News: 1702017006

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Polish train maker denies claims its software bricked rolling stock maintained by competitor

(2023/12/08)


A trio of Polish security researchers claim to have found that trains built by Newag SA contain software that sabotages them if the hardware is serviced by competitors.

Newag, a Polish train maker, emphatically denied that it installed such software [1]in a statement [PDF, Polish] issued Wednesday, attributing any issues to unknown hackers.

The rolling stock and engineering business insists its software is correct and that it did not design the trains' programming logic to fail under specific conditions, as has been claimed. "This is a slander from our competition, which is conducting an illegal black PR campaign against us," it protested.

[2]

Jakub Stępniewicz, Sergiusz Bazański and Michał Kowalczyk – members of Dragon Sector, a Polish security hacking team who go by the names q3k, mrtick, and redford respectively – were hired in May 2022 by Serwis Pojazdów Szynowych ( [3]SPS ), an independent train maintenance firm, to look into problems with Newag Impuls 45WE trains.

[4]

[5]

SPS bid for and won a contract to maintain the trains, beating Newag, according to Polish industry publication [6]Rynek Kolejowy .

SPS then encountered difficulties servicing the rolling stock following a software lockout. According to Bazański (q3k), the trains locked up for no apparent reason after being serviced in third-party workshops. He wrote in [7]a thread on Mastodon that the manufacturer, Newag, argued that these third-party repair shops were deficient and that the manufacturer should be servicing its own trains.

[8]

The security researchers reverse engineered the train's electronics and, in August 2022 found the train-stopping faults appeared to be not a flaw – but a feature.

"We found that the PLC [programmable logic controller] code actually contained logic that would lock up the train with bogus error codes after some date, or if the train wasn't running for a given time," Bazański wrote. "One version of the controller actually contained GPS coordinates to contain the behavior to third-party workshops."

They also claimed to have found an undocumented key combination in the cabin controls that would unlock the trains. On Tuesday, the researchers discussed their findings at the [9]Oh My H@ck conference in Warsaw, Poland.

[10]

The unrecorded talk was [11]documented by infosec writer BadCyber, to whose account the hacking trio referred The Register . They are also preparing a more detailed presentation they intend to deliver at the 37th Chaos Communication Congress in Hamburg, Germany, at the end of the month.

CERT Poland confirmed to The Register that the team had disclosed their findings and that the cyber security agency had alerted relevant authorities. That was more than a year ago, and The Register understands that the ongoing lack of action is partly what motivated the researchers to go public with their findings.

Janusz Cieszyński, Poland’s former minister of digital affairs, [12]has since explained on social media that the president of Newag contacted him to say that the firm had been victimized by cyber criminals. Cieszyński added that the analysis he saw suggested otherwise. ®

Get our [13]Tech Resources



[1] https://www.newag.pl/wp-content/uploads/2023/12/Oswiadczenie-NEWAG-06.12.2023.pdf

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2ZXL3XeRC7GQcs@QifcMCnwAAAEA&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://serwispojazdowszynowych.pl/

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZXL3XeRC7GQcs@QifcMCnwAAAEA&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZXL3XeRC7GQcs@QifcMCnwAAAEA&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[6] https://www.rynek-kolejowy.pl/wiadomosci/nie-uruchamia-sie-kolejny-impuls--na-pomorzu-zachodnim-108548.html

[7] https://social.hackerspace.pl/@q3k/111528162462505087

[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44ZXL3XeRC7GQcs@QifcMCnwAAAEA&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[9] https://omhconf.pl/prelegent-2023-2/#id=54119

[10] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33ZXL3XeRC7GQcs@QifcMCnwAAAEA&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[11] https://badcyber.com/dieselgate-but-for-trains-some-heavyweight-hardware-hacking/

[12] https://x.com/jciesz/status/1732411016221524070?s=20

[13] https://whitepapers.theregister.com/



John Deere-ism Goes International

An_Old_Dog

John Deere-ism (noun) : using hardware and/or software to lock out competing parts or service providers.

or in this case

Francis Boyle

Deerailment.

Re: John Deere-ism Goes International

Anonymous Coward

Cough, cough, Apple

It's a politically motivated witch hunt!

gotes

Paraphrasing Newag's statement.

Hackers entering GPS coordinates of OEM repair shops to prevent trains from failing?

EricM

Yes, sounds completely plausible....

Andre Carneiro

It’s astounding that they would do it in the first place but did they seriously think nobody was going to take a really good look at the code once trains started failing for no good reason?

Andy The Hat

Perhaps but nobody would understand it if it was written in reverse polish ...

KittenHuffer

In reverse Polish if it was written, understand nobody would!

FTFY!

-------------> The one worn backwards mine is!

Lurko

"It’s astounding that they would do it in the first place but did they seriously think nobody was going to take a really good look at the code once trains started failing for no good reason?"

In a word, yes. That's exactly what they thought. And the apparent lack of action by Polish authorities suggests that a few brown bags have changed hands as well.

Don't overlook the fact that the expertise to examine code at this level isn't normally available to the businesses that make and service big heavy hardware like trains, and the normal thinking would be "gawd, it's gone wrong agaaaain! That's the fiftieth time with some random error code. It'll be something deep in the electronics or wiring, we'll never find it. Let's send it back to the makers and pay them to fix it".

Yorick Hunt

The timed expiry or "time bomb" is (or at least was) a common trick employed by programmers who suspected they'd be shown the door as soon as a project's finished - the company would have to call the programmer back months/years after the fact to fix things, of course at painful "consulting" rates.

elsergiovolador

There was no need for that since Java was invented. Just create enough layers of abstraction so that any replacement developer gets lost after going 7 levels deep.

I'm EMOTIONAL now because I have MERCHANDISING CLOUT!!