<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Darknet - The Darkside &#187; industrial system security</title>
	<atom:link href="http://www.darknet.org.uk/tag/industrial-system-security/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.darknet.org.uk</link>
	<description>Ethical Hacking, Penetration Testing &#38; Computer Security</description>
	<lastBuildDate>Tue, 07 Feb 2012 18:34:17 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Smart Grid Security Risks &#8211; Not So Smart Electricity Meters</title>
		<link>http://www.darknet.org.uk/2009/07/smart-grid-security-risks-not-so-smart-electricity-meters/</link>
		<comments>http://www.darknet.org.uk/2009/07/smart-grid-security-risks-not-so-smart-electricity-meters/#comments</comments>
		<pubDate>Tue, 14 Jul 2009 11:04:43 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[Hardware Hacking]]></category>
		<category><![CDATA[Legal Issues]]></category>
		<category><![CDATA[electricity]]></category>
		<category><![CDATA[electricity grid]]></category>
		<category><![CDATA[electricity grid security]]></category>
		<category><![CDATA[hacking electricity grid]]></category>
		<category><![CDATA[industrial control systems]]></category>
		<category><![CDATA[industrial security]]></category>
		<category><![CDATA[industrial system security]]></category>
		<category><![CDATA[ioactive]]></category>
		<category><![CDATA[mike david]]></category>
		<category><![CDATA[smart grid security]]></category>
		<category><![CDATA[smart grids]]></category>
		<category><![CDATA[smart meter]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=1909</guid>
		<description><![CDATA[You might recall we&#8217;ve discussed the security of Industrial Control Systems before, the latest &#8216;evolution&#8217; is the so called Smart Grid. Which in all honestly, doesn&#8217;t seem to be very smart at all. In basic terms they are trying to turn the power-grid into a two way communication medium so consumers homes can report back [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>You might recall we&#8217;ve discussed the security of <a href="http://www.darknet.org.uk/2009/04/industrial-control-systems-safe-i-think-not/">Industrial Control Systems</a> before, the latest &#8216;evolution&#8217; is the so called Smart Grid.</p>
<p>Which in all honestly, doesn&#8217;t seem to be very smart at all. In basic terms they are trying to turn the power-grid into a two way communication medium so consumers homes can report back to the grid what they are using and they can be disconnected via software rather than requiring physical intervention.</p>
<p>The scary part is there&#8217;s no encryption and many things are done without authentication, meaning with a little reverse engineering you can probably shut down the power to anyone on the <em>not-so-smart</em> grid.</p>
<blockquote><p>New electricity meters being rolled out to millions of homes and businesses are riddled with security bugs that could bring down the power grid, according to a security researcher who plans to demonstrate several attacks at a security conference next month.</p>
<p>The so-called smart meters for the first time provide two-way communications between electricity users and the power plants that serve them. Prodded by billions of dollars from President Obama&#8217;s economic stimulus package, utilities in Seattle, Houston, Miami, and elsewhere are racing to install them as part of a plan to make the power grid more efficient. Their counterparts throughout Europe are also spending heavily on the new technology.</p>
<p>There&#8217;s just one problem: The newfangled meters needed to make the smart grid work are built on buggy software that&#8217;s easily hacked, said Mike Davis, a senior security consultant for IOActive. The vast majority of them use no encryption and ask for no authentication before carrying out sensitive functions such as running software updates and severing customers from the power grid. The vulnerabilities, he said, are ripe for abuse.
