Voting machine password hacks as easy as 'abcde'
Obsolete WEP wireless security. Check.
No system logs. Check.
My twelve year old niece could sit in the parking lot outside the voting center with an old version of Back Track and hack this.
With a pringles can yagi, she could hack it from a block away...
But I want you to know that your vote is very important to the government. You owe it to your government to vote...
LOL
Uno
e-voting machine so easy to hack, it will take your breath away“You could have broken into one of these with a very small amount of technical assistance,” Epstein said. “I could teach you how to do it over the phone. It might require an administrator password, but that’s okay, the password is ‘admin’.”
... the version of Windows operating on each of them had not been updated since at least 2004..
... the units have been used in at least two dozen elections across the state. Mississippi and Pennsylvania stopped using them several years ago. Epstein said it is likely no one will ever know whether or not they were tampered with.
“There are no logs kept in the systems,” Epstein said...
“Bottom line is that if no Virginia elections were ever hacked (and we have no way of knowing if it happened), it’s because no one with even a modicum of skill tried,” ...
The AVS WINVote, made by Advanced Voting Solutions, passed necessary voting systems standards and has been used in Virginia and, until recently, in Pennsylvania and Mississippi. It used the easy-to-crack passwords of "admin," "abcde," and "shoup" to lock down its Windows administrator account, Wi-Fi network, and voting results database respectively...
The weak passwords—which are hard-coded and can't be changed...
The Wi-Fi network the machines use is encrypted with wired equivalent privacy, an algorithm so weak that it takes as little as 10 minutes for attackers to break a network's encryption key... the WINVote runs a version of Windows XP Embedded that hasn't received a security patch since 2004,...
If an election was held using the AVS WinVote, and it wasn’t hacked, it was only because no one tried... Further, there are no logs or other records that would indicate if such a thing ever happened, so if an election was hacked any time in the past, we will never know.
Trivial hard coded admin password. Check.How would someone use these vulnerabilities to change an election?
Take your laptop to a polling place, and sit outside in the parking lot.
Use a free sniffer to capture the traffic, and use that to figure out the WEP password (which VITA did for us).
Connect to the voting machine over WiFi.
If asked for a password, the administrator password is “admin” (VITA provided that).
Download the Microsoft Access database using Windows Explorer.
Use a free tool to extract the hardwired key (“shoup”, which VITA also did for us.
Use Microsoft Access to add, delete, or change any of the votes in the database.
Upload the modified copy of the Microsoft Access database back to the voting machine.
Wait for the election results to be published.
Obsolete WEP wireless security. Check.
No system logs. Check.
My twelve year old niece could sit in the parking lot outside the voting center with an old version of Back Track and hack this.
With a pringles can yagi, she could hack it from a block away...
But I want you to know that your vote is very important to the government. You owe it to your government to vote...
LOL
Uno
