Showing posts with label scada. Show all posts
Showing posts with label scada. Show all posts

20131227

#1 ICS and SCADA Security Myth: Protection by Air Gap

In his blog article, Fix the Problem, Stop Bailing out Vendors, Dale Peterson made a brief comment about “fantasy of the air gap”. It was an important comment, but one I think got lost in the other messages Dale offered. So today, I am going to focus on the topic of air gaps.

The existence of an “air gap” between control system networks and the rest of the world has been one of the most enduring fairy tales in the field of SCADA / ICS security. The idea is that in a properly designed system, there is a physical gap between the control network and the business network. Since digital information cannot cross such a gap, bad things like hackers and worms can never get into critical control systems. From this, a corollary flows: “Companies that get worms in their systems obviously have not created the proper air gap and deserved to be infected.”

Now there are many materials supporting the idea of the air gap. Every week a new SCADA and ICS vulnerability notice comes out and every week end users get to read statements like this:

“In addition, it is important to ensure your automation network is protected from unauthorized access using the strategies suggested in this document or isolate the automation network from all other networks using an air gap...”

http://www.blog.beldensolutions.com/1-ics-and-scada-security-myth-protection-by-air-gap/

20120427

Full Disclosure: RuggedCom - Backdoor Accounts in my SCADA network? You don't say...

Author: jc
Organization: JC CREW
Date: April 23, 2012
CVE: CVE-2012-1803

Background:
RuggedCom is one of a handful of networking vendors who capitalize on
the market for "Industrial Strength" and "Hardened" networking
equipment. You'll find their gear installed in traffic control
systems, railroad communications systems, power plants, electrical
substations, and even US military sites. Beyond simple L2 and L3
networking these devices are also used for serial-to-ip converstion in
SCADA systems and they even support modbus and dnp3. RuggedCom
published a handy guide to some of their larger customers at
www.ruggedcom.com/about/customers/. My favorite quote is from a
contractor who installed RuggedCom equipment at a US Air Force base:
"Reliability was not an option." How unfortunately apropos.

Problem:
An undocumented backdoor account exists within all released versions
of RuggedCom's Rugged Operating System (ROS®). The username for the
account, which cannot be disabled, is "factory" and its password is
dynamically generated based on the device's MAC address. Multiple
attempts have been made in the past 12 months to have this backdoor
removed and customers notified...

http://seclists.org/fulldisclosure/2012/Apr/277