Home » Potentially Serious Threat Targets Control Systems
Potentially Serious Threat Targets Control Systems
ChemicalProcessing.com
07/22/2010
According to Byres Security Inc., a new family of threats called Stuxnet appears to be directed specifically at Siemens WinCC and PCS7 products via a previously unknown Windows vulnerability. Byres also discovered a concerted Denial of Service attack against a number of the SCADA information networks such as SCADASEC and ScadaPerspective mailing lists, knocking at least one of these services off line.
Eric Byres, P.E., and Chief Technology Officer of Byres, offers these facts:
• This is a zero-day exploit against all versions of Windows including Windows XP SP3, Windows Server 2003 SP 2, Windows Vista SP1 and SP2, Windows Server 2008 and Windows 7.
• There are no patches available from Microsoft at this time (There are workarounds, which I will describe later).
• This malware is in the wild and probably has been for the past month.
• The known variations of the malware are specifically directed at Siemens WinCC and PCS7 Products.
• The malware is propagated via USB key. It may be also be propagated via network shares from other infected computers.
• Disabling AutoRun does not help! Simply viewing an infected USB using Windows Explorer will infect your computer.
• The objective of the malware appears to be industrial espionage; i.e. to steal intellectual property from SCADA and process control systems. Specifically, the malware uses the Siemens default password of the MSSQL account WinCCConnect to log into the PCS7/WinCC database and extract process data and possibly HMI screens.
The only known workarounds are:
• NOT installing any USB keys into any Windows systems, regardless of the OS patch level or whether AutoRun has been disabled or not
• Disable the displaying of icons for shortcuts (this involves editing the registry)
• Disable the WebClient service
Byres and his team have written a short white paper called “Analysis of Siemens WinCC/PCS7 Malware Attacks.” www.tofinosecurity.com/professional/siemens-pcs7-wincc-malware . If you would like to download the white paper, you will need to register on the website. Byres notes that the whitepaper is in a secure area. People who are already www.tofinosecurity.com web members do not need to reregister.
More News:
-
02/10/2012
ACC Launches Energy Advocacy And Awareness Campaign
Effort to focus on national energy strategy that maximizes all domestic energy resources.
-
02/08/2012
Honeywell Announces Fifth Annual Process Automation Student Competition
'Engineers of Tomorrow' to Present Innovative Designs at Prestigious Honeywell EMEA Users Group Conference in Istanbul, Turkey
-
02/07/2012
Palmer Forms Strategic Alliance With BioBased Technologies
Alliance will facilitate development of bio-based polyols used for rigid foam systems.
-
01/31/2012
HART Communication Names Plant Of The Year
Shell Scotford Upgrader receives 2011 award.
-
01/25/2012
Honeywell Expands HUG Student Competition
Entries now accepted from Korea, India, Japan, China, South East Asia, Australia and New Zealand
-
01/11/2012
Pike Research Report Spotlights Automation Systems Market
Report discusses the trends motivating operators of automation environments.
-
12/12/2011
Industrial Technologies Program Unveils New Name, Mission
Advanced Manufacturing Office to focus on energy efficient processes and technologies.
-
11/28/2011
Heat Exchange Institute Releases Standards for Air Cooled Condensers
First edition outlines design criteria and typical purchaser requirements.
-
11/21/2011
CDP Releases Second Annual Water Disclosure Report
Water poses substantial risk to global companies.
-
11/09/2011
Rockwell Automation Helps Vadxx Turn Waste Into Energy
Proprietary processes to be commercialized before 2012.
- All news »
Print page