as the main line west of Woking as far as Weymouth IIRC.

They've never been extended within the zones, because all the readers there (although similar to look at) are connected to the Oyster system. SWT were led into the ITSO system by DfT on the basis that TfL would become ITSO compatible by about 2010...
 

Ediswan

Established Member
Joined
15 Nov 2012
Messages
3,418
Location
Stevenage
Probably the Advantix was stolen to use the printer/strip encoder module (mainly because the magstrip on a railway ticket is in an unsual position (the centre of the card rather than at the top edge like on a credit card).

I have always believed/assumed the centre stripe was to allow the readers to work with a single read head whichever end of the ticket is inserted first. Mechanically modifying a standard card writer to reach the stripe on a ticket would not be difficult. Conclusion: there are more subtle differences to the ticket stripes than their position (or the thieves made hard work of it).
 

DownSouth

Established Member
Joined
10 Dec 2011
Messages
1,545
I have always believed/assumed the centre stripe was to allow the readers to work with a single read head whichever end of the ticket is inserted first. Mechanically modifying a standard card writer to reach the stripe on a ticket would not be difficult. Conclusion: there are more subtle differences to the ticket stripes than their position (or the thieves made hard work of it).
The Crouzet-designed tickets we have in Adelaide have a central magnetic strip for this same reason.

It's not a great issue for the design of the ticket readers, the head would be exactly the same except for where it's screwed into place during assembly.
 

infobleep

On Moderation
Joined
27 Feb 2011
Messages
13,451
They are 'ITSO type', not Oyster, and have been live since some time in 2008 for the small number of people with seasons valid between stations from Staines to Windsor, who are part of SWT's 'Smart' trial. There are other trial areas, such as the main line west of Woking as far as Weymouth IIRC.

They've never been extended within the zones, because all the readers there (although similar to look at) are connected to the Oyster system. SWT were led into the ITSO system by DfT on the basis that TfL would become ITSO compatible by about 2010...

Southern appear to be rolling it out even though Oyster is it compatible. Surprised SWT didn't just carry on regardless.

Sent from my Nexus 5 using Tapatalk
 

cjmillsnun

Established Member
Joined
13 Feb 2011
Messages
3,275
Ticket stock probably isn't an issue. Lots of avantix stock is kept very insecurely around the network. Not all guards and revenue staff are conscientious. The fraudsters may even have had somebody on the inside, a cleaner maybe, able to pinch stock from a ticket office or guards bag.

OK, it's probably relatively easy to modify a mag-strip reader-encoder to treat rail-tickets, whether by cloning, or by understanding the format. Fine.
Still leaves the pretty difficult problem of either procuring blank tickets, or of printing fake ones (inc. the mag stripe!). Not trivial.

See above...
 

anme

Established Member
Joined
8 Aug 2013
Messages
1,777
Smart card technology might not be the solution everyone expects it to be:

http://nakedsecurity.sophos.com/2012/09/24/android-nfc-hack-lets-subway-riders-evade-fares/

Well, smart card technology is not perfect, but if done in a reasonably competent manner it should be more secure than paper and magnetic strips. The vulnerability described in the link is found in a specific type of disposable card, and appears to be simple to fix without changing the cards (although the article doesn't make a lot of sense to me - if the one way counter wasn't being updated, how could the system EVER work?).
 

jon0844

Veteran Member
Joined
1 Feb 2009
Messages
30,865
Location
UK
I am pretty sure smartcards could be made relatively safe, and regularly updated as required to make them safer.

In comparison to a paper ticket, which it would appear has now been totally compromised and the problem is just limited by the number of people willing to do it, not those able to do it, it's another reason that we need to get changing over as soon as possible.
 

DownSouth

Established Member
Joined
10 Dec 2011
Messages
1,545
Smart card technology might not be the solution everyone expects it to be:

http://nakedsecurity.sophos.com/2012/09/24/android-nfc-hack-lets-subway-riders-evade-fares/
That's not an argument against smartcards, just an argument for doing it well.

The only problems with first-generation smartcard systems such as Oyster and Octopus is that they are already obsolete and in need of "Oyster2" to be rolled out featuring better security and higher capacity validators able to query the central database in real time. Even a backwards-compatible progressive rollout of current technology could fix this, and would be close to seamless if it started with the validators, was followed by the cards and then by the deactivation of the backwards compatibility.

One feature which an updated "Oyster2" system desperately needs is the ability to recharge on a website or app and then have it loaded onto the card at any validator instead of defeating the purpose of a convenient recharge by requiring a specific station vending machine be used. Any station validators with a fixed network connection should get it loaded within the hour instantly, and for on-board validators it would become available from the following day after they get a download in the depot with all the pending web/app recharges overnight.
 

swt_passenger

Veteran Member
Joined
7 Apr 2010
Messages
34,252
Southern appear to be rolling it out even though Oyster is it compatible. Surprised SWT didn't just carry on regardless.

