Close
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Logo
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Home Cloud
    • Cloud
    • Cybersecurity
    • Development
    • Networking

    Stuxnet-Like Trojans Can Exploit Critical Flaw in Chinese Industrial Software

    Written by

    Fahmida Y. Rashid
    Published January 12, 2011
    Share
    Facebook
    Twitter
    Linkedin

      eWEEK content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More.

      A critical security flaw in supervisory-control-and-data-acquisition (SCADA) systems used in China raises the possibility of another Stuxnet-like attack, a security researcher said.

      The latest stable version of KingView, the SCADA software developed by Beijing WellinControl Technology Development, contains a critical heap overflow vulnerability, wrote Dillon Beresford, a security researcher at NSS Labs, on his personal blog. KingView is used to visualize process data in industrial control systems and has been used throughout Chinese industry, including the aerospace and national defense industries.

      “This is not any old software,” Beresford warned, noting that the vulnerability affected one of the “most widely trusted and used” SCADA software systems in China.

      SCADA systems are used to operate critical equipment at industrial facilities, factories, power plants, and oil and gas refineries.

      While poking around the Chinese SCADA software, Beresford found a heap overflow vulnerability in a software module that listens for and processes incoming log events from the human machine interface module. The vulnerability allows remote attackers to take full control of the Windows system running the flawed software, Beresford said.

      While heap overflows typically require more technical expertise to discover and exploit than stack overflows, this particular flaw could be discovered by someone with only an “intermediate” amount of skill, he said.

      That is very worrying as Stuxnet, the Trojan that compromised various SCADA systems around the world last year and crippled Iran’s nuclear program, had been created by “a lot of people with very specialized skills and knowledge,” said Randy Abrams, director of technical education at ESET.

      Exploiting this vulnerability would not pose much difficulty for these kinds of developers.

      Stuxnet was “definitely going after” SCADA systems, Abrams said, but it is not clear whether Iran was the ultimate target. It’s also not clear whether the “authors accomplished their objective,” Abrams said.

      Many Chinese industrial installations were hit hard by Stuxnet. With more vulnerabilities being exposed in SCADA software from Chinese companies, the specter of a modified Stuxnet, or a brand-new Trojan with Stuxnet capabilities, becomes more real.

      Beresford published exploit code that takes advantage of the vulnerability to execute arbitrary code, after he got no response from WellinTech or CN-CERT, China’s National Computer Emergency Response Team, after he contacted them with his discovery in September.

      “I’m not sure what’s worse, a 0-day for the most popular SCADA software in China floating around in the wild,” or the lack of response from CN-CERT, he wrote on his blog. He turned to the United States counterpart, US-CERT, for help, but the Chinese still didn’t respond.

      He’d hoped WellinTech would rollout a fix or a new version with the flaw patched quietly, but after months of no response, he decided to publicize the flaw to force the company’s hand. The Python code triggers a heap overflow and uses infected shell code to open a cell on port 4444. The code was released as a module for the Metasploit penetration testing framework and in stand-alone form.

      “Hopefully this will be an incentive to issue a patch to all of Wellintech’s customers,” he wrote.

      Beresford told ThreatPost that he’d found several other vulnerabilities in other SCADA software packages from other Chinese vendors, and that he was in the midst of contacting the companies and CN-CERT to prepare patches for those holes, as well.

      Fahmida Y. Rashid
      Fahmida Y. Rashid

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      MOST POPULAR ARTICLES

      Artificial Intelligence

      9 Best AI 3D Generators You Need...

      Sam Rinko - June 25, 2024 0
      AI 3D Generators are powerful tools for many different industries. Discover the best AI 3D Generators, and learn which is best for your specific use case.
      Read more
      Cloud

      RingCentral Expands Its Collaboration Platform

      Zeus Kerravala - November 22, 2023 0
      RingCentral adds AI-enabled contact center and hybrid event products to its suite of collaboration services.
      Read more
      Artificial Intelligence

      8 Best AI Data Analytics Software &...

      Aminu Abdullahi - January 18, 2024 0
      Learn the top AI data analytics software to use. Compare AI data analytics solutions & features to make the best choice for your business.
      Read more
      Latest News

      Zeus Kerravala on Networking: Multicloud, 5G, and...

      James Maguire - December 16, 2022 0
      I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
      Read more
      Video

      Datadog President Amit Agarwal on Trends in...

      James Maguire - November 11, 2022 0
      I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
      Read more
      Logo

      eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

      Facebook
      Linkedin
      RSS
      Twitter
      Youtube

      Advertisers

      Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

      Advertise with Us

      Menu

      • About eWeek
      • Subscribe to our Newsletter
      • Latest News

      Our Brands

      • Privacy Policy
      • Terms
      • About
      • Contact
      • Advertise
      • Sitemap
      • California – Do Not Sell My Information

      Property of TechnologyAdvice.
      © 2024 TechnologyAdvice. All Rights Reserved

      Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.

      ×