Home Discord Chat
Go Back   ChiefsPlanet > Nzoner's Game Room
Register FAQDonate Members List Calendar

Reply
 
Thread Tools Display Modes
Old 08-24-2007, 03:11 PM  
jAZ jAZ is offline
Supporter
 
jAZ's Avatar
 
Join Date: Apr 2001
Location: Tucson, AZ
Casino cash: $9847493
IBM Hacking Researcher: Nuclear Reactor "one of the easiest (hacks) I'd ever done"

http://www.forbes.com/2007/08/22/sca..._0822hack.html

Security
America's Hackable Backbone
Andy Greenberg, 08.22.07, 6:00 PM ET


The first time Scott Lunsford offered to hack into a nuclear power station, he was told it would be impossible. There was no way, the plant's owners claimed, that their critical components could be accessed from the Internet. Lunsford, a researcher for IBM's Internet Security Systems, found otherwise.

"It turned out to be one of the easiest penetration tests I'd ever done," he says. "By the first day, we had penetrated the network. Within a week, we were controlling a nuclear power plant. I thought, 'Gosh. This is a big problem.'"

In retrospect, Lunsford says--and the Nuclear Regulatory Commission agrees--that government-mandated safeguards would have prevented him from triggering a nuclear meltdown. But he's fairly certain that by accessing controls through the company's network, he could have sabotaged the power supply to a large portion of the state. "It would have been as simple as closing a valve," he says.

In Pictures: America's Hackable Backbone
The disturbingly vulnerable system that Lunsford hijacked is powered by Supervisory Control and Data Acquisition software, or SCADA, a type of software made by companies including Siemens, ABB, Rockwell Automation and Emerson.

SCADA systems are used around the country to control infrastructure like water filtration and distribution, trains and subways, natural gas and oil pipelines, and practically every kind of industrial manufacturing. And as some security professionals are pointing out, those weaknesses are increasingly connected to the Internet, leaving large parts of America's critical infrastructure exposed to anyone with moderate information technology training and a laptop.

At the DefCon hacker conference earlier this month, security researcher Ganesh Devarajan gave a presentation detailing how researchers can find flaws in SCADA systems using "fuzzing," a technique that floods software with data and tracks which input causes a crash, allowing hackers to inject their own commands.

"These are simple bugs, but very dangerous ones," says Devarajan, associate security analyst at 3Com-owned security firm TippingPoint. He says he's alerted SCADA software vendors to all the flaws he's found, but he nonetheless imagines a scenario in which someone plants a contaminant in a water reservoir and hacks into water-quality sensor systems to prevent detection. "If someone can provide false data," he says, "They own the system."

To be sure, the threat of attacks on major SCADA systems isn't entirely new, and the wave of cyberterrorism predictions that followed Sept. 11, 2001, have largely been dismissed as hype and paranoia. But given SCADA systems' vulnerability, many experts wonder why those attacks haven't yet materialized.

One answer may be the sheer complexity of major infrastructure systems: Though SCADA computers have weak external security, controlling them takes engineering expertise. Most hackers could only gain enough control to create the fear that they're capable of something worse, says Alan Paller, director of the SANS Institute.

That means that even if outright attacks aren't increasing, there's a growing threat of extortion, says Paller. In fact, the SANS Institute hosts a crisis response center for cyberattacks, and Paller says he's learned of multiple threats within the last year and a half from hackers claiming to have infiltrated SCADA systems and demanding ransom. Other shakedowns have likely gone unreported.

Paller predicts that those incidents will increase. "There's been very active and sophisticated chatter in the hacker community, trading exploits on how to break through capabilities on these systems," he says. "That kind of chatter usually precedes bad things happening."

Extortion is more than an economic problem; racketeers could easily trigger an accident while trying to demonstrate control over a facility, says Marcus Ranum, chief security officer for Tenable Security. "To spin a pump or move a valve, you don't have to be a petroleum engineer," he says. "Then again, you could spin the wrong pump and blow something up."

