Two university students identified a security vulnerability earlier this year that could potentially allow people to use over a million internet-enabled laundry machines for free. These machines are located in various residences and college dorms across different continents.
Despite having reported the issue months ago, the jaw-dropping vulnerability remains unresolved. CSC ServiceWorks, the provider in question, has not taken actions to rectify the issue despite multiple contact attempts by the students.
Alexander Sherbrooke and Iakov Taranenko of UC Santa Cruz stated to TechCrunch that this security flaw makes it feasible for individuals to remotely command CSC-operated laundry machines to run without paying.
Sherbrooke recounted an episode where, from his laptop, he managed to prompt a laundry machine to begin a washing cycle without having funds in his account. The machine signaled readiness for a free wash. In a different scenario, the students inflated their laundry account balance visible in the CSC Go mobile app to millions of dollars without actual transaction.
CSC ServiceWorks is notable for its large footprint in the laundry service industry with machines situated in locations like hotels and educational institutions in the US, Canada, and Europe.
The students reached out to the company through various means including online forms and a direct phone call, only to meet with silence from CSC’s end.
Having no success with the company, the students turned to the CERT Coordination Center at Carnegie Mellon University which offers support to security researchers in responsibly disclosing vulnerabilities.
After adhering to the ethical disclosure period of three months typically given by researchers for companies to address vulnerabilities, the students opted to make their findings known. Initially brought to light at their university cybersecurity club, they are now going public with their discovery.
The security rupture lies within the API of the CSC’s mobile application, CSC Go. The API lacks essential server-side security verifications, effectively trusting any command that bypasses the app’s local checks.
By studying the app’s communication with CSC’s servers, the students learned how to directly send instructions, circumventing the intended security measures.
The researchers express concerns over the potential misuse that could impact not only the company’s revenue but also the safety aspects of internet-connected appliances. They noted the unresolved danger that arises from the ability to interact with these machines remotely.
After reporting their findings, CSC erased the fictional balance from the students’ accounts but has not addressed the underlying security issue.
Despite their disappointment in CSC’s inaction, the students maintain their dedication to ethical hacking and the improvement of cyber security practices.
FAQs
What was the discovered security flaw?
The security flaw involved the ability to remotely send commands to internet-connected CSC laundry machines to run cycles without paying, manipulate account balances, and potentially interact with any machine within CSC’s network.
How did the students discover this flaw?
They discovered it by sending a script of code from a laptop to a laundry machine, successfully starting a cycle without funds. Additionally, they experimented with the CSC Go mobile app’s API, bypassing local security checks with direct server commands.
Has the vulnerability been resolved?
No, the security flaw remains unaddressed by CSC ServiceWorks despite the students’ multiple contact attempts and responsible disclosure through CERT Coordination Center.
What is the potential impact of the flaw?
This flaw could lead to the misuse of laundry services, financial losses for CSC ServiceWorks, and potential safety risks if the remote commands can bypass built-in safety features of the laundry machines.
Conclusion
The discovery of a critical security flaw by two vigilant university students has brought to light the growing need for stringent cybersecurity in the growing realm of Internet of Things (IoT) devices. While the educational benefit for the students and the potential for free laundry has an undeniable appeal, the overarching concern regarding user safety and the financial implications for the company cannot be understated. CSC ServiceWorks’ ignorance of the vulnerability only exacerbates the risk and underscores the urgency for improved cybersecurity responsiveness by large tech vendors to safeguard consumer interests and company integrity.










































