Security3.08.2011

Critical infrastructure equipment discoverable via Google

Supervisory Control and Data Acquisition (SCADA) systems are used to run critical infrastructure systems, such as power plants. Despite their importance, researchers are now saying these systems lack proper security measures and in some cases are available via a Google search.

Speaking at the Black Hat conference in Las Vegas, chief technology officer at FusionX, Tom Parker, demonstrated how easy it is to access these systems. Parker typed some search terms into Google related to a Programmable Logic Controller, and received numerous results. Among these was a reference to an “RTU pump status” for a remote terminal unit, commonly used in water treatment plants. The result also included a password for the RTU – “1234”.

Parker highlighted the extent of the vulnerability when saying, “You can do a Google search with your Web browser and start operating [circuit] breakers, potentially.”

Fellow researcher Jonathan Pollet,  founder of Red Tiger Security, went on to highlight how some of these SCADA systems don’t have any form of access control. “You can make it do anything you want it to do. If that RTU or PLC has large motors connected to it, pumping out water or chemicals, the equipment could be turned off. If it was a substation and the power recloser switches were closed, we could break it open and create an (electricity) outage for an entire area or city…The bottom line is you could cause physical damage to whatever is connected to that PLC,” said Pollet.

Read the full story over at: Cnet.

Show comments

Latest news

More news

Trending news

Sign up to the MyBroadband newsletter