Showing posts with label PLC. Show all posts
Showing posts with label PLC. Show all posts

Thursday, December 1, 2011

DHS and FBI have disputed that the Springfield, Illinois incident was a cyberattack

Apparent cyberattack destroys pump at Illinois water utility

A pump at a public water utility in Springfield, Illinois was destroyed after cyberattackers gained access to a SCADA system controlling the device, according to a security expert who obtained an official report on the incident.

CS-CERT has released the following statement saying that DHS and FBI have disputed that the Springfield, Illinois incident was a cyberattack.

ICS-CERT is assisting the FBI to gather more information about the separate Houston incident.

>UPDATE - Recent Incidents Impacting Two Water Utilities
ICSJWG Communications [ICSJWG.Communications@HQ.DHS.GOV]


Greetings:

After detailed analysis, DHS and the FBI have found no evidence of a cyber intrusion into the SCADA system of the Curran-Gardner Public Water District in Springfield, Illinois.

There is no evidence to support claims made in the initial Fusion Center report – which was based on raw, unconfirmed data and subsequently leaked to the media – that any credentials were stolen, or that the vendor was involved in any malicious activity that led to a pump failure at the water plant. In addition, DHS and FBI have concluded that there was no malicious or unauthorized traffic from Russia or any foreign entities, as previously reported. Analysis of the incident is ongoing and additional relevant information will be released as it becomes available.

In a separate incident, a hacker recently claimed to have accessed an industrial control system responsible for water supply at another U.S. utility. The hacker posted a series of images allegedly obtained from the system. ICS-CERT is assisting the FBI to gather more information about this incident.

ICS-CERT has not received any additional reports of impacted manufacturers of ICS or other ICS related stakeholders related to these events. If DHS ICS-CERT identifies any information about possible impacts to additional entities, it will disseminate timely mitigation information as it becomes available. ICS-CERT encourages those in the industrial control systems community who suspect or detect any malicious activity against/involving control systems to contact ICS-CERT.

Regards,

ICS-CERT
E-mail: ics-cert@dhs.gov
Toll Free: 1-877-776-7585
For CSSP Information and Incident Reporting: www.ics-cert.org

Thursday, September 22, 2011

PLC's have little or no security!!

Luigi Vulnerabilities of ICS products

Italian researcher Luigi Auriemma has released another set of vulnerability advisories and proof of concept exploit code for a variety of ICS products. He is finding overflows on the proprietary services the vendors are writing. You hear often in ICS, “don’t scan it because it will crash”. This is what he is finding, and he says it is not difficult.

This is not to diminish the finding. Sometimes hard evidence like he is presenting is what is needed rather than a generic warning. It is the same rationale why we are doing Project Basecamp even though “everyone knows that PLC’s have little or no security and are easily compromised”.

Luigi is doing a bit more than scanning. He has built up a toolset that he uses against all products, not just ICS. He also then does a bit more work to find where the crash occurred and write up some proof of concept code.

Here is the list of products with vulnerabilities in what we are calling Luigi II:
  • Azeotech DAQFactory
  • Beckhoff TwinCAT
  • Cogent Datahub
  • Measuresoft SCADAPro
  • Progea Movicon
  • Rockwell Automation RSLogix
Most of the products are free or low cost HMI or engineering workstation products. RSLogix is used to configure the RA line of Logix PLC’s which are widely deployed in the critical infrastructure. Beckhoff is the big EtherCAT vendor, a high performance ICS protocol used primarily in manufacturing and in Europe.

The other vendors are smaller, add-on HMI, visualization and data transfer products that are used in either very small systems or as an addition/accessory to a larger system.

ICS-CERT has bulletins out for all the Luigi II advisories, but at this point they are just relaying the information. That may be all that is warranted for this type of vulnerability. ICS-CERT time might be better spent writing a useful and effective bulletin that is still lacking for the Beresford vulns, or even Stuxnet.

Focusing their expertise on the vulns most likely to impact the US critical infrastructure. Finally, no mention of Luigi Auriemma per ICS-CERT policy of only recognizing researchers who coordinate disclosure through them.