Not every SCADA sabotage scenario is so hypothetical. In 2000, Vitek Boden, a 48-year-old man fired from his job at a sewage-treatment plant in Australia, remotely accessed his former workplace's computers and poured toxic sludge into parks and rivers; he hoped the plant would re-hire him to solve the leakage problem.

In January of 2003, computers infected with the Slammer worm shut down safety display systems at the Davis-Besse power plant in Ohio, though the plant was already shut down at the time. Seven months later, another computer virus was widely suspected by security researchers of leading to a power loss at a plant providing electricity to parts of New York State, despite the Nuclear Regulatory Commission's argument that no evidence of virus-involvement was found.

SCADA systems' lack of security features is a symptom of their age; most were developed at a time when critical infrastructure systems weren't connected to the Internet and needed no intrusion prevention. Some have a 20-year life span, making them obsolete for years after they're installed. And many of the companies that develop SCADA software make installing security patches difficult or, fearing that patches will hamper the software's operation, don't offer customer support for patched systems.

All of which still leaves U.S. infrastructure open to crippling attacks by criminal hackers or cyberterrorists, says Jim Christy, director of future exploration at the Department of Defense's Cyber Crime Center. "This is an Achille's heel for several of our critical systems," Christy says. "Nation-states and terrorist organizations are definitely looking at this as an option, a weapon of mass disruption."

That kind of risk means major security changes are necessary, says Christy. But because SCADA systems are largely owned by the private sector, critical infrastructure like power plants and water systems may remain vulnerable until the problem affects profits--or leads to disaster. Christy argues that we can't wait that long: His unofficial opinion is that SCADA needs government regulation.

"The government mandates fire sprinklers. Those cost builders money, but they save property and lives," he says. "If critical infrastructure is important to our national security, shouldn't there be minimum standards it has to meet?"
Posts: 24,799
jAZ has just been standing around suckin' on a big ol' chili dog.jAZ has just been standing around suckin' on a big ol' chili dog.jAZ has just been standing around suckin' on a big ol' chili dog.jAZ has just been standing around suckin' on a big ol' chili dog.jAZ has just been standing around suckin' on a big ol' chili dog.jAZ has just been standing around suckin' on a big ol' chili dog.jAZ has just been standing around suckin' on a big ol' chili dog.jAZ has just been standing around suckin' on a big ol' chili dog.jAZ has just been standing around suckin' on a big ol' chili dog.jAZ has just been standing around suckin' on a big ol' chili dog.jAZ has just been standing around suckin' on a big ol' chili dog.
    Reply With Quote
Old 08-24-2007, 03:14 PM   #2
bishop_74 bishop_74 is offline
Veteran
 
bishop_74's Avatar
 

Join Date: Aug 2000
Location: Denver, CO. USA
Casino cash: $8684993
I must remember to thank Forbes for writing an article on it before it was secured.
Posts: 3,642
bishop_74 's adopt a chief was Sabby Piscitellibishop_74 's adopt a chief was Sabby Piscitellibishop_74 's adopt a chief was Sabby Piscitellibishop_74 's adopt a chief was Sabby Piscitellibishop_74 's adopt a chief was Sabby Piscitellibishop_74 's adopt a chief was Sabby Piscitellibishop_74 's adopt a chief was Sabby Piscitellibishop_74 's adopt a chief was Sabby Piscitellibishop_74 's adopt a chief was Sabby Piscitellibishop_74 's adopt a chief was Sabby Piscitellibishop_74 's adopt a chief was Sabby Piscitelli
    Reply With Quote
Old 08-24-2007, 03:19 PM   #3
CoMoChief CoMoChief is offline
Mahomes Dynasty
 
CoMoChief's Avatar
 

Join Date: Mar 2005
Location: Parts Unknown
Casino cash: $8052254
Holy shit.
__________________
Posts: 39,156
CoMoChief is too fat/Omaha.CoMoChief is too fat/Omaha.CoMoChief is too fat/Omaha.CoMoChief is too fat/Omaha.CoMoChief is too fat/Omaha.CoMoChief is too fat/Omaha.CoMoChief is too fat/Omaha.CoMoChief is too fat/Omaha.CoMoChief is too fat/Omaha.CoMoChief is too fat/Omaha.CoMoChief is too fat/Omaha.
    Reply With Quote
Old 08-24-2007, 03:20 PM   #4
DMAC DMAC is offline
MVP
 
