4 ms·
Maybe its optimistic, but I'd hope this has caused a big enough stir among people running Siemens installations that they are taking care of this issue. If so,
by bigmac 16y ago
Maybe its optimistic, but I'd hope this has caused a big enough stir among people running Siemens installations that they are taking care of this issue. If so, that will give it a short lifetime. Even if the individual plant admins aren't doing so, Siemens must be taking action here, right?
I guess I'm buying into the idea that its difficult to do attacks against PLC's for SCADA systems. I have to claim ignorance on that issue, but it sure seems like its a hard problem. That difficulty, combined with the relative sophistication of the malware (four 0days, etc) lends credence to the idea that its a targeted attack.
Additionally, releasing malware that targets something like that and then just waiting to see which plants you end up owning seems unlikely. What is the motivation? Once you figure out which ones you own, then you write more custom attacks against those targets?
- dguido 16y agoOne of the exploited bugs is a default admin password in Siemens SCADA equipment. Siemens released a statement shortly after Stuxnet was discovered, urging admins not to change the default password because it might have unexpected consequences. Of course this attack was targeted in the sense that it went after SCADA equipment, but there was far more than a single target. Like I said, this is malware and malware is multi-purpose and reusable, and in this case it was used many, many times. These guys are looking for a story about how a single target was THE target, but they're missing the big picture.