Hacked Jet d'Eau

To tourists, Geneva's Jet d'Eau is a majestic plume of water against the sky. To us, it's a 140-meter-high, publicly accessible attack surface. We decided to take a deep dive into the SCADA systems that control Geneva's water pressure, and what we found was... leaky.

SCADA? More Like SCAD-uh-oh!

The industrial control systems (ICS) that manage civic infrastructure are notoriously insecure. We're talking about systems designed in the 90s, now connected to the internet for "convenience." Our investigation suggests the Jet d'Eau's control panel is accessible via a web interface with default credentials that are probably `admin:password123`.

Imagine the possibilities. A skilled attacker could weaponize the fountain, aiming its powerful jet at nearby buildings. Or, for the more artistically inclined hacker, they could modulate the water pressure to send messages in Morse code. We suspect a rival faction of hackers has already tried it, but their message was garbled. They probably forgot to URL-encode their payload. Amateurs.

Stuxnet for Fountains

This isn't just about a fountain; it's about the vulnerability of our critical infrastructure. If the Jet d'Eau is this exposed, what about the rest of the city's systems? For now, the fountain remains a symbol of Geneva. But it's also a reminder that with enough skill, you can pwn just about anything. Even water. 💧