{"id":98007,"date":"2024-05-17T16:05:16","date_gmt":"2024-05-17T16:05:16","guid":{"rendered":"https:\/\/entertainment.runfyers.com\/index.php\/2024\/05\/17\/exclusive-two-students-uncover-security-bug-that-could-let-millions-do-their-laundry-for-free\/"},"modified":"2024-05-17T16:05:16","modified_gmt":"2024-05-17T16:05:16","slug":"exclusive-two-students-uncover-security-bug-that-could-let-millions-do-their-laundry-for-free","status":"publish","type":"post","link":"https:\/\/entertainment.runfyers.com\/index.php\/2024\/05\/17\/exclusive-two-students-uncover-security-bug-that-could-let-millions-do-their-laundry-for-free\/","title":{"rendered":"EXCLUSIVE: Two students uncover security bug that could let millions do their laundry for free"},"content":{"rendered":"<p> <br \/>\n<\/p>\n<div>\n<p id=\"speakable-summary\" class=\"wp-block-paragraph\">A pair of university students say they found and reported earlier this year a security flaw allowing anyone to avoid paying for laundry provided by over a million internet-connected laundry machines in residences and college campuses around the world.<\/p>\n<p class=\"wp-block-paragraph\">Months later, the vulnerability remains open after the vendor, CSC ServiceWorks, repeatedly ignored requests to fix the flaw.<\/p>\n<p class=\"wp-block-paragraph\">UC Santa Cruz students Alexander Sherbrooke and Iakov Taranenko told TechCrunch that the vulnerability they discovered allows anyone to remotely send commands to laundry machines run by CSC and operate laundry cycles for free.<\/p>\n<p class=\"wp-block-paragraph\">Sherbrooke said he was sitting on the floor of his basement laundry room in the early hours one January morning with his laptop in hand, and \u201csuddenly having an \u2018oh s\u2014\u2019 moment.\u201d From his laptop, Sherbrooke ran a script of code with instructions telling the machine in front of him to start a cycle despite having $0 in his laundry account. The machine immediately woke up with a loud beep and flashed \u201cPUSH START\u201d on its display, indicating the machine was ready to wash a free load of laundry.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">In another case, the students added an ostensible balance of several million dollars into one of their laundry accounts, which reflected in their <a href=\"https:\/\/mycscgo.com\/laundry\" target=\"_blank\" rel=\"noreferrer noopener\">CSC Go mobile app<\/a> as though it were an entirely normal amount of money for a student to spend on laundry.<\/p>\n<p class=\"wp-block-paragraph\">CSC ServiceWorks is a large laundry service company, <a href=\"https:\/\/www.cscsw.com\/about-us\/\" target=\"_blank\" rel=\"noreferrer noopener\">touting a network<\/a> of over a million laundry machines installed in hotels, university campuses, and residences across the United States, Canada and Europe.<\/p>\n<p class=\"wp-block-paragraph\">Since CSC ServiceWorks does not have a dedicated security page for reporting security vulnerabilities, Sherbrooke and Taranenko sent the company several messages through its online contact form during January, but heard nothing back from the company. A phone call to the company landed them nowhere either, they said.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">The students also sent their findings to the CERT Coordination Center at Carnegie Mellon University, which helps security researchers disclose flaws to affected vendors and provide fixes and guidance to the public.<\/p>\n<p class=\"wp-block-paragraph\">The students are now revealing more about their findings after waiting longer than the customary three months that security researchers typically grant vendors to fix flaws before going public. The pair first disclosed their research in a presentation at their <a href=\"https:\/\/slugsec.ucsc.edu\/posts\" target=\"_blank\" rel=\"noreferrer noopener\">university cybersecurity club<\/a> earlier in May.<\/p>\n<p class=\"wp-block-paragraph\">It\u2019s unclear who, if anyone, is responsible for cybersecurity at CSC, and representatives for CSC did not respond to TechCrunch\u2019s requests for comment.<\/p>\n<p class=\"wp-block-paragraph\">The student researchers said the vulnerability is in the API used by CSC\u2019s mobile app, <a href=\"https:\/\/mycscgo.com\/laundry\" target=\"_blank\" rel=\"noreferrer noopener\">CSC Go<\/a>. An API allows apps and devices to communicate with each other over the internet. In this case, the customer opens the CSC Go app to top up their account with funds, pay, and begin a laundry load on a nearby machine.<\/p>\n<p class=\"wp-block-paragraph\">Sherbrooke and Taranenko discovered that CSC\u2019s servers can be tricked into accepting commands that modify their account balances because any security checks are done by the app on the user\u2019s device and automatically trusted by CSC\u2019s servers. This allows them to pay for laundry without actually putting real funds in their accounts.