DMAC's Avatar
 

Join Date: Sep 2005
Location: Springfield, MO
Casino cash: $10008735
Thanks for sharing...TO THE WORLD!
Posts: 11,651
DMAC 's phone was tapped by Scott Pioli.DMAC 's phone was tapped by Scott Pioli.DMAC 's phone was tapped by Scott Pioli.DMAC 's phone was tapped by Scott Pioli.DMAC 's phone was tapped by Scott Pioli.DMAC 's phone was tapped by Scott Pioli.DMAC 's phone was tapped by Scott Pioli.DMAC 's phone was tapped by Scott Pioli.DMAC 's phone was tapped by Scott Pioli.DMAC 's phone was tapped by Scott Pioli.DMAC 's phone was tapped by Scott Pioli.
    Reply With Quote
Old 08-24-2007, 03:20 PM   #5
Mr. Laz Mr. Laz is offline
Don't Tease Me
 
Mr. Laz's Avatar
 

Join Date: Dec 2000
Location: KS
Casino cash: $11047037
yikes
__________________
Posts: 95,626
Mr. Laz is obviously part of the inner Circle.Mr. Laz is obviously part of the inner Circle.Mr. Laz is obviously part of the inner Circle.Mr. Laz is obviously part of the inner Circle.Mr. Laz is obviously part of the inner Circle.Mr. Laz is obviously part of the inner Circle.Mr. Laz is obviously part of the inner Circle.Mr. Laz is obviously part of the inner Circle.Mr. Laz is obviously part of the inner Circle.Mr. Laz is obviously part of the inner Circle.Mr. Laz is obviously part of the inner Circle.
    Reply With Quote
Old 08-24-2007, 03:21 PM   #6
Eleazar Eleazar is offline
Beyond the Rapids
 
Eleazar's Avatar
 

Join Date: May 2003
Location: Langley, VA
Casino cash: $-370000
Welp, better shut'em all down. Grass hut time boys.
Posts: 80,659
Eleazar is obviously part of the inner Circle.Eleazar is obviously part of the inner Circle.Eleazar is obviously part of the inner Circle.Eleazar is obviously part of the inner Circle.Eleazar is obviously part of the inner Circle.Eleazar is obviously part of the inner Circle.Eleazar is obviously part of the inner Circle.Eleazar is obviously part of the inner Circle.Eleazar is obviously part of the inner Circle.Eleazar is obviously part of the inner Circle.Eleazar is obviously part of the inner Circle.
    Reply With Quote
Old 08-24-2007, 03:25 PM   #7
Donger Donger is offline
"Think BOOM!"
 
Donger's Avatar
 

Join Date: Nov 2003
Location: 33.675° N 106.475° W
Casino cash: $10379900
VARSITY
Having SCADA systems accessible through the Internet is really bad idea. I work (in a roundabout way) in the SCADA world, and you'd be amazed how many are IP-based and completely open to the world.

Oh, and the title is misleading. He probably only had access to the plant's HMI, not the reactor itself.
__________________
I think the young people enjoy it when I "get down," verbally, don't you?
Posts: 180,652
Donger is obviously part of the inner Circle.Donger is obviously part of the inner Circle.Donger is obviously part of the inner Circle.Donger is obviously part of the inner Circle.Donger is obviously part of the inner Circle.Donger is obviously part of the inner Circle.Donger is obviously part of the inner Circle.Donger is obviously part of the inner Circle.Donger is obviously part of the inner Circle.Donger is obviously part of the inner Circle.Donger is obviously part of the inner Circle.
    Reply With Quote
Old 08-24-2007, 03:28 PM   #8
Frazod Frazod is offline
WE ARE THE CHAMPIONS
 
Frazod's Avatar
 

Join Date: Aug 2000
Casino cash: $3155085
Quote:
Originally Posted by Donger
Having SCADA systems accessible through the Internet is really bad idea. I work (in a roundabout way) in the SCADA world, and you'd be amazed how many are IP-based and completely open to the world.

