Dr. Michael Schroeder

46 Followers
65 Following
51 Posts
vArchitect | Ph.D | Blogger at http://elasticsky.de | VCIX | Trainer | vExpert 7* | Pro | VMCE | VMUG & VeeamUG Leader | Photographer | Globetrotter
Tweetyhttps://twitter.com/microlytix
Bloghttps://elasticsky.de
LinkedInhttps://www.linkedin.com/in/dr-michael-schroeder/

I can finally reveal some research I've been involved with over the past year or so.

We (@redford, @mrtick and I) have reverse engineered the PLC code of NEWAG Impuls EMUs. These trains were locking up for arbitrary reasons after being serviced at third-party workshops. The manufacturer argued that this was because of malpractice by these workshops, and that they should be serviced by them instead of third parties.

1/4

We found that the PLC code actually contained logic that would lock up the train with bogus error codes after some date, or if the train wasn't running for a given time. One version of the controller actually contained GPS coordinates to contain the behaviour to third party workshops.

It was also possible to unlock the trains by pressing a key combination in the cabin controls. None of this was documented.

2/4

The key unlock was deleted in newer PLC software versions, but the lock logic remained.

After a certain update by NEWAG, the cabin controls would also display scary messages about copyright violations if the HMI detected a subset of conditions that should've engaged the lock but the train was still operational.

The trains also had a GSM telemetry unit that was broadcasting lock conditions, and in some cases appeared to be able to lock the train remotely.

3/4

@redford and @mrtick held an unrecorded talk a bout this at OhMyHack in Warsaw - I unfortunately couldn't make it because of Munich snow.

For now this is making the rounds in Polish-speaking sources, but we do have a talk scheduled about this at 37C3, in which we plan to do a deep dive into this and actually publish our findings.

@zaufanatrzeciastrona 's article about this: https://zaufanatrzeciastrona.pl/post/o-trzech-takich-co-zhakowali-prawdziwy-pociag-a-nawet-30-pociagow/

O trzech takich, co zhakowali prawdziwy pociąg – a nawet 30 pociągów | Zaufana Trzecia Strona

Pociąg produkcji polskiej firmy nagle zepsuł się w trakcie serwisu. Fachowcy byli bezradni - pociąg był w porządku, tylko nie chciał jechać. W ostatnim odruchu…

Zaufana Trzecia Strona
Registration to #vmwareexplore 2023 open and busy.
#vExpert
Wonderful view on the western Alpes on our way to Barcelona heading for #vmwareexplore2023
#vmug #vExpert

While I was bummed I didn't get #MTE for VMware Explore this year, always enjoy talking with our users ... VMTN Community folks just reached out to host an AMA session #VMTN2644BCN as part of the VMTN TechTalk at Explore 🥳

Limited spots, sign up now!

https://event.vmware.com/flow/vmware/explore2023bcn/content/page/catalog?search=VMTN2644BCN%20&tab.contentcatalogtabs=1627421929827001vRXW

Lots of buzz for new Raspberry Pi 5 - https://www.raspberrypi.com/news/introducing-raspberry-pi-5/

Some nice perf updates & interesting, it also uses disaggregated chiplet architecture like upcoming Intel Meteor Lake

4/8GB is great but where's 16GB+ models ... need moar memory for #ESXionARM 😁

Introducing: Raspberry Pi 5! - Raspberry Pi

Announcing Raspberry Pi 5, coming in late October: over 2x faster than Raspberry Pi 4, featuring silicon designed in-house at Raspberry Pi.

Raspberry Pi
Day 2 of #vmug #TechX300 in Copenhagen is about to start.
Full load of more technical deep dives by #VMware and community speakers to come.
A big shout-out to the Danish VMUG team. Good job.
#vExpert
@vmware_emea
vSAN 8 Update 2 - what's new on technical level

Earlier this month I had the opportunity to participate in the VMware Exclusive Blogger Early Access Program. This is where VMware experts share news and