![]() |
![]() ![]() |
![]() |
![]()
Post
#1
|
|
Moving Target ![]() ![]() Group: Members Posts: 352 Joined: 10-August 10 From: Madison, WI Member No.: 18,916 ![]() |
Earlier this summer, cyber security experts uncovered the Stuxnet Malware virus, an internet worm that can search for and wreak havoc upon specific, electronic, industrial systems (which it has done in Iran). Kevin Pereira talks to Wired.com's Ryan Singel to learn more about Stuxnet, its complexities and its effects on international politics. It's all a very delicate situation.
Read more: http://g4tv.com/attackoftheshow/theloop/72...l#ixzz10qCQ5AVk G4 Story on Industrial hacking in Iran. |
|
|
![]()
Post
#2
|
|
Moving Target ![]() ![]() Group: Dumpshocked Posts: 583 Joined: 1-October 09 From: France Member No.: 17,693 ![]() |
|
|
|
![]()
Post
#3
|
|
Moving Target ![]() ![]() Group: Members Posts: 352 Joined: 10-August 10 From: Madison, WI Member No.: 18,916 ![]() |
Well derp.
You guys are good. |
|
|
![]()
Post
#4
|
|
Runner ![]() ![]() ![]() ![]() ![]() ![]() Group: Members Posts: 3,179 Joined: 10-June 10 From: St. Louis, UCAS/CAS Border Member No.: 18,688 ![]() |
So to answer, yes we have. (IMG:style_emoticons/default/wink.gif)
|
|
|
![]()
Post
#5
|
|
Moving Target ![]() ![]() Group: Members Posts: 172 Joined: 26-July 10 Member No.: 18,852 ![]() |
Yep very dangerous. So much computer control, a friend of mine works for a giant ceramics plant that uses computer control to run huges ovens that you could drive a bus into and run over 1k degrees. So a virus like that could do some serious damage. and I don't want to think about the nuclear power plants.
|
|
|
![]()
Post
#6
|
|
Moving Target ![]() ![]() Group: Members Posts: 664 Joined: 3-February 08 Member No.: 15,626 ![]() |
Yep very dangerous. So much computer control, a friend of mine works for a giant ceramics plant that uses computer control to run huges ovens that you could drive a bus into and run over 1k degrees. So a virus like that could do some serious damage. and I don't want to think about the nuclear power plants. That would require that key systems to nuclear reactors be computerized. For that very reason, most are not. |
|
|
![]()
Post
#7
|
|
Runner ![]() ![]() ![]() ![]() ![]() ![]() Group: Dumpshocked Posts: 2,946 Joined: 1-June 09 From: Omaha Member No.: 17,234 ![]() |
The nest security software in the world is still Airgap.
|
|
|
![]()
Post
#8
|
|
Old Man Jones ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Group: Dumpshocked Posts: 4,415 Joined: 26-February 02 From: New York Member No.: 1,699 ![]() |
Air gap style security doesn't help if your construction and engineering contractors keep sticking strange USB keys into your network.
(IMG:style_emoticons/default/smile.gif) -k |
|
|
![]()
Post
#9
|
|
Target ![]() Group: Members Posts: 69 Joined: 30-August 10 Member No.: 18,986 ![]() |
Some more interesting speculation:
QUOTE It is hard to ignore the fact that the highest number of infections seems to be in Iran. Can we think of any reasonable target that would match the scenario? Yes, we can. Look at the Iranian nuclear program. Strange -- they are presently having some technical difficulties down there in Bushehr. There also seem to be indications that the people in Bushehr don't seem to be overly concerned about cyber security. When I saw this screenshot last year (http://www.upi.com/News_Photos/Features/The-Nuclear-Issue-in-Iran/1581/2/) I thought, these guys seem to be begging to be attacked. If the picture is authentic, which I have no means of verifying, it suggests that approximately one and a half year before scheduled going operational of a nuke plant they're playing around with software that is not properly licensed and configured. I have never seen anything like that even in the smallest cookie plant. The pure fact that the relevant authorities did not seem to make efforts to get this off the web suggests to me that they don't understand (and therefore don't worry about) the deeper message that this tells.
Now you may ask, what about the many other infections in India, Indonesia, Pakistan etc. Strange for such a directed attack. Than, on the other hand, probably not. Check who comissions the Bushehr plant. It's a Russian integrator that also has business in some of the countries where we see high infection rates. What we also see is that this company too doesn't seem to be overly concerned about IT security. As I am writing this, they're having a compromised web site (http://www.atomstroyexport.com/index-e.htm) that tries to download stuff from a malware site that had been shut down more than two years ago (www.bubamubaches.info). So we're talking about a company in nukes that seems to be running a compromised web presence for over two years? Strange. |
|
|
![]()
Post
#10
|
|
Runner ![]() ![]() ![]() ![]() ![]() ![]() Group: Members Posts: 3,179 Joined: 10-June 10 From: St. Louis, UCAS/CAS Border Member No.: 18,688 ![]() |
Air gap style security doesn't help if your construction and engineering contractors keep sticking strange USB keys into your network. (IMG:style_emoticons/default/smile.gif) -k So what you're saying is "Don't be a fool, virus scan your tool?" (IMG:style_emoticons/default/wink.gif) |
|
|
![]()
Post
#11
|
|
Runner ![]() ![]() ![]() ![]() ![]() ![]() Group: Dumpshocked Posts: 2,946 Joined: 1-June 09 From: Omaha Member No.: 17,234 ![]() |
Air gap style security doesn't help if your construction and engineering contractors keep sticking strange USB keys into your network. (IMG:style_emoticons/default/smile.gif) -k If your allowing them to do that, or hell made them able to do it then you really havn't implemented Airgap right. It is finding that acceptable line between decreased convenience and functionality vs security that is what Infosec is all about. |
|
|
![]()
Post
#12
|
|
Old Man Jones ![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() Group: Dumpshocked Posts: 4,415 Joined: 26-February 02 From: New York Member No.: 1,699 ![]() |
If your allowing them to do that, or hell made them able to do it then you really havn't implemented Airgap right. It is finding that acceptable line between decreased convenience and functionality vs security that is what Infosec is all about. Looking at Krojar's post, it appears the folks at Iran's nuke plant barely seems to know what infosec even is. (IMG:style_emoticons/default/rotate.gif) I mean, I made my comment because the USCYBCOM seems to think the virus was spread by one unwitting contractor was plugging an infected USB key into many different systems, and many of the areas that contractor was doing work show a significant infection rate. -k |
|
|
![]() ![]() |
![]() |
Lo-Fi Version | Time is now: 11th March 2025 - 07:28 PM |
Topps, Inc has sole ownership of the names, logo, artwork, marks, photographs, sounds, audio, video and/or any proprietary material used in connection with the game Shadowrun. Topps, Inc has granted permission to the Dumpshock Forums to use such names, logos, artwork, marks and/or any proprietary materials for promotional and informational purposes on its website but does not endorse, and is not affiliated with the Dumpshock Forums in any official capacity whatsoever.