Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Security

August 5th, 2011, 09:58 GMT · By

Insecure SCADA Systems Can Be Found with Google

SHARE:

Adjust text size:


SCADA systems connected to the Internet pose security risks
Enlarge picture
Security experts warn that some companies fail to properly secure their SCADA systems and leave them accessible from the Internet. Some control interfaces have even been indexed by Google.

During a Black Hat USA workshop entitled "Building, Attacking And Defending SCADA Systems in the Age of Stuxnet," FusionX CTO Tom Parker showed how searching for particular strings in Google can be used to locate insecure programmable logic controllers (PLCs).

PLCs are the building blocks of supervisory control and data acquisition (SCADA) systems. They are programmed to control industrial equipment according to specified parameters or received commands.

According to CNET, Parker's Google search query returned a link to the web interface of a Remote Terminal Unit (RTU) usually found in water treatment plants. The entry also listed "1234" as password.

Meanwhile, co-presenter Jonathan Pollet, founder and principal consultant at Red Tiger Security, said that earlier this year he located an unprotected ABB transformer running an electricity substation in the United Kingdom using the same method.

"This shouldn't even be on the Internet. It's an active substation," the security expert said. He contacted the company that owns the transformer and while it started requiring a password, the control interface can still be found in Google.

According to Pollet, the problem is that SCADA communication protocols have not been designed with encryption and strong access controls in mind, mainly because at that time it wasn't assumed that SCADA equipment will be connected to the Internet.

However, in order to cut down costs and simplify maintenance, companies have enabled remote access without changing the protocols. The best way to securely achieve this would be through network segmentation with secure authentication required for each segment.

SCADA security is a topic that has increasingly captured researchers' attention since the Stuxnet industrial sabotage malware was discovered last year.

TELL US WHAT YOU THINK:

1,323 hits · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Researcher Demonstrates SCADA Attacks

US Department of Homeland Security Fears Stuxnet Copycats

Security Expert Finds Holes In Sensitive Chinese Government Systems

SCADA Software Increasingly Under Scrutiny by Security Researchers

Exploits for Numerous 0-Day SCADA Vulnerabilities Published Online

READER COMMENTS:



No user comments yet.
Be the first to express your opinion!
Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM