Hoping to Teach a Lesson, Researchers Release Exploits for Critical Infrastructure Software
InfoSec News <[email protected]> Fri, 20 Jan 2012 02:46:09 -0600 (CST)
| Newsgroups | gmane.comp.security.attrition.infosec-news |
|---|---|
| Message-ID | <[email protected]> |
This message is in MIME format. The first part should be readable text, while the remaining parts are likely unreadable without MIME-aware tools. --742952673-926241093-1327048156=:28829 Content-Type: TEXT/PLAIN; FORMAT=flowed; CHARSET=UTF-8 Content-ID: <alpine.DEB.2.02.1201200245542.28999-+lq4ijtN3NWD1tnzEPnUTA@public.gmane.org> Content-Transfer-Encoding: quoted-printable http://www.wired.com/threatlevel/2012/01/scada-exploits/ By Kim Zetter Threat Level Wired.com January 19, 2012 MIAMI, Florida -- A group of researchers has discovered serious security=20 holes in six top industrial control systems used in critical=20 infrastructure and manufacturing facilities and, thanks to exploit=20 modules they released on Thursday, have also made it easy for hackers to=20 attack the systems before they=E2=80=99re patched or taken offline. The vulnerabilities were found in widely used programmable logic=20 controllers (PLCs) made by General Electric, Rockwell Automation,=20 Schneider Modicon, Koyo Electronics and Schweitzer Engineering=20 Laboratories. PLCs are used in industrial control systems to control functions in=20 critical infrastructure such as water, power and chemical plants; gas=20 pipelines and nuclear facilities; as well as in manufacturing facilities=20 such as food processing plants and automobile and aircraft assembly=20 lines. The vulnerabilities, which vary among the products examined, include=20 backdoors, lack of authentication and encryption, and weak password=20 storage that would allow attackers to gain access to the systems. The=20 security weaknesses also make it possible to send malicious commands to=20 the devices in order to crash or halt them, and to interfere with=20 specific critical processes controlled by them, such as the opening and=20 closing of valves. [...] --742952673-926241093-1327048156=:28829 Content-Type: text/plain; charset="us-ascii" MIME-Version: 1.0 Content-Transfer-Encoding: 7bit Content-Disposition: inline _____________________________________________________ Did a friend send you this article? Make it your New Year's Resolution to subscribe to InfoSec News! http://www.infosecnews.org/mailman/listinfo/isn --742952673-926241093-1327048156=:28829--