Hoping to Teach a Lesson, Researchers Release Exploits for Critical Infrastructure Software

InfoSec News <[email protected]> Fri, 20 Jan 2012 02:46:09 -0600 (CST)
Newsgroups gmane.comp.security.attrition.infosec-news
Message-ID <[email protected]>
  This message is in MIME format.  The first part should be readable text,
  while the remaining parts are likely unreadable without MIME-aware tools.

--742952673-926241093-1327048156=:28829
Content-Type: TEXT/PLAIN; FORMAT=flowed; CHARSET=UTF-8
Content-ID: <alpine.DEB.2.02.1201200245542.28999-+lq4ijtN3NWD1tnzEPnUTA@public.gmane.org>
Content-Transfer-Encoding: quoted-printable

http://www.wired.com/threatlevel/2012/01/scada-exploits/

By Kim Zetter
Threat Level
Wired.com
January 19, 2012

MIAMI, Florida -- A group of researchers has discovered serious security=20
holes in six top industrial control systems used in critical=20
infrastructure and manufacturing facilities and, thanks to exploit=20
modules they released on Thursday, have also made it easy for hackers to=20
attack the systems before they=E2=80=99re patched or taken offline.

The vulnerabilities were found in widely used programmable logic=20
controllers (PLCs) made by General Electric, Rockwell Automation,=20
Schneider Modicon, Koyo Electronics and Schweitzer Engineering=20
Laboratories.

PLCs are used in industrial control systems to control functions in=20
critical infrastructure such as water, power and chemical plants; gas=20
pipelines and nuclear facilities; as well as in manufacturing facilities=20
such as food processing plants and automobile and aircraft assembly=20
lines.

The vulnerabilities, which vary among the products examined, include=20
backdoors, lack of authentication and encryption, and weak password=20
storage that would allow attackers to gain access to the systems. The=20
security weaknesses also make it possible to send malicious commands to=20
the devices in order to crash or halt them, and to interfere with=20
specific critical processes controlled by them, such as the opening and=20
closing of valves.

[...]


--742952673-926241093-1327048156=:28829
Content-Type: text/plain; charset="us-ascii"
MIME-Version: 1.0
Content-Transfer-Encoding: 7bit
Content-Disposition: inline

_____________________________________________________
Did a friend send you this article? Make it your
New Year's Resolution to subscribe to InfoSec News!
http://www.infosecnews.org/mailman/listinfo/isn
--742952673-926241093-1327048156=:28829--