8 ms·
Urgent/11 – Zero Day Vulnerabilities Impacting VxWorks
- Arrezz 7y agoThe scale of this is baffling! And from what I've seen in the industrial side of things I doubt that everything will be patched anytime soon sadly.
- sp332 7y agoIf we gave them each an IP address, they'd use around half of the IPv4 address space.
- peterwwillis 7y agoAnd there are many medical devices running on VxWorks. Changes to medical devices can take months to years due to quality testing and recertification. (software changes aren't as bad as a physical change, but it still takes a while)
- raggles 7y agoespecially when many of the devices have to be returned to manufacturer for the update... including a whole bunch of RTUs that run electrical transmission/distribution systems.
- mc32 7y agoOn the industrial side all these devices are in completely segregated airgapped networks. Obviously someone could strike havoc via USB, etc., but it’s not as bad as it could be.
- Xylakant 7y agoI’d expect sonicwall firewalls and xerox printers at least to have network connectivity.
- koolba 7y agoA buck shot approach of mailing malicious USB devices would likely be devastating.
- mc32 7y agoMaybe. But it would have to be smart. These systems are regulated by tight SOPs which don’t allow for the plugging in random USB devices.
- dreamcompiler 7y agoDepends on the org. For some companies, you could drop a few USB devices in the parking lot and they'd be toast. Others fill the USB ports on their computers with epoxy.
- koolba 7y ago> Others fill the USB ports on their computers with epoxy. How do you plug in a mouse or keyboard?
- dreamcompiler 7y agoYou plug those in and epoxy them so they can never be removed.
- closeparen 7y agoInternal networks, yes. Airgapped, probably not.
- dreamcompiler 7y agoWhy do you believe this? Connections between industrial control networks and corporate internet-facing business networks are ubiquitous [0]. They happen because somebody needed a link for convenience and forgot to tell management, or somebody put a wifi router on the IC network just to get their job done. This stuff happens because people act like people, policy be damned. So yeah, this is really, really bad. [0] This is well-established infosec fact. It's not controversial. Latest case I know of was at JPL a few weeks ago. https://duckduckgo.com/?q=jpl+infosec https://duckduckgo.com/?q=jpl+infosec
- mc32 7y agoAgreed. Some orgs are better than others at practicing good security hygiene. The better ones have awareness of their network and have systems monitoring their networks, etc. There are afterall the equivalents of Qualys in the IA world.
- java-man 7y agoWow, I was going to comment "IoT, the 'S' stands for 'security'", but this is about VxWorks, a battle proven (literally) RTOS. This illustrates a point that now, in 2019, there is literally no OS designed for security. I mean, security was never a real goal. Even software specifically written to address security requirements could easily have gaping holes (re Heartbleed)...
- java-man 7y agoI wonder if there is a company that's really interested in developing a secure (by design) operating system. Apart from you-know-who?
- sp332 7y agoOpenBSD?
- java-man 7y agohttps://www.cvedetails.com/vulnerability-list/vendor_id-97/product_id-163/Openbsd-Openbsd.html https://www.cvedetails.com/vulnerability-list/vendor_id-97/p... I might hazard to say that (in my opinion) no OS written in a memory unsafe language is secure by design.
- tadfisher 7y agoTock might fit the bill then (Rust): https://www.tockos.org/documentation/design https://www.tockos.org/documentation/design
- yellingdog 7y agoGHS Integrity?
- java-man 7y agohttps://nvd.nist.gov/vuln/detail/CVE-2019-7715 https://nvd.nist.gov/vuln/detail/CVE-2019-7715 https://nvd.nist.gov/vuln/detail/CVE-2019-7711 https://nvd.nist.gov/vuln/detail/CVE-2019-7711
- Causality1 7y agoThere's a reason it's often referred to as "Internet of Shit". I highly doubt anything is going to change until someone figures out how to use an internet-connected power outlet to burn down a house. It's going to be a decade-removed version of the wireless router issue: huge botnets will go on for years and years and maybe eventually manufacturers will slowly close security holes and institute better practices. Even that I doubt, since routers are made by a handful of major companies and IoT devices are made by hundreds of fly-by-night outfits who're likely to be out of business in five years.
- closeparen 7y agoVxWorks is a serious, long term player in the embedded space. This is the operating system you’ll find on the moon. Not really related to the fly-by-night internet of shit.
- Causality1 7y agoIndeed they are, but I refer to the legions of no-name products that make up much of the consumer industry. Smart lightbulbs, power outlets, rain meters, etc. The original headline was much less specific before it was edited.