Oh, and the title is misleading. He probably only had access to the plant's HMI, not the reactor itself.
I was thinking this while I was reading the article. Just because something can be made accessible to the internet, does it HAVE to be accessible to the internet? This just seems stupid.

Seems like these guys could take a page from Battlestar Galactica and unplug their computers.
Posts: 119,484
Frazod is obviously part of the inner Circle.Frazod is obviously part of the inner Circle.Frazod is obviously part of the inner Circle.Frazod is obviously part of the inner Circle.Frazod is obviously part of the inner Circle.Frazod is obviously part of the inner Circle.Frazod is obviously part of the inner Circle.Frazod is obviously part of the inner Circle.Frazod is obviously part of the inner Circle.Frazod is obviously part of the inner Circle.Frazod is obviously part of the inner Circle.
    Reply With Quote
Old 08-24-2007, 03:29 PM   #9
htismaqe htismaqe is offline
'Tis my eye!
 
htismaqe's Avatar
 

Join Date: Aug 2000
Location: Chiefsplanet
Casino cash: $10269900
SCADA + Internet = bad

At least put them behind some security...
Posts: 100,022
htismaqe is obviously part of the inner Circle.htismaqe is obviously part of the inner Circle.htismaqe is obviously part of the inner Circle.htismaqe is obviously part of the inner Circle.htismaqe is obviously part of the inner Circle.htismaqe is obviously part of the inner Circle.htismaqe is obviously part of the inner Circle.htismaqe is obviously part of the inner Circle.htismaqe is obviously part of the inner Circle.htismaqe is obviously part of the inner Circle.htismaqe is obviously part of the inner Circle.
    Reply With Quote
Old 08-24-2007, 03:30 PM   #10
talastan talastan is offline
Manning, we're coming for you!
 
talastan's Avatar
 

Join Date: Jul 2006
Location: Springfield, Mo
Casino cash: $10004950
But of course we're safe from terrorist attacks....??Right??
__________________
Can we please just draft AND DEVELOP a QB - est. since 1983

Check out my band:

Truett and the Traitors
Posts: 4,815
talastan has just been standing around suckin' on a big ol' chili dog.talastan has just been standing around suckin' on a big ol' chili dog.talastan has just been standing around suckin' on a big ol' chili dog.talastan has just been standing around suckin' on a big ol' chili dog.talastan has just been standing around suckin' on a big ol' chili dog.talastan has just been standing around suckin' on a big ol' chili dog.talastan has just been standing around suckin' on a big ol' chili dog.talastan has just been standing around suckin' on a big ol' chili dog.talastan has just been standing around suckin' on a big ol' chili dog.talastan has just been standing around suckin' on a big ol' chili dog.talastan has just been standing around suckin' on a big ol' chili dog.
    Reply With Quote
Old 08-24-2007, 03:31 PM   #11
Donger Donger is offline
"Think BOOM!"
 
Donger's Avatar
 

Join Date: Nov 2003
Location: 33.675° N 106.475° W
Casino cash: $10379900
VARSITY
Quote:
Originally Posted by frazod
I was thinking this while I was reading the article. Just because something can be made accessible to the internet, does it HAVE to be accessible to the internet? This just seems stupid.

Seems like these guys could take a page from Battlestar Galactica and unplug their computers.
Most do it so that operators can access the system remotely. It adds convenience, but obviously can add some other issue as well.
__________________
I think the young people enjoy it when I "get down," verbally, don't you?
Posts: 180,652
Donger is obviously part of the inner Circle.Donger is obviously part of the inner Circle.Donger is obviously part of the inner Circle.Donger is obviously part of the inner Circle.Donger is obviously part of the inner Circle.Donger is obviously part of the inner Circle.Donger is obviously part of the inner Circle.Donger is obviously part of the inner Circle.Donger is obviously part of the inner Circle.Donger is obviously part of the inner Circle.Donger is obviously part of the inner Circle.
    Reply With Quote
Old 08-24-2007, 03:33 PM   #12
Ultra Peanut Ultra Peanut is offline
v^V^v^V^v^V^
 