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">By analyzing the network traffic while logged in and using the CSC Go app, Sherbrooke and Taranenko found they could circumvent the app\u2019s security checks and send commands directly to CSC\u2019s servers, which are not available through the app itself.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">Technology vendors like CSC are ultimately responsible for making sure their servers are performing the proper security checks, otherwise it\u2019s akin to having a bank vault protected by a guard who doesn\u2019t bother to check who is allowed in.<\/p>\n<p class=\"wp-block-paragraph\">The researchers said potentially anyone can create a CSC Go user account and send commands using the API because the servers are also not checking if new users owned their email addresses. The researchers tested this by creating a new CSC account with a made-up email address.<\/p>\n<p class=\"wp-block-paragraph\">With direct access to the API and referencing CSC\u2019s <a href=\"https:\/\/mycscgo.com\/api\/v1\/docs\/static\/index.html\" target=\"_blank\" rel=\"noreferrer noopener\">own published list of commands for communicating with its servers<\/a>, the researchers said it is possible to remotely locate and interact with \u201cevery laundry machine on the CSC ServiceWorks connected network.\u201d\u00a0<\/p>\n<p class=\"wp-block-paragraph\">Practically speaking, free laundry has an obvious upside. But the researchers stressed the potential dangers of having heavy-duty appliances connected to the internet and vulnerable to attacks. Sherbrooke and Taranenko said they were unaware if sending commands through the API can bypass the safety restrictions that modern laundry machines come with to prevent overheating and fires. The researchers said someone would have to physically push the laundry machine\u2019s start button to begin a cycle, until then the settings on the front of the laundry machine cannot be changed unless someone resets the machine.<\/p>\n<p class=\"wp-block-paragraph\">CSC quietly wiped out the researchers\u2019 account balance of several million dollars after they reported their findings, but the researchers said the bug remains unfixed and it\u2019s still possible for users to \u201cfreely\u201d give themselves any amount of money.<\/p>\n<p class=\"wp-block-paragraph\">Taranenko said he was disappointed that CSC did not acknowledge their vulnerability.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">\u201cI just don\u2019t get how a company that large makes those types of mistakes then has no way of contacting them,\u201d he said. \u201cWorst case scenario, people can easily load up their wallets and the company loses a ton of money, why not spend a bare minimum of having a single monitored security email inbox for this type of situation?\u201d<\/p>\n<p class=\"wp-block-paragraph\">But the researchers are undeterred by the lack of response from CSC.\u00a0<\/p>\n<p class=\"wp-block-paragraph\">\u201cSince we\u2019re doing this in good faith, I don\u2019t mind spending a few hours waiting on hold to call their help desk if it would help a company with its security issues,\u201d said Taranenko, adding that it was \u201cfun to get to do this type of security research in the real world and not just in simulated competitions.\u201d<\/p>\n<figure class=\"wp-block-embed is-type-wp-embed is-provider-techcrunch wp-block-embed-techcrunch\"\/>\n<\/div>\n<p><br \/>\n<br \/><a href=\"https:\/\/techcrunch.com\/2024\/05\/17\/csc-serviceworks-free-laundry-million-machines\/\" target=\"_blank\" rel=\"noopener\">Source link <\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>A pair of university students say they found and reported earlier this year a security flaw allowing anyone to avoid paying for laundry provided by over a million internet-connected laundry machines in residences and college campuses around the world. Months later, the vulnerability remains open after the vendor, CSC ServiceWorks, repeatedly ignored requests to fix [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":98008,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[14],"tags":[],"class_list":{"0":"post-98007","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-tech"},"_links":{"self":[{"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/posts\/98007","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/comments?post=98007"}],"version-history":[{"count":0,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/posts\/98007\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/media\/98008"}],"wp:attachment":[{"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/media?parent=98007"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/categories?post=98007"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/entertainment.runfyers.com\/index.php\/wp-json\/wp\/v2\/tags?post=98007"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}