- Havoc 7y agoNot at all surprised. Busy kitting out my place with (consumer - jikes) IoT...and basically just connecting the stuff long enough to get it online via Home Assistant. ...next step...firewall all the IOT IPs. Once they're connected to Home Assistant they don't need internet access.
- throwanem 7y agoJust don't use a NetApp or Sonicwall firewall...
- plopz 7y agoCompletely random aside, but the site's scrolling is horrible. Clicking near the edge randomly starts scrolling when the bar isn't visible and I can't middle click and drag to scroll the page at all.
- fastflo 7y agovxworks ... have you ever tried to implement something with that ugly hack? -- and seen how nice it can be with other, proper operating systems? as many already said: not at all surprised.
- AnimalMuppet 7y agoYes, I have. And why do you call it an ugly hack? For what it does, it does it quite well. If that's what you need, then it's a very nice system. If you need something else, use something else.
- TickleSteve 7y agoVxWorks is well regarded and works extremely well, and yes, I've implemented plenty with it.
- gruez 7y agoOff topic: Why are web developers constantly reimplementing native browser functionality? This site for instance has their own scroll implementation that's laggy, adds unwanted smoothing, and of course has less functionality (middle-click scrolling doesn't work, nor does autoscrolling). Fortunately I can get the native implementation by disabling scripts, but I've seen sites that are `overflow: hidden` so you're forced to use their scrolling logic.
- qarthandyc 7y agoI couldn't agree more. While it's enticing to show your creativity in something like scrolling, it almost always negatively impacts the site...as it definitely has here.
- Deimorz 7y agoIt's a huge problem with the current SPA trend. Sites are re-implementing all sorts of basic functionality like scrolling, links, and form inputs and invariably do a myopic job of it where they only implement basic functions or ones that the developer personally uses. There are so many sites now where you can't Ctrl-click, middle-click or right-click links and get proper behavior, where inputs don't work the way they should, where sites try to hijack keyboard shortcuts (and of course assume everyone's using the default ones), where scrolling with the keyboard messes up layouts because they assume you're going to gradually scroll down with a mouse or swipe, where browser extensions can't affect element types because everything is just a <div>, etc. It's a gigantic pain in the ass for consistent usability across sites, and a complete disaster for accessibility as well.
- cronix 7y agoIt's why I use reader mode in FF. All that js, ads and other crap just go bye bye leaving you with only the article content that you wanted to read to begin with, like it should be.
- dpedu 7y agoProject managers/product designers that don't understand their problem domain paired with developers that won't say no. There's a couple extensions that are supposed to target and disable this behavior, but I've found them flakey at best.
- cesarb 7y agoEverything old is new again: "WinNuke is an example of a Nuke remote denial-of-service attack (DoS) that affected the Microsoft Windows 95, Microsoft Windows NT and Microsoft Windows 3.1x computer operating systems. The exploit sent a string of out-of-band data (OOB data) to the target computer on TCP port 139 (NetBIOS), [...]" https://en.wikipedia.org/wiki/WinNuke https://en.wikipedia.org/wiki/WinNuke
- BubRoss 7y agoThat's how I would free up my friend's phone lines when I wanted to call them.
- caf 7y agoThat's what I was thinking when I read "Four memory corruption vulnerabilities stemming from erroneous handling of TCP’s Urgent Pointer field" - the hardline on your desk is ringing, and the caller ID says 1996.
- dundercoder 7y agoWe used to win nuke the computer labs in high school after playing the first 15 seconds of blur song2. It got to the point where just playing the song would cause Ethernet dongles across the room to get ripped right out of laptops. Ahh the old days.
- xvilka 7y agoSeems WindRiver also adding[1] VxWorks support in the Rust language. There should be more efforts into bringing safer and secure languages, toolchains, even OS themselves into IoT, IIoT, and even RTOS worlds. [1] https://github.com/rust-lang/rust/pull/61946 https://github.com/rust-lang/rust/pull/61946
- pjmlp 7y agoSavvy safety oriented developers already have a few options, it is not only about Rust, although it is nice to see it doing progress there. https://www.mikroe.com/ https://www.mikroe.com/, Pascal and Basic https://www.astrobe.com/default.htm https://www.astrobe.com/default.htm, Oberon https://www.aicas.com/cms/ https://www.aicas.com/cms/, RealTime Java https://www.ptc.com https://www.ptc.com, RealTime Java and Ada https://www.ghs.com https://www.ghs.com, Ada and INTEGRITY RTOS