pmcnamara
News Editor

Scariest Black Hat story so far: Power plants at risk

Opinion
Aug 5, 20112 mins

Researcher demonstrates ability to hack and control industrial computers

Last night at Black Hat in Las Vegas, security researcher Dillon Beresford showed a group of reporters and government types how he can commandeer the Siemens S7 computers that are control many industrial operations, including power plants.

(16 recent milestones of a million, billion or more)

Our report from IDG News Service reporter Robert McMillan notes early on that there are limits as to what Beresford is allowed to reveal publicly regarding his research. From that story:

The NSS Labs researcher said he’s found ways to bypass the S7’s security measures and read and write data into the computer’s memory — even when the system has password protection enabled. He can steal sensitive information from the systems, he said. And on one model, the S7 300, he found a command shell, apparently left in the system’s firmware by Siemens engineers, that he can connect to and use to run commands on the system.

After poking around for a bit he discovered a hard-coded username and password that allowed him access to a Unix-like shell program on the systems, where he can run his own commands: Username: basisk; password: basisk.

This shell is a “back door” to the system that could be misused by an attacker, Beresford said.

If that’s what he can talk about, I’d rather not contemplate what’s being held back.

 And the dancing monkeys didn’t help matters at all.

Welcome regulars and passersby. Here are a few more recent buzzblog items. And, if you’d like to receive Buzzblog via e-mail newsletter, here’s where to sign up. Follow me on Twitter here and on Google+ here.