</p></blockquote>
<p>An embedded hardware system that will accept new firmware without authentication and nothing is encrypted? That is a hackers playground!</p>
<p>I hope they consider re-architecting the whole system ASAP on a secure platform and rolling that out as a software update. This is no small matter, this is the power grid we are talking about here &#8211; lives and business can be seriously effected by someone malicious who wanted to screw up the system.</p>
<p>Imagine if you work out the system and get in there first installing your own firmware which won&#8217;t accept any more updates from the main Grid system.</p>
<blockquote><p>&#8220;For an embedded platform, they&#8217;re kind of scary,&#8221; he said. &#8220;It&#8217;s really not designed from the ground up for security. Just imagine if somebody is outside your house and has the unique identifier that&#8217;s printed on your meter.&#8221;</p>
<p>Companies that make gear for smart grids include GE Energy, The ABB Group, Sensus Metering, Itron and Landis+Gyr</p>
<p>One deficiency common among many of the meters is the use of insecure programming functions, such as memcpy() and strcpy(), which are two of the most common sources of exploitable software bugs. In many cases, the devices use general purpose hardware and software that aren&#8217;t designed for highly targeted or mission critical systems.</p></blockquote>
<p>And all paid for by the new president and his generous stimulus packages. It seems like the whole thing has been taped together with band-aids.</p>
<p>There&#8217;s no excuse at all for using insecure programming functions in this day and age, I mean it&#8217;s 2009 for goodness sake.</p>
<p>How long has C programming been around now? And the concept of security and secure programming, especially for critical infrastructure systems like this.</p>
<p></p>
<p>Source: <a href="http://www.theregister.co.uk/2009/06/12/smart_grid_security_risks/">The Register</a> (<em>Thanks Alan</em>)</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Smart+Grid+Security+Risks+%E2%80%93+Not+So+Smart+Electricity+Meters+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D1909+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2009/07/smart-grid-security-risks-not-so-smart-electricity-meters/&amp;t=Smart+Grid+Security+Risks+%E2%80%93+Not+So+Smart+Electricity+Meters" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2009/07/smart-grid-security-risks-not-so-smart-electricity-meters/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2009/07/smart-grid-security-risks-not-so-smart-electricity-meters/&amp;title=Smart+Grid+Security+Risks+%E2%80%93+Not+So+Smart+Electricity+Meters" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2009/07/smart-grid-security-risks-not-so-smart-electricity-meters/&amp;title=Smart+Grid+Security+Risks+%E2%80%93+Not+So+Smart+Electricity+Meters" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2009/07/smart-grid-security-risks-not-so-smart-electricity-meters/&amp;title=Smart+Grid+Security+Risks+%E2%80%93+Not+So+Smart+Electricity+Meters" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2009/07/smart-grid-security-risks-not-so-smart-electricity-meters/&amp;title=Smart+Grid+Security+Risks+%E2%80%93+Not+So+Smart+Electricity+Meters" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2009%2F07%2Fsmart-grid-security-risks-not-so-smart-electricity-meters%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2009/07/smart-grid-security-risks-not-so-smart-electricity-meters/feed/</wfw:commentRss>
		<slash:comments>4</slash:comments>
		</item>
		<item>
		<title>Industrial Control Systems Safe? I Think Not</title>
		<link>http://www.darknet.org.uk/2009/04/industrial-control-systems-safe-i-think-not/</link>
		<comments>http://www.darknet.org.uk/2009/04/industrial-control-systems-safe-i-think-not/#comments</comments>
		<pubDate>Tue, 28 Apr 2009 08:52:41 +0000</pubDate>
		<dc:creator>Darknet</dc:creator>
				<category><![CDATA[General Hacking]]></category>
		<category><![CDATA[Hardware Hacking]]></category>
		<category><![CDATA[control systems]]></category>
		<category><![CDATA[control systems security]]></category>
		<category><![CDATA[hacking control systems]]></category>
		<category><![CDATA[hacking power stations]]></category>
		<category><![CDATA[industrial control systems]]></category>
		<category><![CDATA[industrial system security]]></category>
		<category><![CDATA[power station security]]></category>

		<guid isPermaLink="false">http://www.darknet.org.uk/?p=1739</guid>
		<description><![CDATA[It seems like there is some serious hacking going on, attacks on power stations and industrial control systems. You&#8217;d think most of these systems would be offline, or at least behind a solid DMZ. But as we&#8217;ve seen before they often get exposed by people plugging into the LAN then accessing the net through dial-up [...]]]></description>
			<content:encoded><![CDATA[<p></p>
<p>It seems like there is some serious hacking going on, attacks on power stations and industrial control systems.</p>
<p>You&#8217;d think most of these systems would be offline, or at least behind a solid DMZ. But as we&#8217;ve seen before they often get exposed by people plugging into the LAN then accessing the net through dial-up or nowadays through mobile data (HSDPA/3G etc.).</p>
<p>The sad thing is deaths have actually resulted from such intrusions.</p>
<blockquote><p>The networks powering industrial control systems have been breached more than 125 times in the past decade, with one resulting in U.S. deaths, a control systems expert said Thursday.</p>
<p>Joseph Weiss, managing partner of control systems security consultancy Applied Control Solutions, didn&#8217;t detail the breach that caused deaths during his testimony before a U.S. Senate committee, but he did say he&#8217;s been able to find evidence of more than 125 control systems breaches involving systems in nuclear power plants, hydroelectric plants, water utilities, the oil industry and agribusiness.</p>
<p>&#8220;The impacts have ranged from trivial to significant environmental damage to significant equipment damage to deaths,&#8221; he told the Senate Commerce, Science and Transportation Committee. &#8220;We&#8217;ve already had a cyber incident in the United States that has killed people.&#8221;</p></blockquote>
<p>More than 125 breaches? That&#8217;s quite a significant number. The scary part is the Nuclear plants, imagine if a cyberterrorist or hacker can cause a Nuclear meltdown or malfunction in a Nuclear facility?</p>
<p>I&#8217;d like to see the US government look into this area a little more and perhaps implement some new standards for Control System security.</p>
<p>It&#8217;s an area that really needs tighter security and legislation.</p>
<blockquote><p>At other times, Weiss has talked about a June 1999 gasoline pipeline rupture near Bellingham, Washington. That rupture spilled more than 200,000 gallons of gasoline into two creeks, which ignited and killed three people. Investigators found several problems that contributed to the rupture, but Weiss has identified a computer failure in the pipeline&#8217;s central control room as part of the problem.</p>
<p>It could take the U.S. a long time to dig out from coordinated attacks on infrastructure using control systems, Weiss told senators. Damaged equipment could take several weeks to replace, he said. A coordinated attack &#8220;could be devastating to the U.S. economy and security,&#8221; he said. &#8220;We&#8217;re talking months to recover. We&#8217;re not talking days.&#8221;</p>
<p>The industrial control system industry is years behind the IT industry in protecting cybersecurity, and some of the techniques used in IT security would damage control systems, Weiss added. &#8220;If you penetration-test a legacy industrial control system, you will shut it down or kill it,&#8221; he said. &#8220;You will be your own hacker.&#8221;</p></blockquote>
<p>The problem with these kind of attacks is they might involve multiple vectors in one attack which means it takes a long long time to investigate and work out what actually happened.</p>
<p>It&#8217;s backwards too because Industrial Control Systems are so important in our lives but their security is so so far behind.</p>
<p>Definitely an area to watch, I hope some positive improvements are made.</p>
<p></p>
<p>Source: <a href="http://www.cio.com/article/print/485615">CIO</a> (<em>Thanks Navin</em>)</p>
<div class="tweetthis" style="text-align:left;"><p> <a class="tt" href="http://twitter.com/intent/tweet?text=Industrial+Control+Systems+Safe%3F+I+Think+Not+http%3A%2F%2Fdarknet.org.uk%2F%3Fp%3D1739+from+%40THEdarknet" title="Post to Twitter"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/twitter/tt-twitter-micro3.png" alt="Post to Twitter" /></a> <a class="tt" href="http://www.facebook.com/share.php?u=http://www.darknet.org.uk/2009/04/industrial-control-systems-safe-i-think-not/&amp;t=Industrial+Control+Systems+Safe%3F+I+Think+Not" title="Post to Facebook"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/facebook/tt-facebook-micro3.png" alt="Post to Facebook" /></a> <a class="tt" href="http://www.google.com/buzz/post?url=http://www.darknet.org.uk/2009/04/industrial-control-systems-safe-i-think-not/&amp;imageurl=" title="Post to Google Buzz"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/gbuzz/tt-gbuzz-micro3.png" alt="Post to Google Buzz" /></a> <a class="tt" href="http://delicious.com/post?url=http://www.darknet.org.uk/2009/04/industrial-control-systems-safe-i-think-not/&amp;title=Industrial+Control+Systems+Safe%3F+I+Think+Not" title="Post to Delicious"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/delicious/tt-delicious-micro3.png" alt="Post to Delicious" /></a> <a class="tt" href="http://digg.com/submit?url=http://www.darknet.org.uk/2009/04/industrial-control-systems-safe-i-think-not/&amp;title=Industrial+Control+Systems+Safe%3F+I+Think+Not" title="Post to Digg"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/digg/tt-digg-micro3.png" alt="Post to Digg" /></a> <a class="tt" href="http://reddit.com/submit?url=http://www.darknet.org.uk/2009/04/industrial-control-systems-safe-i-think-not/&amp;title=Industrial+Control+Systems+Safe%3F+I+Think+Not" title="Post to Reddit"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/reddit/tt-reddit-micro3.png" alt="Post to Reddit" /></a> <a class="tt" href="http://stumbleupon.com/submit?url=http://www.darknet.org.uk/2009/04/industrial-control-systems-safe-i-think-not/&amp;title=Industrial+Control+Systems+Safe%3F+I+Think+Not" title="Post to StumbleUpon"><img class="nothumb" src="http://www.darknet.org.uk/wp-content/plugins/tweet-this/icons/en/su/tt-su-micro3.png" alt="Post to StumbleUpon" /></a></p></div><div class="AWD_like_button "><iframe src="http://www.facebook.com/plugins/like.php?href=http%3A%2F%2Fwww.darknet.org.uk%2F2009%2F04%2Findustrial-control-systems-safe-i-think-not%2F&amp;send=false&amp;layout=standard&amp;width=&amp;show_faces=false&amp;action=like&amp;colorscheme=light&amp;font=arial&amp;height=40" scrolling="no" frameborder="0" style="border:none; overflow:hidden; width:px; height:40px;" allowTransparency="true"></iframe></div>]]></content:encoded>
			<wfw:commentRss>http://www.darknet.org.uk/2009/04/industrial-control-systems-safe-i-think-not/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
	</channel>
</rss>

