Softpedia
 

NEWS CATEGORIES:



NEWS ARCHIVE >>
SOFTPEDIA REVIEWS >>
MEET THE EDITORS >>
Home > News > Security

November 21st, 2011, 15:00 GMT · By Eduard Kovacs

South Houston SCADA Systems Protected by Three Character Password

SHARE:

Adjust text size:


One of the screenshots of the human machine interface provided by the hacker
Enlarge picture
There's been a lot of debate lately on the hacks that targeted SCADA system and now the hacker came forward to state that what he actually did can barely be called a hack since there was not much protection to guard the infrastructure.

According to Threat Post, the hacker who calls himself pr0f claims that even a child with some Simatic knowledge could have easily passed through the barriers, since everything was protected by a simple three-character password.

“I'm sorry this ain't a tale of advanced persistent threats and stuff, but frankly most compromises I've seen have been have been a result of gross stupidity, not incredible technical skill on the part of the attacker. Sorry to disappoint,” he said.

All this comes after he posted some screenshots of the human machine interface that's used to control the Texas water utility.

He then stated his frustration on the fact that the DHS considered the whole incident to be a mere pump failure instead of a cybercriminal activity.

“This was stupid. You know. Insanely stupid. I dislike, immensely, how the DHS tend to downplay how absolutely F***** the state of national infrastructure is,” pr0f said at the time.

After the hacking operation he claimed that it's not his intention to expose any information or to cause damage to the machinery, his main goal being to prove the Department of Homeland Security wrong.

The whole debate around the security of SCADA systems began after Joe Weiss, a security expert, wrote a blog post in which he announced that a SCADA software vendor was breached and customer information was stolen.

He argued that the credentials were utilized to access the industrial control systems of a water utility.

“We don't have cyber forensics, so when they see [issues] they don't think it's a cyber problem. They just think it's a glitch in the system. Why won't we have a cyber Pearl Harbor? Because we won't know it,” Weiss said.

TELL US WHAT YOU THINK:

1,469 hits · 1 comment · Link to this article · Print article · Send to friend · Subscribe to news

MUST-READ RELATED ARTICLES:


Hacker Proves Attack on Water Utility in South Houston

Water System Hacked, Attacker IP Traced to Russia

NJStar Translation Software Vulnerable to Stack Overflow Attacks

DHS: Hackers Came Close to Affecting US Critical Infrastructure

DHS Fears Anonymous Might Attack Industrial Control Systems

READER COMMENTS:


Comment #1 by: Bueller on 22 Nov 2011, 11:40 UTC reply to this comment

Here are some more references on the same topic:
http://www.wired.com/threatlevel/2011/11/hackers-destroy-water-pump/2
http://www.chicagotribune.com/news/chi-111118water-pump-facility,0,1531638.story
http://news.cnet.com/8301-27080_3-57327030-245/u.s-water-utility-reportedly-hacked-last-week-expert-says/

Copyright © 2001-2012 Softpedia. Contact/Tip us at

WindowsGamesDriversMacLinuxScriptsMobileHandheldNews

SUBMIT PROGRAM   |   ADVERTISE   |   GET HELP   |   SEND US FEEDBACK   |   RSS FEEDS   |   UPDATE YOUR SOFTWARE   |   ROMANIAN FORUM