Rugged OS (industry, military & power plant OS) has backdoor into SCADA networks
seclists.org
seclists.org
BTW - RuggedCom was recently sold to Siemens for C$382 million - hope they have informed them about this issue otherwise I guess it soon will be lawyer time.
In any case, someone is RuggedCom should be fired for doing nothing about this. My impression after reading the Seclist notice is that they were playing a waiting game.
"Factory" user/password combinations have long been a problem - often not revealed to the purchaser of the equipment[1][2]. This one is especially bad because it cannot be disabled even if the user knows about it.
[1] http://all.net/CID/Attack/papers/BadDefaults.html
[2] Oracle is notorious for default users/passwords http://www.petefinnigan.com/default/default_password_list.ht...
Not a good day.
There are often no "admins" of these systems. They are installed, the support contract lapses, and they continue to run—vulnerabilities and all. Sometimes there may have been an air-gap, but a desire for remote management results in a 'net link being connected. A VPN or firewall is typically the only security in-place.
The systems often run beyond what we in IT could call a sensible shelf live, because they're the control system for a major plant or piece of infrastructure. Shutting them down to do the upgrade bears a cost of its own (note that I am not condoning this behaviour).
It's disappointing, and dangerous, but hopefully as we move to more generalised hardware and IE60850/IP (over ModBus, DNP3, etc) solutions, things will improve. I think some organisations are running a race they're destined to lose though, especially as intruders set their sights on these weaknesses.
"Workarounds: ROS users can disable the rsh service and set the number of allowed telnet connections to 0."
there is currently no solution available.
Solution We are currently unaware of a practical solution to this problem.
What's the point of a remote management switch you can't access?
"...An attacker with knowledge of an ROS device's MAC address may be able to gain complete administrative control of the device..."
From my experience most of these devices are read-only monitors, but I'm sure there are exceptions. This little issue could be a big deal for their certification. I'm surprised they didn't take it more seriously. This is the hackers-will-take-over-our-power-grid kind of scenario the public doesn't like to think about.
That's probably simple enough that even I could read it in assembly and figure it out. I don't know if getting a firmware image is difficult, but the actual generator certainly isn't the hard part here.
I'm wondering if that modulo value has any meaning - looking at it in a few different formats hasn't immediately struck any sparks with me.
Downvote? People don't watch the classics anymore!
It's a prime number, close to 1 billion