The Register® — Biting the hand that feeds IT

Feeds

SCADA vuln imperils critical infrastructure, feds warn

Secret accounts open control systems to attack

  • print
  • alert

Agentless Backup is Not a Myth

An electronic device used to control machinery in water plants and other industrial facilities contains serious weaknesses that allow attackers to take it over remotely, the US agency that safeguards the nation's critical infrastructure has warned.

Some models of the Modicon Quantum PLC used in industrial control systems contain multiple hidden accounts that use predetermined passwords to grant remote access, the Industrial Control System Cyber Emergency Response Team said in an advisory (PDF) issued on Tuesday. Palatine, Illinois–based Schneider Electric, the maker of the device, has produced fixes for some of the weaknesses and continues to develop additional mitigations.

The PLCs, or programmable logic controllers, reside at the lowest levels of an industrial plant, where computerized sensors meet the valves, turbines, or other machinery that's being controlled. The default passwords are hard-coded into Ethernet cards the systems use to funnel commands into the devices, and temperatures and other data out of them. The Ethernet modules also allow administrators to remotely log into the machinery using protocols such as telnet, FTP, and something called the Windriver Debug port.

According to a blog post published on Monday by independent security researcher Rubén Santamarta, the NOE 100 and NOE 771 modules contain at least 14 hard-coded passwords, some of which are published in support manuals. Even in cases where the passcodes are obscured using cryptographic hashes, they are trivial to recover thanks to documented weaknesses in the underlying VxWorks operating system. As a result, attackers can exploit the weakness to log into devices and gain privileged access to its controls.

Hard-coded passwords are a common weakness built into many industrial control systems, including some S7 series of PLCs from Siemens. Because the systems control the machinery connected to dams, gasoline refineries, and water treatment plants, unauthorized access is considered a national security threat because it could be used to sabotage their operation.

The FBI has said it's investigating claims a Houston, Texas–based water utility was breached last month by someone claiming to have accessed the internet-connected computers that control its generators, blowers, and other sensitive gear.

“Hard-coded backdoor credentials that give you administrator rights to a system are pretty severe,” said K. Reid Wightman, a security assessor with Digital Bond, a consultancy that focuses solely on ICS security. He said it can be hard for attackers to exercise too much control over an ICS by taking over the PLC alone, because there's often no indication what kind of equipment is connected to it.

“You don't have the human machine interface so you don't really know what the PLC is plugged into,” he explained. “I really don't know if the [device] is a release valve, an input valve, or a lightbulb.”

Research Wightman plans to release next month at the SCADA Security Scientific Symposium in Miami could increase the damage that attackers can do after gaining access to many widely used PLCs. Among other things, he said his findings would show how to tamper with the device so that they attack other systems they are attached to.

Indeed, in Monday's blog post, Santamarta said the hard-coded credentials could be exploited to install malicious firmware on the controllers. He also alluded to “non-documented functionalities with security implications” in the Schneider devices. He said he discovered the hidden accounts by reverse engineering the firmware that controls the PLCs.

A rudimentary search on the server search engine known as Shodan revealed what appear to be working links to several of the vulnerable Schneider models. Santamarta said there is no fix for the devices other than to retire the faulty Ethernet cards and replace them with better-designed ones. Tuesday's ICS-CERT advisory said the fixes from Schneider removes the telnet and Windriver services. The advisory made no mention of changes to FTP services. ®

Follow dangoodin001.

Steps to Take Before Choosing a Business Continuity Partner

Anonymous Coward

visit the control room?

... how are they going to do that when control admin has been outsourced to India/wherever?

3
0

I've said it before, and i'll say it again...

Why the HELL are these connected up to a web-facing network? Sounds like something even a secondary-school student would catch as a security risk.

Fine, keep it on an intranet, with maybe a VPN login if you really need it, but this? It just smacks of slap-dash development.

3
0

Idiots ignoring basic design rules

The problem with these systems is the idiots that connect them to the internet . Used as designed (NO INTERNET CONNECTION) PLCs with built in passwords are not a problem. (Earlier PLCs did not even have accounts and passwords as they were designed to be used only on well secured networks with no idiot users.)

If a connection has to be made (to satisfy some hare brained management decision) then it should be by a single - well hardened - Linux system to mitigate as far as possible the ill effects.

3
0

More from The Register

 breaking news
Number of cops abusing Police National Computer access on the rise
Only a telegram from the Queen can get you off it
 breaking news
NSA PRISM snoop-gate: Won't someone think of the children, wails Apple
10,000 things probed, mostly about missing kids, Alzheimer patients, we're told
Flash flaw potentially makes every webcam or laptop a PEEPHOLE
But it's a Google problem - Chrome only, insists Adobe
Internet fraud still stings suckers
Australians twice as gullible as Americans
 breaking news
NSA PRISM-gate: Relax, GCHQ spooks 'keep us safe', says Cameron
Whatever they are up to, it's all above board, we're told
 breaking news
Yahoo! joins! rivals! in! PRISM! data! request! admission!
Keep calm and carry on using American tech firms, folks
PRISM snitch claims NSA hacked Chinese targets since 2009
Snowden suddenly looks safer in Hong Kong after revelations
 breaking news
US chief spook: Look, we only want to spy on 6.66 BEELLLION of you
Americans assured they are not in the NSA's sights
Speech-to-text drives motorists to distraction
Will talking to you mean I crash into that car up ahead, Siri?
DHS warns of vulns in hospital medical equipment
Has your doctor's anasthesia machine been hacked?