Tales of Security: Sea Interception
Vladimir Bezmaly | 10/19/2017
A strange report was received by the Metropolitan Police. Company A, a transport carrier whose bulk carrier had recently collided with a cargo vessel of Company B, asked to examine the computer control system of the bulk carrier. The reason for this was a letter received by the CEO of the company. The letter stated that the cause of the collision of the bulk carrier was the interception of control of the vessel.
- Johann, have your employees ever operated ships?
- No, I don't think so, Mr. Commissioner! What? Is it time?
- Alas, it seems it's time.
— But seriously?
— But seriously, we need to check the computer system of the dry cargo ship Gloria of company A. There is a suspicion that it has been hacked. This is what caused the collision of the dry cargo ship.
- Y-e-e-e-e, you've given us a task. Well, let's try.
- Karl, Mark! Your subordinates and you will have to work as sailors.
- Boss, of me?
— I am absolutely serious. The cargo ship Gloria is in the dock. You will have to find out whether its IT system was hacked, and if possible, find out who did it. And “who” is the last question. It is much more important, if a hack did occur, to make sure that it does not happen again on other ships.
Two weeks have passed.
- Johann, it's much worse than we thought. The ship's IT latvia mobile database is full of vulnerabilities. Weak passwords, easily accessible satellite dishes, configuration errors that can be identified by a simple search. Not only that, we got a complete list of the crew. And all this can be used for phishing attacks, learning more about the crew members on social networks.
- It's fun, though.
— Moreover, we have gained access to satellite communications equipment, which contains location data, cargo-related information, and much more.
— Your conclusion?
— The conclusion is simple. The IT system has definitely been hacked. But that's not all. There are a lot of such courts. The IT systems on them were built a long time ago, when no one thought about information security. All courts need to be checked.
Are you laughing or making fun
-
- Posts: 529
- Joined: Mon Dec 23, 2024 3:13 am