Securing Smart Cities: Kaspersky Lab researchers examined a variety of e-kiosks and interactive terminals used in modern cities for different purposes – from paying for various services to entertainment. 
In this context, they discovered that many of them have vulnerabilities, which can expose users' private data and be used for interception or the spread of malicious code.
In addition to electronic kiosks, experts also investigated traffic cameras used in cities, as well as their supporting infrastructure. As a result, they discovered that malicious users could easily access these cameras and manipulate the collected data at will.
Modern cities are complex ecosystems, consisting of hundreds of different components, including digital ones. While these are intended to make citizens’ lives easier and safer, they can also pose threats to their data and security, as the findings of the research conducted by Kaspersky Lab experts have shown.
Cinema ticketing terminals, bicycle rental kiosks, government e-kiosks, airport booking and information terminals, and taxi passenger information and entertainment systems may look different, but inside, most of them are the same. Each such terminal is essentially a device that runs on either the Windows or Android platform. The main difference compared to regular devices is the special e-kiosk software that runs on the public terminals and acts as the user interface.
This software gives the user easy access to specific features of the terminal, while at the same time restricting access to other features of the device's operating system, including launching an Internet browser or a digital keyboard. Access to these functions offers attackers a wealth of opportunities to compromise the system, as if they were in front of a computer. The research showed that almost all public e-kiosks contain one or more vulnerabilities in their digital security, which would allow an attacker to access hidden features of the operating system.
In one specific case, the terminal user interface contained a web-link. All the attacker had to do was simply click on it to launch the browser and then – via the standard Help dialog – to start the operation of a virtual keyboard. In another case involving a public service e-kiosk, the script required the user to press the “Print” button. After that, for a few seconds the print dialog of the standard browser would open and – if he was fast enough – the attacker could press the “change” key [in the print parameters] and enter the Help window. From there, he could open the control panel and the on-screen keyboard. Thus, the attacker can have at his disposal all the solutions required for entering information (the virtual keyboard and the mouse pointer) and use the computer for his own purposes – e.g. to launch malware, get information from printed files, obtain the device administrator password, etc. And these are just some of the vulnerabilities discovered by Kaspersky Lab researchers.
“Some of the public terminals we have investigated were processing very sensitive information, such as the user’s personal data, including credit card numbers and verified contacts (for example, mobile phone numbers). Many of these terminals are connected to each other, as well as to other networks. For an attacker, this can be a very good cover for different types of attacks – from simple hooliganism to sophisticated intrusion into the terminal owner’s network. Moreover, we believe that in the future public e-kioskswill be integrated with additional “smart” infrastructures of cities, as they are a convenient way to interact with multiple services. Before this happens, vendors need to make sure that it is impossible to hack the terminals through the vulnerabilities we have discovered,” said Denis Makrushin, Security Specialist at Kaspersky Lab.
Another part of the investigation involved traffic cameras located in cities. Using the search engine Shodan, the researchers were able to locate multiple iPad addresses belonging to such devices that are freely accessible on the Internet. Since there were no active passwords, anyone could view the footage recorded by the cameras and more. The researchers discovered that some of the tools used to control these cameras were also publicly available on the Internet.
“In some cities, traffic camera systems monitor certain lanes on highways – a feature that could easily be disabled. So, if an attacker needs to shut down the system in a specific location for a period of time, they could easily do so. Considering that these cameras can be used for security and law enforcement purposes, it is really easy to imagine how these vulnerabilities can help in committing criminal acts, such as car theft, etc. Therefore, it is very important that these networks remain protected, at least from direct access to the Internet,”commented Vladimir Dashchenko, Security Specialist at Kaspersky Lab.
The full text of the research, as well as tips for protecting "Smart City" systems, are available on the Securelist.com.
The research is also available on the website of the "Securing Smart Cities" initiative (Securingsmartcities.org), a global, non-profit organization that aims to solve the existing and future digital security problems of "smart cities", through the collaboration of businesses, government agencies, media, other non-profit initiatives and individuals around the world.
