Vulnerability Lets Hackers Control Building Locks, Electricity, Elevators and More

Status
Not open for further replies.

Fiery

Level 1
Thread author
Jan 11, 2011
2,007
A critical vulnerability discovered in an industrial control system used widely by the military, hospitals and others would allow attackers to remotely control electronic door locks, lighting systems, elevators, electricity and boiler systems, video surveillance cameras, alarms and other critical building facilities, say two security researchers.

The vulnerability in the Tridium Niagara Framework allows an attacker to remotely access the system’s config.bog file, which holds all of the system’s configuration data, including usernames and passwords to log in to the framework and control systems managed by it.

Billy Rios and Terry McCorkle, noted security researchers with Cylance, who have found numerous vulnerabilities in the Tridium system and other industrial control systems in the last two years, demonstrated a zero-day attack on the system at the Kaspersky Security Analyst Summmit on Tuesday. The attack exploits a remote, pre-authenticated vulnerability that, combined with a privilege-escallation bug, gave them root on the system’s platform, which underlies the devices.

“The platform is written in Java, which is really, really good from an exploitation standpoint,” Rios said. “Once we can own the platform, a lot of the other stuff is very very straightforward [to attack].”

Read more: http://origin2.www.wired.com/threatlevel/2013/02/tridium-niagara-zero-day/
 

Fiery

Level 1
Thread author
Jan 11, 2011
2,007
Java's fault once again :rolleyes:

"The platform is written in Java which is really, really good from an exploitation standpoint"
 
N

Nige_40

That is crazy, what will they get up to next. I would not like to guess. :)
 

WinAndLinuxTutorials

Level 4
Verified
Honorary Member
Aug 23, 2011
2,291
Next vulnerability in Java is to be able to put an end to our lives. :D

Java: Joining Acute Vulnerabilities Altogether. :p
 
Status
Not open for further replies.

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top