Wilders Security Forums  

Go Back   Wilders Security Forums > Other Security Topics > other security issues & news
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old April 10th, 2008, 04:17 PM
lucas1985's Avatar
lucas1985 lucas1985 is offline
Global Moderator
 
Join Date: Nov 2006
Location: France, May 1968
Posts: 4,047
Default White hat hackers infiltrate a power grid in one day

Quote:
In a matter of hours, the team infiltrated the grid's supervisory, control and data acquisition (SCADA) networks using simple phishing tools: social engineering and browser exploits.

Social Engineering is seen by many as a glamorized confidence trick. The penetration team checked distribution lists for SCADA user groups, harvested appropriate email addresses, and then employed a simple trick to gain the targeted user's access. Employees were sent an e-mail about a plan to cut their benefits which included a link to a Web site with "more information." The address linked to a malware that granted the hackers remote access. The trick was effective within minutes.
Quote:
These SCADA systems suffer the same vulnerabilities any system does that runs on the same standard operating system and server hardware. Companies have perpetuated the weakness of these systems by not performing important software upgrades because they would force downtime.
Full article
__________________
"Pouvoir à l'Imagination. Power to the imagination. La imaginación al poder".

"Perfect is the enemy of good enough". Voltaire.
  #2  
Old April 10th, 2008, 04:38 PM
Pedro's Avatar
Pedro Pedro is offline
Massive Poster
 
Join Date: Nov 2006
Posts: 3,492
Default Re: White hat hackers infiltrate a power grid in one day

I think the problem is we're talking about the same network, the internet.
Some things probably shouldn't be connected. Cost and efficiency is definitely a factor, but.. one should analyze a problem from all angles.
  #3  
Old April 10th, 2008, 05:41 PM
lucas1985's Avatar
lucas1985 lucas1985 is offline
Global Moderator
 
Join Date: Nov 2006
Location: France, May 1968
Posts: 4,047
Default Re: White hat hackers infiltrate a power grid in one day

Quote:
Originally Posted by Pedro
I think the problem is we're talking about the same network, the internet.
Some things probably shouldn't be connected. Cost and efficiency is definitely a factor, but.. one should analyze a problem from all angles.
Sure
Add basic education (social engineering was their weapon), patch policy (vulnerable systems aren't patched because of downtime), etc.
__________________
"Pouvoir à l'Imagination. Power to the imagination. La imaginación al poder".

"Perfect is the enemy of good enough". Voltaire.
  #4  
Old April 12th, 2008, 12:53 PM
Rasheed187 Rasheed187 is offline
Very Frequent Poster
 
Join Date: Jul 2004
Location: The Netherlands
Posts: 1,883
Default Re: White hat hackers infiltrate a power grid in one day

They should put one of us in charge, let´s see if hackers can infect machines restricted and controlled by LUA, HIPS/Sandbox and a firewall passing all leaktests!

Last edited by Rasheed187 : April 14th, 2008 at 07:11 PM.
  #5  
Old April 14th, 2008, 06:40 AM
Mrkvonic Mrkvonic is offline
Linux Systems Expert
 
Join Date: May 2005
Posts: 7,428
Default Re: White hat hackers infiltrate a power grid in one day

Hello,
Actually, you don't need any of those. Simply separate extranet from the intranet ... that's it. Remove or disable any peripherals and you have an uncrackable system.
Mrk
__________________
http://www.dedoimedo.com

All your base are belong to us

Linux Systems Expert / Systems Programmer, Linux System Administrator, LPIC-1, LPIC-2 (WIP), GSEC, CCHD, CCHA
  #6  
Old April 14th, 2008, 07:16 PM
Rasheed187 Rasheed187 is offline
Very Frequent Poster
 
Join Date: Jul 2004
Location: The Netherlands
Posts: 1,883
Default Re: White hat hackers infiltrate a power grid in one day

Yes of course, I was just joking (although security tools will always be needed) but I never really understood these kind of news messages, I mean how the heck is it possible that hackers can penetrate for example air traffic control? I think I´ve read about that a while back, looks like they´ve got a couple of idiots in charge.
  #7  
Old April 14th, 2008, 07:30 PM
Carver's Avatar
Carver Carver is offline
Very Frequent Poster
 
Join Date: Feb 2006
Location: USA
Posts: 1,421
Default Re: White hat hackers infiltrate a power grid in one day

Quote:
Originally Posted by Rasheed187
Yes of course, I was just joking (although security tools will always be needed) but I never really understood these kind of news messages, I mean how the heck is it possible that hackers can penetrate for example air traffic control? I think I´ve read about that a while back, looks like they´ve got a couple of idiots in charge.
And people wonder how 9-ll happened, now with computers..well that brings a whole new level of distruction.
 

Wilders Security Forums > Other Security Topics > other security issues & news « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 04:47 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums