View RSS Feed

rjcrystal

Introduction to SCADA hacking

Rate this Entry
by , 04-07-2012 at 09:39 AM (3025 Views)
hi guys this is my first post so please ignore any mistakes
so first what is SCADA ? its abbreviated as Supervisory Control and Data Acquisition so basically there are lots of hardwares in it and is used in power grids, Dams and many other industries. they use primitive softwares that are easy to exploit. remember Stuxnet that exploited Iran`s windows computer to exploit iran`s nuclear facility which was of Siemens. same way there are lots of companies who make SCADA and for ease of use and to control them from remote places they have internet connection

so basically there are PLC (programmable logic contoller) which are exploited mostly. the I/O cycles are controlled by RISC (Reduced instruction set computing) processor

PLCs use RISC processors to run continuous, cyclical programs and they take time in their I/O cycle to talk to the SCADA unit and receive instructions from the SCADA to modify its instruction sets or operating parameters. SCADA typically operates by evaluating the input data and determine if it is within an allowable set of parameters.

1st Shodan tracks Vulnerable SCADA devices
hackers know what an HTTP header does... and also that a hacker can identify that what software or authentication a server is running. with the use of that hackers find vulnerable SCADA devices. A website called Shodanhq does it and makes their work easy
from that a specific code(something like dorks) hackers can get lots of vulnerable SCADA devices

2nd exploits
SCADA exploits are hard to get coz no one shares that sometimes you need to make your own but you can get some from exploit Db or there is are modules by metasploit to exploit some of them are here or here

RESOURCES
1. shodanhq.com
2. scadahacker.com
3. SCADA dorks list
4.SCADA security research and tools

warning SCADA hacking is a very dangerous it can get people killed and lot of property damage...
this article is for education purposes only

Updated 04-11-2012 at 12:22 AM by rjcrystal

Tags: None Add / Edit Tags
Categories
Uncategorized

Comments

  1. H@CK3R_ADI's Avatar
    awesome article...kudos to u.......very good mate but this should be shared privately
  2. P0si0n_31337's Avatar
    Nice Info mate thanks 4 sharing.

Trackbacks

Total Trackbacks 0
Trackback URL: