Jonathan D. Abolins · @JonAbolins
19 followers · 142 posts · Server infosec.exchange

«A Widespread Logic Controller Flaw Raises the Specter of » -
More than 120 models of Siemens’ S7-1500 PLCs contain a serious vulnerability—and no fix is on the way. wired.com/story/siemens-s7-150

#stuxnet #ics #scada #icssecurity #plcs

Last updated 3 years ago

cynicalsecurity :cm_2: · @cynicalsecurity
986 followers · 3743 posts · Server bsd.network

R. Ma et al., "Towards Comprehensively Understanding the Run-time Security of Programmable Logic Controllers: A 3-year Empirical Study"¹

Programmable Logic Controllers (PLCs) are the core control devices in Industrial Control Systems (ICSs), which control and monitor the underlying physical plants such as power grids. PLCs were initially designed to work in a trusted industrial network, which however can be brittle once deployed in an Internet-facing (or penetrated) network. Yet, there is a lack of systematic empirical analysis of the run-time security of modern real-world PLCs. To close this gap, we present the first large-scale measurement on 23 off-the-shelf PLCs across 13 leading vendors. We find many common security issues and unexplored implications that should be more carefully addressed in the design and implementation. To sum up, the unsupervised logic applications can cause system resource/privilege abuse, which gives adversaries new means to hijack the control flow of a runtime system remotely (without exploiting memory vulnerabilities); 2) the improper access control mechanisms bring many unauthorized access implications; 3) the proprietary or semi-proprietary protocols are fragile regarding confidentiality and integrity protection of run-time data. We empirically evaluated the corresponding attack vectors on multiple PLCs, which demonstrates that the security implications are severe and broad. Our findings were reported to the related parties responsibly, and 20 bugs have been confirmed with 7 assigned CVEs.

__
¹ arxiv.org/abs/2212.14296

#researchpapers #arxiv #scada #ics #plcs

Last updated 3 years ago

Mx. Dahlia · @DahliaRedux
34 followers · 68 posts · Server mastodon.world

I mean, I 'can' do to a certain level... I worked as a maintenance engineer in industry for a while, I know 1990s , basic industrial I can replace components, I can build a and work my way around on 90s builds. I can use and a

I'm just not hot on the side of things. I can do 'settings' 🤣

#tech #plcs #Programmablelogiccontrollers #instrumentation #electrics #electronic #pc #dos #synths #daw #sequencer #software

Last updated 3 years ago

- is evolving and Kyiv is winning.
@ITArmyUKR
targets and hit every day with . Moscow hackers have too many targets and are less effective. H/T
@Cyberknow20
difesaesicurezza.com/en/cyber-

#InfoSec #CyberSecurity #DDoS #OpRussia #Anonymous #plcs #scada #cyberwarfare #Russia #Ukraine

Last updated 3 years ago