Russian speed cameras with fake software and backdoors in Slovakia

· heise online ·

4 min read Original article ↗

Slovakia has installed numerous Russian-made speed cameras that are repeatedly insecure and have cheated during the certification of the measurement software. Furthermore, they contain several backdoors. This has been uncovered by the country’s data security authority, NBÚ (Národný bezpečnostný úrad).

The NBÚ is publicly warning against the use of stationary speed cameras with cameras of the types Model NERO R-ONE, ostensibly from the Cypriot shell company Sodasus, Model Cordon from the Croatian company NEROline, and Model Cordon from the Russian company Simicon. According to NBÚ findings, all three are actually the same product from Simicon.

Slovakia received 30 million euros from EU funds to renew its road monitoring system. For this, it procured 279 of these stationary speed cameras with cameras. The stated goal is a tenfold increase in revenue from traffic fines. Reports that these were actually Russian devices were initially denied by the government.

The NBÚ borrowed one of the devices and conducted a superficial examination. The accusation proved to be true; only the brand and model designation had been changed. Worse still: the speed cameras do not use the certified software for speed measurements at all and are a security disaster.

According to the technical report, the device claims to be certified for speed measurement by radar. And indeed, there is a file on the installed storage medium whose checksum matches a Slovak certificate.

However, the file is unusable. For one thing, it has been made unusable by manipulation before the checksum was created, and for another, without manipulation, it would be intended for x86 processors. However, the devices have incompatible ARM processors. Vehicle speeds are calculated by completely different software that is not certified.

The government stated that the cameras would only be accessible via a state intranet. In reality, however, there are numerous additional access methods. These include freely accessible cable connections installed directly on the device, infrared, Bluetooth (none of which were examined in detail), and active WLAN. Although this is password-protected, it allows connection establishment using WPA, which has been cracked since at least 2009.

According to documentation, the surveillance devices have a 3G/4G mobile radio modem. In reality, the NBÚ found a second, undocumented 3G/4G modem. This was not difficult, as there is one externally accessible SIM card slot outside the camera’s field of view. These slots were empty in the borrowed device. Conveniently, several Russian phone numbers are pre-programmed into the device; the device accepts commands via SMS from these senders without further verification and executes them.

Furthermore, the manufacturer has pre-programmed two OpenVPN connections with fixed login data. Device management is supposed to be done via an insecure web interface. However, the NBÚ has found that administrator access is available via telnet and ssh, whose login data are also pre-defined by the manufacturer. Anyone wishing to use this access, for example to intercept the camera’s live stream, has a wealth of options: a serial connection on the device for a console, WLAN from nearby, network connection at the device or from a distance (with or without VPN), and, after inserting a SIM card, via one of two mobile radio modems.

Secure Boot is deactivated, and the installed software contains “numerous pre-programmed passwords.” To top it off, the built-in server for the web interface has full access rights; if an attacker finds a vulnerability in the web interface, they can execute any function on the system with full administrator rights. The programmer himself recognized that this is unwise and noted in the source code: “TODO!!! FIXME!!!”

The NBÚ has identified as many as 260 potentially insecure executions in the code, “in places where input processing is insufficient and the vulnerabilities can actually be exploited. A profound security analysis of the source code was not performed because it was not necessary given the current results.”

The government has announced that it will not install any further devices of this type in Slovakia for now. However, it apparently does not entirely trust its authority, which specializes in data security and the protection of state secrets. A further investigation by other experts is to follow.

(ds)

Don't miss any news – follow us on Facebook, LinkedIn or Mastodon.

This article was originally published in German. It was translated with technical assistance and editorially reviewed before publication.