Ski Lift In Austria Left Control Panel Open On the Internet (bleepingcomputer.com)
An anonymous reader writes: Officials from the city of Innsbruck in Austria have shut down a local ski lift after two security researchers found its control panel open wide on the Internet, and allowing anyone to take control of the ski lift's operational settings. There was no authentication in place, and anyone accessing the control panel could have modified the ski lift's speed, the distance between cable cars, and cable tension.
Coincidentally, researchers discovered the ski lift's control panel on the same day that NBC ran a report about a ski lift system suffering a mechanical malfunction, going at crazy speeds, and injuring 10 people. Both ski lifts were from the same vendor, but researchers say they weren't aware of the NBC report when they stumbled upon the one in Austria. Innsbruck officials shut down the ski lift for a security audit, and the ski lift is still nonoperational today.
Coincidentally, researchers discovered the ski lift's control panel on the same day that NBC ran a report about a ski lift system suffering a mechanical malfunction, going at crazy speeds, and injuring 10 people. Both ski lifts were from the same vendor, but researchers say they weren't aware of the NBC report when they stumbled upon the one in Austria. Innsbruck officials shut down the ski lift for a security audit, and the ski lift is still nonoperational today.
Can anyone explain why a ski lift could possibly need Internet-connected settings? What possible benefit is there to being able to control it if you aren't physically there to judge the operating conditions and environment, and to watch the customers?
great, now every time i get on a roller coaster, elevator, or subway train i'm just going to be wondering about whether there are online control systems for those things, and if i trust that company to properly secure it. it's a problem likely to become more widespread over time.
i could live a little longer in this prison
I hear it got infected by the S0nnyB0n0 virus.
Table-ized A.I.
They could have protected themselves with APK's hosts files.
But alas, that dumb bitch doesn't know how to sign software he expect you to run as administrator.
ZIP - so much winning...
Kingsmen!! The second one which was brilliant if odd.
Dennis Onstenk
Why the hell does a ski lift control panel need to be online? Insane.