s7scan by Danila Parnishchev is a tool that scans networks, enumerates Siemens PLCs and gathers basic information about them, such as PLC firmware and hardware version, network configuration and security parameters such as:
Showing posts with label Siemens. Show all posts
Showing posts with label Siemens. Show all posts
Monday, October 15, 2018
Tuesday, December 22, 2015
Monday, February 16, 2015
Thursday, October 9, 2014
What is my encryption key?
Update for update for WinCC <7.3. Now for Siemens SIMATIC PCS 7 <8.1.
Details: https://ics-cert.us-cert.gov/advisories/ICSA-14-205-02A
Details: https://ics-cert.us-cert.gov/advisories/ICSA-14-205-02A
Wednesday, July 23, 2014
Siemens SIMATIC WinCC 7.3: Vulnerabilities/Fixes
New version of WinCC/new features/new advisories/new vulnerabilities. Kudos Gleb Gritsai, Dmitry Nagibin and Alexander Tlyapov .
CVE-2014-4682/HTTP/sensitive data (session) leakage
CVE-2014-4683/HTTP/remote privileges escalation (useful with CVE-2014-4682 and CVE-2013-3958)
CVE-2014-4685/Local/lot of funny stuff with Windows IPC objects
CVE-2014-4686/RPC/hardcoded key in authentication sequence/our new favorite slide
Details in SSA-214365.
CVE-2014-4682/HTTP/sensitive data (session) leakage
CVE-2014-4683/HTTP/remote privileges escalation (useful with CVE-2014-4682 and CVE-2013-3958)
CVE-2014-4685/Local/lot of funny stuff with Windows IPC objects
CVE-2014-4686/RPC/hardcoded key in authentication sequence/our new favorite slide
Details in SSA-214365.
Labels:
Releases,
Siemens,
Vulnerabilities,
WinCC
Location:
Daejeon, South Korea
Thursday, March 20, 2014
Time is compressing...
Update for previous post. New fixes for Siemens S7 1200 PLC.
http://www.siemens.com/innovation/pool/de/forschungsfelder/siemens_security_advisory_ssa-654382.pdf
Enjoy.
Labels:
1200,
PLC,
Releases,
Siemens,
Vulnerabilities
Location:
Alaska, USA
Saturday, March 15, 2014
All your PLC are belong to us (2)
Fixes for Siemens S7 1500 PLC are published.
Thanks to Yury Goltsev, Ilya Karpov, Alexey Osipov, Dmitry Serebryannikov and Alex Timorin.
There are a lot of, but combination of Authentication bypass (INSUFFICIENT ENTROPY/CVE-2014-2251) and Hardcoded SNMP community string (once again)/NO-CVE/Unfixed is the best.
Links
http://www.siemens.com/innovation/pool/de/forschungsfelder/siemens_security_advisory_ssa-456423.pdf
http://ics-cert.us-cert.gov/advisories/ICSA-14-073-01
Some good stuff for 1200/TIA portal in queue.
Enjoy...
Thanks to Yury Goltsev, Ilya Karpov, Alexey Osipov, Dmitry Serebryannikov and Alex Timorin.
There are a lot of, but combination of Authentication bypass (INSUFFICIENT ENTROPY/CVE-2014-2251) and Hardcoded SNMP community string (once again)/NO-CVE/Unfixed is the best.
Links
http://www.siemens.com/innovation/pool/de/forschungsfelder/siemens_security_advisory_ssa-456423.pdf
http://ics-cert.us-cert.gov/advisories/ICSA-14-073-01
Some good stuff for 1200/TIA portal in queue.
Enjoy...
Labels:
1500,
PLC,
Releases,
Siemens,
Vulnerabilities
Location:
Sevastopol, Sevastopol' city, Ukraine
Saturday, January 4, 2014
30C3 releases: all in one
Thank you everybody for the awesome Chaos Communication Congress.
Just a collection of our 30C3 releases in one post.
ICS/SCADA/PLC Google/Shodan Cheat Sheet
http://scadastrangelove.blogspot.com/2013/12/internet-connected-icsscadaplc30c3.html
THC Hydra with Siemens S7-300 support
http://scadastrangelove.blogspot.com/2013/12/hydra-vs-siemens-s7-30030c3-release.html
Slides and video from SCADA Strangelove 2 talk. Passen Sie auf! Russischen Akzent!
Just a collection of our 30C3 releases in one post.
ICS/SCADA/PLC Google/Shodan Cheat Sheet
http://scadastrangelove.blogspot.com/2013/12/internet-connected-icsscadaplc30c3.html
THC Hydra with Siemens S7-300 support
http://scadastrangelove.blogspot.com/2013/12/hydra-vs-siemens-s7-30030c3-release.html
Slides and video from SCADA Strangelove 2 talk. Passen Sie auf! Russischen Akzent!
Labels:
30c3,
phdays,
Releases,
Siemens,
Vulnerabilities,
Wonderware,
Yokogawa
Location:
Hamburg, Germany
Tuesday, November 12, 2013
SCADA Security Deep Inside
Members of SCADA StrangeLove Gleb Gritsai and Alexander Tlyapov gave a talk at Zeronights conference @Moscow. New slides were splitted into two parts:
- Industrial protocols (MMS and IEC 104) and how to act during a penetration testing of ICS enviroment with this protocols
- Patched WinCC vulnerabilities discovered by SCADA SL group including Alexander's results of deep reverse engineering of solution
We'd like to thank attendees for their questions and interest in topic. This year showed there is a room for organizational improvements, but the conference talks and the community compensate any negative impressions. Kudos to the organizers of the Zeronights conference for bringing up this international security event and giving us a chance to speak there.
- Industrial protocols (MMS and IEC 104) and how to act during a penetration testing of ICS enviroment with this protocols
- Patched WinCC vulnerabilities discovered by SCADA SL group including Alexander's results of deep reverse engineering of solution
We'd like to thank attendees for their questions and interest in topic. This year showed there is a room for organizational improvements, but the conference talks and the community compensate any negative impressions. Kudos to the organizers of the Zeronights conference for bringing up this international security event and giving us a chance to speak there.
Monday, November 4, 2013
Power of Community 2013 special release of ICS/SCADA toolkit
Special release of ICS/SCADA toolkit for our speech and workshop at Power of Community conference. Lets play with industrial protocols: S7, Profinet, IEC-60870-5-104, iec-61850-8-1 !
Download
Enjoy...
Labels:
iec-60870-5-104,
iec-61850-8-1,
POC2013,
powerofcommunity,
profinet,
Releases,
S7,
Siemens
Location:
Seoul, South Korea
Thursday, August 1, 2013
SSA-064884: WinCC/TIA Portal fixes
Siemens updates WinCC SCADA and TIA Portal to fix two minor
issues in HMI panels discovered by our team:
- CVE-2013-4911: CSRF (Cross-site request forgery) attacks, compromising integrity and availability of the system
- CVE-2013-4912: URL redirection to untrusted websites
Thanks for Timur Yunusov and Sergey Bobrov for research and thanks for Siemens Product CERT for fix and collaboration.
Details
Siemens SSA-064884:
ICS-CERT ICSA-13-213-02:https://ics-cert.us-cert.gov/advisories/ICSA-13-213-02
Enjoy
Subscribe to:
Posts (Atom)







