Smashing Security

How to hack a prison, and the hidden threat of online checkouts

20 snips
Oct 22, 2025
In this discussion, Scott Helme, a web security expert and founder of Report URI, shares a jaw-dropping tale of how an inmate manipulated prison web kiosks in Romania. He reveals how an inmate gained unauthorized access to staff credentials, allowing him to alter financial records and sentences. The conversation shifts to payment security, as Scott outlines new PCI DSS rules targeting risky JavaScript practices on payment pages, aiming to combat the infamous Magecart skimmers. Listeners also get tips on automating tasks using Keyboard Maestro and creating tutorials with Screen Studio.
Ask episode
AI Snips
Chapters
Transcript
Episode notes
ANECDOTE

Prison Kiosk Account Takeover

  • A Romanian prisoner obtained a staff password and used web kiosks to gain admin access to the prison system.
  • He viewed accounts, granted porn access, inflated balances and briefly added massive funds before reverting changes.
ANECDOTE

Months Of Admin Abuse Went Unnoticed

  • The inmate spent over 300 hours logged in as an admin and even altered other prisoners' earned sentence credits.
  • An accounting discrepancy eventually exposed the tampering when purchases didn't reduce balances.
ADVICE

Respond Fast: Change Credentials And Lockdown

  • Immediately rotate compromised credentials and implement multi-factor authentication for administrative portals.
  • Remove unnecessary input methods (e.g., keyboards on kiosks) and reduce attack surface quickly after detection.
Get the Snipd Podcast app to discover more snips from this episode
Get the app