Conpot (ICS/SCADA Honeypot)

Existen HomeyPots para diferentes escenarios, simulando SSH, SNMP, un servicio HTTP vulnerable etc..

El de hoy es algo especial, ya que se trata de un HoneyPot que simula ser un servicio ICS/. Ha habido varios incidentes relacionados con los , por no decir que hay algunos de los que se encuentran expuestos en Internet.

¿Incidentes relacionados con Scada?

Pues por ejemplo: “En junio de 2010, Irán sufrió un severo ataque a parte de infraestructura crítica, principalmente a sus reactores nucleares, a través de un virus denominado Stuxnet, que contaminó el software denominado SCADA  (Supervisores de Control y de Adquisición de Datos) utilizada por aquel país, vía un USB que fue introducido a las computadoras por uno de los trabajadores.”

LAS VEGAS — BLACK HAT USA — SCADA experts here today demonstrated just how easy it is to commandeer the antiquated networking protocols used in an oil-well pumping station and other SCADA environments, causing a simulated oil tank to nearly overflow using spoofed commands to the programmable logic controller (PLC).

While the live demo by Cimation researchers Brian Meixell and Erick Forner drew audience laughter with the model-simulated oil well and pump contraption — at one point spraying some of the bluish-green dyed liquid, and the grand finale when they hacked the remote terminal unit’s HMI interface and inserted a game of Solitaire on its screen — their message was sobering.

“We only had a 24-volt pump in the demo, but this [attack] could cause a complete environmental catastrophe” in a real oil-well drilling environment, Forner said.

The researchers, whose day jobs include installing and supporting SCADA systems in oil rigs, basically wrote a few basic Python scripts that told the remote controllers what to do. In the live demo, they commanded the valve and pump to work on “high” and to nearly overflow the simulated oil. They also showed how they could send phony data that convinced the system that the pump was empty when it was actually rising, forcing it to nearly overflow.

“So you can have the operator seeing something entirely different than what’s happening in the process, causing the pipe to burst and the tank to overflow,” Forner says. “The operator would see the tank levels decreasing, when, in fact, they were increasing.”

No specific software vulnerabilities or bugs are required for this attack: It comes down to the lack of security in the serial Modbus/TCP protocol, a networking protocol that dates back to the 1970s and operates on port 502. “There is no authentication or security at all designed into it,” Forner says.

“We are sending packets over the network, unauthenticated” and controlling the PLC devices with the scripts, he says. “We were able to disable the safety logic … and force inputs and outputs” to turn a pump on, off, or sabotage its flow.

Meanwhile, the researchers say they’ve found via Shodan scans some 93,000 devices reachable via the Internet that speak Modbus. Preventing attacks on these systems, such as those the two demonstrated, would require command-level filtering for the PLCs, or removing the systems from the public IP network altogether, they said.

So are these environments getting hit by attacks yet? “A lot of why we’re not seeing a lot of attacks here is that you don’t know what you’re looking for if you don’t know what to do with it,” Forner says. “These devices have been attached to the Net for years. Now people are starting to look at this and are starting to care.”

resource: Kelly Jackson Higgins