[SGVLUG] Hacker breaks into water plant systems

matti mathew_2000 at yahoo.com
Sat Nov 19 09:06:45 PST 2011



note, we discussed this.. oh about 10 years ago at a Usenix security conference!!!
( accessing industrial control equipment, and submitting values WHICH exceed the input ranges of the equipment,
i.e. engineered to take values, say 1-255, what happens when you send -1? 99999? hint, at that
time no one thought any of the related programming had any bounds checking, hopefully some of that
has changed.. )

Geez, amazes me that no one really wakes up to these issues until this happens.



Hacker claims break in into water plant systems:

http://news.cnet.com/8301-27080_3-57327968-245/hacker-says-he-broke-into-texas-water-plant-others/



thanks
matti
-------------- next part --------------
An HTML attachment was scrubbed...
URL: http://www.sgvlug.net/pipermail/sgvlug/attachments/20111119/93508bac/attachment.html 


More information about the SGVLUG mailing list