Image
 
Latest Additions
 
EH-Net Login
Welcome Guest.






Lost Password?
No account yet? Register
Who's Online
We have 21 guests and 3 members online
EH-Net Donations

Enter Amount:
$

Google Ads
EH-Net News Feeds
Latest Additions
Book Recommendations





 
Advertisement

You are here: Home arrow Forum arrow Ethical Hacking Discussions and Related Certificationsarrow Malwarearrow CTO Defends Researcher's Decision to Reveal SCADA Exploit
Ethical Hacker Community Forums
January 08, 2009, 12:24:10 AM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: ChicagoCon 2-Day Ethical Hacking Conference with MS Blue Hats Oct 31 - Nov 1. Tickets Only $100! www.chicagocon.com/content/view/103/51/
 
   Home   Help Calendar Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: CTO Defends Researcher's Decision to Reveal SCADA Exploit  (Read 995 times)
0 Members and 1 Guest are viewing this topic.
don
Editor-In-Chief
Administrator
Hero Member
*****
Offline Offline

Posts: 2435


Editor-In-Chief


View Profile WWW
« on: September 19, 2008, 11:52:57 AM »

Quote

The chief technology officer of a security firm is standing behind the decision by one of his researchers to release exploit code for a SCADA vulnerability, despite a mountain of criticism being lobbied against them.

Researcher Kevin Finisterre recently released attack code that takes advantage of a stack-based buffer overflow bug in Supervisory Control and Data Acquisition (SCADA) software. The vulnerability was announced in early June by its discoverer, Core Security Technologies, and the affected software's manufacturer, Georgia-based Citect, has since delivered patches to affected customers.

No breaches have been reported, according to a Citect statement.

Finisterre said he decided to create the exploit because he believed the initial disclosure did not receive enough exposure. But because the code is designed to infiltrate industrial control systems, responsible for running some of the nation's most critical infrastructure -- such as oil and gas pipelines and the electric grid -- Finisterre and his company, Netragard, caught some heat.

CTO Adriel Desautels told SCMagazineUS.com on Friday that he and Finisterre received 12 to 18 emails from people questioning why the exploit, developed through the publicly available Metasploit framework, was released in the first place.

Desautels said he stands by the decision.

First the exploit will motivate people to patch by giving them a way to test their systems against the vulnerability, he said. Second, it will encourage SCADA software developers to write more secure code.

"I think releasing the exploit code was actually necessary," he said. "He's actually doing a free service. I would believe Kevin has actually reduced risk."

In addition, the exploit becomes less valuable to hackers now that it is publicly known, Desautels said.

He added that if researchers such as Finisterre are denounced for disclosures such as this, they will be less inclined to "do the right thing" because they don't want to be "portrayed as the bad guy."

But Rich Mogull, founder of independent consultancy Securosis, told SCMagazineUS.com that researchers often must show restraint in revealing exploits, especially when they are inherent to SCADA.

"If you told me you're releasing an exploit tool a couple of months after an IE patch comes out, I wouldn't say the same thing," Mogull said. "SCADA guys do not update their stuff. There are huge problems in SCADA. I cannot overemphasize...the disconnect we see between the SCADA community and the security community."

Desautels said that while he does not always agree with releasing exploits, it was fine in this case.

"Citect knew about this vulnerability for many months and had released patches," he said.

Mogull said the obligation to encourage users to patch and developers to build secure software does not fall on researchers.

"You're not screwing with some corporate IT department," he said of the exploit. "You let someone take over the wrong part of a SCADA system, and you bring down power."

The North American Reliability Corp. (NERC), for one, is undertaking a slew of initiatives to improve its response to critical infrastructure protection. NERC, responsible for overseeing the power system in North America, recently appointed its first-ever chief security officer and is establishing a task force to review its process for setting cybersecurity standards.


Original story:
http://www.scmagazineus.com/CTO-defends-researchers-decision-to-reveal-SCADA-exploit/article/116613/

Don
Logged

CISSP, MCSE, CEH, Security+ SME
ChrisG
EH-Net Columnist
Hero Member
*****
Offline Offline

Posts: 1049


View Profile WWW
« Reply #1 on: September 19, 2008, 02:21:22 PM »

so its the security community's fault that SCADA people have bad business practices therefore exploit code shouldnt  be released?

dumb...
Logged

...tests i took go here...

http://carnal0wnage.blogspot.com/
Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.7 | SMF © 2006-2008, Simple Machines LLC
Joomla Bridge by JoomlaHacks.com
Valid XHTML 1.0! Valid CSS!
Page created in 0.043 seconds with 23 queries.
 
Sponsors

cwnp_moto__120x90.gif

Polls
How many security events including conferences and training do you attend a year:
 
Support EH-Net


Support EH-Net by
Buying all of your
Amazon items using
the search bar above.

cbtnuggets_logo_125.jpg
Try CBT Nuggets Free!
Recent Forum Topics
Vote For EH-Net

progenic.com
Click here to Vote!

binarica.com
Binarica Logo

Add to Technorati Favorites
technorati fave

 
         
Advertisement

© 2009 The Ethical Hacker Network
Joomla! is Free Software released under the GNU/GPL License.