Ultra Peanut's Avatar
 

Join Date: Aug 2001
Location: Holland*
Casino cash: $10005177
And?
__________________
Posts: 39,518
Ultra Peanut is blessed with 50/50 Hindsight.Ultra Peanut is blessed with 50/50 Hindsight.Ultra Peanut is blessed with 50/50 Hindsight.Ultra Peanut is blessed with 50/50 Hindsight.Ultra Peanut is blessed with 50/50 Hindsight.Ultra Peanut is blessed with 50/50 Hindsight.Ultra Peanut is blessed with 50/50 Hindsight.Ultra Peanut is blessed with 50/50 Hindsight.Ultra Peanut is blessed with 50/50 Hindsight.Ultra Peanut is blessed with 50/50 Hindsight.Ultra Peanut is blessed with 50/50 Hindsight.
    Reply With Quote
Old 08-24-2007, 03:34 PM   #13
htismaqe htismaqe is offline
'Tis my eye!
 
htismaqe's Avatar
 

Join Date: Aug 2000
Location: Chiefsplanet
Casino cash: $10269900
Quote:
Originally Posted by Donger
Most do it so that operators can access the system remotely. It adds convenience, but obviously can add some other issue as well.
There's good ways to secure that, though, too.
Posts: 100,022
htismaqe is obviously part of the inner Circle.htismaqe is obviously part of the inner Circle.htismaqe is obviously part of the inner Circle.htismaqe is obviously part of the inner Circle.htismaqe is obviously part of the inner Circle.htismaqe is obviously part of the inner Circle.htismaqe is obviously part of the inner Circle.htismaqe is obviously part of the inner Circle.htismaqe is obviously part of the inner Circle.htismaqe is obviously part of the inner Circle.htismaqe is obviously part of the inner Circle.
    Reply With Quote
Old 08-24-2007, 03:36 PM   #14
Donger Donger is offline
"Think BOOM!"
 
Donger's Avatar
 

Join Date: Nov 2003
Location: 33.675° N 106.475° W
Casino cash: $10379900
VARSITY
Quote:
Originally Posted by htismaqe
There's good ways to secure that, though, too.
Yeah, but what fun would that be?
__________________
I think the young people enjoy it when I "get down," verbally, don't you?
Posts: 180,652
Donger is obviously part of the inner Circle.Donger is obviously part of the inner Circle.Donger is obviously part of the inner Circle.Donger is obviously part of the inner Circle.Donger is obviously part of the inner Circle.Donger is obviously part of the inner Circle.Donger is obviously part of the inner Circle.Donger is obviously part of the inner Circle.Donger is obviously part of the inner Circle.Donger is obviously part of the inner Circle.Donger is obviously part of the inner Circle.
    Reply With Quote
Old 08-24-2007, 03:40 PM   #15
Frazod Frazod is offline
WE ARE THE CHAMPIONS
 
Frazod's Avatar
 

Join Date: Aug 2000
Casino cash: $3155085
Quote:
Originally Posted by Donger
Yeah, but what fun would that be?
Well, seeing as how I live downwind from a nuclear plant, personally I'd rather not get irradiated by evile hackers just because some nuclear engineer wants to be able to telecommute.
Posts: 119,484
Frazod is obviously part of the inner Circle.Frazod is obviously part of the inner Circle.Frazod is obviously part of the inner Circle.Frazod is obviously part of the inner Circle.Frazod is obviously part of the inner Circle.Frazod is obviously part of the inner Circle.Frazod is obviously part of the inner Circle.Frazod is obviously part of the inner Circle.Frazod is obviously part of the inner Circle.Frazod is obviously part of the inner Circle.Frazod is obviously part of the inner Circle.
    Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is On

Forum Jump




All times are GMT -6. The time now is 05:37 AM.


This is a test for a client's site.
Fort Worth Texas Process Servers
Covering Arlington, Fort Worth, Grand Prairie and surrounding communities.
Tarrant County, Texas and Johnson County, Texas.
Powered by vBulletin® Version 3.8.8
Copyright ©2000 - 2024, vBulletin Solutions, Inc.