Close
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Subscribe
Logo
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Subscribe
    Home Cybersecurity
    • Cybersecurity
    • Development
    • Networking

    SCADA Security Widely Discussed at Black Hat in Wake of Stuxnet Attack

    Written by

    Fahmida Y. Rashid
    Published August 8, 2011
    Share
    Facebook
    Twitter
    Linkedin

      eWEEK content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More.

      Security researchers pointed out the vulnerability of industrial-control systems, such as programmable logic controllers and other units, during the recent Black Hat security conference in Las Vegas.

      SCADA (Supervisory Control and Data Acquisition) systems are used to run power plants, manufacturing processing, petrochemical production and other critical infrastructure. At the Black Hat conference in Las Vegas, SCADA systems kept popping up in various panels as researchers discussed various ways they were vulnerable.

      Dillon Beresford, a researcher with NSS Labs, revealed a backdoor in Siemens S7-300, S7-400 and S7-1200 devices that allowed him to hack inside and capture passwords. In a live demonstration, he showed how he could reprogram and control the programmable logic controllers. These Siemens devices are used in power and manufacturing plants around the world, and were vulnerable to this hack, which could cause them to shut down or crash attached systems.

      Beresford claimed it took him only two-and-a-half hours to write the exploit code after he found a hard-coded password that allowed him to open a command shell. He was able to do “other things,” such as perform a memory dump and capture passwords. The backdoor was likely put in place for diagnostic purposes, Beresford said.

      There are plenty of PLCs connected to the Internet, and “an attack on PLCs for 24 hours could cause it to blow up a plant,” Bereseford said, adding that he wasn’t trying to “freak” anyone out. Hacking SCADA systems is no longer in the hands of nation-states, but in those of independent researchers as well, and it was just a “matter of time,” according to Beresford.

      “It’s not just the spooks who have these capabilities. Average guys sitting in their basements can pull this off,” said Beresford.

      Thomas Brandstetter, acting head of Siemens’ product computer emergency response team, was on stage with Beresford and confirmed the company was working on fixes for its devices.

      “Siemens created a product CERT eight months ago to handle vulnerabilities in its products and to work with the security community,” Brandstetter said.

      In a more light-hearted finding, Beresford also found an “Easter egg” of animated dancing monkeys in the Siemens firmware.

      In a different session Aug. 4, Tom Parker, CTO of FusionX, typed in some search terms associated with a programmable logic controller, in Google. A page referencing the Remote Terminal Unit’s pump status, like those used in water-treatment plants and pipelines that connect to the Internet, appeared in the search results page. The search also yielded up the RTU’s default password, “1234.”

      Attackers are increasingly using search engines to discover vulnerable systems, default passwords and sensitive files, Noa Bar Yosef told eWEEK. With Google and Microsoft compiling and maintaining very thorough search indexes, attackers have access to valuable vulnerability information when planning and executing attacks, Yosef said. Attackers use automated tools to generate more than 80,000 daily queries to probe the Web for vulnerable Web applications, according to Yosef.

      Most SCADA protocols have no security built in, so when a PLC receives a command, it assumes it’s from a legitimate source and executes it without performing any checks or authentication, according to Jonathan Pollet, founder of Red Tiger Security, who co-presented with Parker. Anyone who discovers the PLC’s IP address can send commands to the device, Pollet said.

      In the case of Parker’s presentation, if that RTU had any motors attached to it, remote attackers could use the information available online to turn it off or create an outage. Parker and Pollet discovered through a series of Google searches that an electricity substation in the United Kingdom was running a transformer with no password required. They were able to see circuit breaker statuses, when it was last worked on and the unit’s status, Pollet said.

      Interest in SCADA security has increased since last year when Stuxnet, a worm that targets Siemens SCADA systems, emerged. Exploiting the auto-run vulnerability in Windows systems and other security flaws in Siemens systems, the worm damaged centrifuges in Iran’s nuclear enrichment facility.

      During a panel on how GSM networks can be used to hack into cars, Don Bailey, a researcher with security consulting company iSec Partners, also mentioned how SCADA systems were vulnerable as they could be controlled via text messages.

      Fahmida Y. Rashid
      Fahmida Y. Rashid

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      MOST POPULAR ARTICLES

      Artificial Intelligence

      9 Best AI 3D Generators You Need...

      Sam Rinko - June 25, 2024 0
      AI 3D Generators are powerful tools for many different industries. Discover the best AI 3D Generators, and learn which is best for your specific use case.
      Read more
      Cloud

      RingCentral Expands Its Collaboration Platform

      Zeus Kerravala - November 22, 2023 0
      RingCentral adds AI-enabled contact center and hybrid event products to its suite of collaboration services.
      Read more
      Artificial Intelligence

      8 Best AI Data Analytics Software &...

      Aminu Abdullahi - January 18, 2024 0
      Learn the top AI data analytics software to use. Compare AI data analytics solutions & features to make the best choice for your business.
      Read more
      Latest News

      Zeus Kerravala on Networking: Multicloud, 5G, and...

      James Maguire - December 16, 2022 0
      I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
      Read more
      Video

      Datadog President Amit Agarwal on Trends in...

      James Maguire - November 11, 2022 0
      I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
      Read more
      Logo

      eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

      Facebook
      Linkedin
      RSS
      Twitter
      Youtube

      Advertisers

      Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

      Advertise with Us

      Menu

      • About eWeek
      • Subscribe to our Newsletter
      • Latest News

      Our Brands

      • Privacy Policy
      • Terms
      • About
      • Contact
      • Advertise
      • Sitemap
      • California – Do Not Sell My Information

      Property of TechnologyAdvice.
      © 2024 TechnologyAdvice. All Rights Reserved

      Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.