I think the point is that the ability of TfL's Oyster estate to generally read ITSO compatible cards is something that is very new, and has gone beyond the trial stage only within the last few months.

SWT's ITSO/Oyster hardware issues are getting on for 6 or 7 years old. When their ITSO readers were put in everywhere as per the franchise spec the ability to 'just carry on regardless' wasn't technically possible.
 

infobleep

On Moderation
Joined
27 Feb 2011
Messages
13,451
I think the point is that the ability of TfL's Oyster estate to generally read ITSO compatible cards is something that is very new, and has gone beyond the trial stage only within the last few months.

SWT's ITSO/Oyster hardware issues are getting on for 6 or 7 years old. When their ITSO readers were put in everywhere as per the franchise spec the ability to 'just carry on regardless' wasn't technically possible.

Was the issue of TFL not being ready only discovered after the roll out or could they have halted the roll out given the problems, before it was completed. Seems a shame to have a load of readers just gathering dust. Given that Southern are now rolling out their system I assume South West Trains can start activating their system to more ticket types.

Sent from my Nexus 5 using Tapatalk
 

island

Veteran Member
Joined
30 Dec 2010
Messages
17,908
Location
0036
One feature which an updated "Oyster2" system desperately needs is the ability to recharge on a website or app and then have it loaded onto the card at any validator instead of defeating the purpose of a convenient recharge by requiring a specific station vending machine be used. Any station validators with a fixed network connection should get it loaded within the hour instantly, and for on-board validators it would become available from the following day after they get a download in the depot with all the pending web/app recharges overnight.

This is not compatible with an asynchronous system because someone could pick up the same top-up several times before the gateline/bus/whatever reports that it's been picked up.

Auto top-up overcomes the issue as you only have to nominate a station once to get it going, after which the auto top-ups trigger on any validation.
 

jon0844

Veteran Member
Joined
1 Feb 2009
Messages
30,865
Location
UK
One feature which an updated "Oyster2" system desperately needs is the ability to recharge on a website or app and then have it loaded onto the card at any validator instead of defeating the purpose of a convenient recharge by requiring a specific station vending machine be used.

Tell me about it. Still having so much grief trying to get my balance moved over from one Oyster to another (Barclaycard Oyster to a new card). Can't do it online (says my Barclaycard isn't an adult Oyster?!) so thought - sod it, I'll cancel the auto topup on that and set up auto topup on the new card, then use the remaining balance.

So, elected King's Cross St Pancras to be my station to both deactivate one card and start another. Was told it included National Rail, but I guess not.

Arrive at King's Cross (paper ticket) and walk to St Pancras to travel on Oyster. Touch new card, goes red. Didn't put on £10 and set up auto top up.

Okay, so I tried to deactivate my current Oyster. Beep - open gates. No double beep or anything else.

And guess what? It had auto topped up a further £20.

So obviously those gates weren't included. What a monumental f*** up!

Went to LUL ticket hall and tried TVM, but that doesn't work. Was told by staff I could only do anything by starting a journey through the tube gates, but I was free to come out and then phone up to get that aborted journey refunded.

Total mess. Oyster '2' really must fix that. I should be able to top up my account online and tap the card against my phone to top up too!
 

Geronimo

Member
Joined
17 Apr 2014
Messages
45
Location
north north west of Betelgeuse
Originally Posted by Tracky
Ticket stock probably isn't an issue. Lots of avantix stock is kept very insecurely around the network. Not all guards and revenue staff are conscientious. The fraudsters may even have had somebody on the inside, a cleaner maybe, able to pinch stock from a ticket office or guards bag.

Originally Posted by Geronimo
OK, it's probably relatively easy to modify a mag-strip reader-encoder to treat rail-tickets, whether by cloning, or by understanding the format. Fine.
Still leaves the pretty difficult problem of either procuring blank tickets, or of printing fake ones (inc. the mag stripe!). Not trivial.

See above...

Sorry, still difficult. It's not because some ticket stock is not held securely that they are easy to procure. Not saying it's impossible, but tricky to pull off. Very likely to be very limited. Very unlikely to be that costly in term of revenue loss that it requires expensive additional drastic measures.

That eBay link was interesting. But who is to say that it's not a honey trap?
 

island

Veteran Member
Joined
30 Dec 2010
Messages
17,908
Location
0036
St. Pancras, Kings Cross St. Pancras, and Kings Cross are deemed to be separate stations.
 
Status
Not open for further replies.

Top