First real-world SCADA attack in US

Jason Gurtz jasongurtz at npumail.com
Mon Nov 21 21:51:02 UTC 2011


> Having worked on plenty of industrial and other control systems I can
> safely say security on the systems is generally very poor.   The
> vulnerabilities have existed for years but are just now getting
> attention.

+1

Just for context, let me tell everyone about an operational characteristic
of one such system (Sold by a Fortune 10 (almost Fortune 5 ;) company for
not a small amt. of $) that might be surprising; the hostname of the
server system cannot be longer than eight characters.

The software gets so many things so very very wrong I wonder how it is
there are not more exploits!

~JasonG






More information about the NANOG mailing list