Уровень 0 · материалов: 3
В кластер входят документы об обнаружении конкретных технических уязвимостей в российских государственных или транспортных информационных системах и картах.
Общие признаки: критические ошибки безопасности, утечка персональных данных, инфраструктура Москвы и РЖД, публичные сети Wi-Fi, недостатки шифрования
Группа выше: Уязвимости российских и государственных систем
Смысл: The main idea is to highlight a critical privacy vulnerability in the Moscow Metro's public Wi-Fi where spoofing a MAC address allowed unauthorized access to users' personal information, including phone numbers.
A vulnerability in Moscow Metro's free Wi-Fi allowed anyone to steal users' phone numbers and personal data by simply spoofing their MAC addresses.
Смысл: The text aims to expose a severe privacy flaw in Moscow's social cards, where full passport data is stored using broken encryption, making it accessible to anyone with basic hardware.
Moscow's Social Cards use compromised Mifare Classic encryption, allowing attackers to wirelessly steal full passport data from users' pockets.
Смысл: The author describes a casual penetration test performed on the Sapsan high-speed train's Wi-Fi network, revealing critical security failures that allowed access to passenger databases and internal RZD network VPNs.
A cybersecurity enthusiast easily breached the Sapsan train's Wi-Fi system, gaining access to passenger data and internal RZD networks due to poor administrative practices.