Serial Port Scans Find More Than 100,000 Hackable Devices
forbes.com
forbes.com
Fortunately, I was rewarded for being paranoid and doing everything I could to lock these devices down pre-deployment as none of them were vulnerable to these attacks. It was certainly a stressful day as I checked each of them one by one, though.
[0]: https://community.rapid7.com/community/metasploit/blog/2013/...
I'm using the devices shown in the bottom of the picture at http://www.digi.com/products/wireless-routers-gateways/routi...
These electrical substations are in the "middle of nowhere". We can't exactly call up the cable or telephone companies and get an Internet connection installed. Fortunately, cellular service is available, even though it is extremely slow in some of these locations.
The devices are, at their most basic, cellular routers -- a LAN port on one side connects to the industrial equipment equipment and the device connects to the cellular network to give them Internet access. An IPSec VPN from the device back to the utility's office provides a connection to their management software so that they can communicate with the industrial equipment.
The industrial gear is "smart". Need to disconnect a customer because they didn't pay their bill? Send out a digital message and their electricity gets shut off. Huge storm roll through the area? They can quickly see how many customers -- and where -- are without power.
IP connectivity to the industrial equipment means they can control everything from their main office and not have to do a "truck roll" for every service change and such, saving them tons of time and money.
If anyone wants the big talk HD gave on this, it was the keynote for 2012 DerbyCon.
Here's the slides.
https://speakerdeck.com/hdm/derbycon-2012-the-wild-west
It starts out really fluffy and eventually he gets to the good stuff (i.e. old grandmas computers from 1998 that are still online)
1. All devices running linux will have /dev/console tied to UART.
2. For others, typically a printf routine would write to UART.
The problem the article talks about occurs when the OEM "forgets" to turn off the UART (either in software or just by breaking the pins during manufacturing).
Did you read the article? He's not hacking commercial/industrial devices like gas pumps by driving to a gas station and using a USB-serial adapter to physically attach a laptop or smartphone.
Rather, the owners of the gas pumps legitimately attached a serial-to-Ethernet translator themselves to allow applications on their TCP/IP network to control the gas pump hardware. But they didn't secure the connection with an effective firewall or authentication requirement, so now not just the legitimate application, but anyone on the public Internet, can send commands to the pump.