Latest news
But last week, at the SCADA Security Scientific Symposium held in Miami, visitors had the opportunity to hear a damning presentation held by researchers grouped around Project Basecamp which revealed that their testing of six widely used programmable logic controllers (PLCs) resulted in the discovery of alarming security bugs that are mostly design flaws and (even!) features, and of the fact that some of them can't even take a probing without crashing.
One of the devices, the Control Microsystems' SCADAPack, bricked early on into testing. The remaining five (General Electric's D20ME, Koyo's Direct LOGIC H4-ES, Rockwell Automation's Allen-Bradley ControlLogix and Allen-Bradley MicroLogix, Schneider Electric's Modicon Quantum, and Schweitzer's SEL-2032) displayed a dazzling array of back door accounts, old hardware and firmware, lousy security controls, configuration files easily obtainable by attackers, buffer overflow and remotely exploitable vulnerabilities, unexpected crashes, weak password implementation and authentication protection, and inability to upload custom firmware:

ThreatPost reports that despite the reservations of some security experts that have questioned the researchers' action of making this information public before sharing it with the vendors, most industrial control security experts are satisfied that someone has finally pointed out these things they knew for years.
"A large percentage of these vulnerabilities the vendor already knows about and has chosen to live with, so this is not news to them," commented Dale Peterson, CEO of SCADA security firm Digital Bond, which organized the project, and said that the best way to avoid uncomfortable disclosures is to do a better job making secure products.
He expressed his belief that this presentation should be the moment when SCADA systems and PLC vendors finally realize that they have to take security more seriously. For their part, the researchers collaborated with Rapid 7 and Tenable in order to create test modules for the Metasploit Framework and the Nessus scanner for these vulnerabilities, in the hope that vendors will be pushed to make changes with security in mind.


Spotlight

Cyber espionage campaign uses professionally-made malware
Posted on 20 May 2013. | A massive cyber espionage campaign has been hitting government ministries, IT companies, academic research institutions, and more.

Ransomware adds password stealing to its arsenal
Posted on 17 May 2013. | Microsoft researchers are warning about a new variant of the well-known Reveton ransomware doing rounds.

Application vulnerabilities still a top security concern
Posted on 16 May 2013. | Respondents to a new (ISC)2 study identified application vulnerabilities as their top security concern. A significant gap persists between software developers’ priorities and security professionals’ concerns.

IT security jobs: What's in demand and how to meet it
Posted on 15 May 2013. | Let's say you want a career in information security, where do you start? What credentials do you need? What are employers looking for? Read on to find some answers.

Hacking charge stations for electric cars
Posted on 15 May 2013. | Ofer Shezaf talks about what charge stations really are, why they have to be ‘smart’ and the potential risks created to the grid, to the car and most importantly to its owner’s privacy and safety.
By subscribing to our early morning news update, you will receive a daily digest of the latest security news published on Help Net Security.
With over 500 issues so far, reading our newsletter every Monday morning will keep you up-to-date with security risks out there.






