Threat Level: green Handler on Duty: Daniel Wesemann

SANS ISC InfoSec Handlers Diary Blog


Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!

SCADA hacks published on Pastebin

Published: 2011-11-23
Last Updated: 2011-11-23 15:50:30 UTC
by Johannes Ullrich (Version: 1)
2 comment(s)

 

pastebin.com has become a simple platform to publish evidence of various attacks. Lenny a few months back already noted that it may be useful for organizations to occasionally search pastebin for data leakage. Recently, an individual using the alias of pr0f published evidence of attacking the South Houston water system.

This made me look for other "pastes" by pr0f. What I found:

More Simatic HTML (not clear were it comes from)

http://pastebin.com/wY6XD97L

A Vacuum gauge configuration file from Caltech

http://pastebin.com/TgRTgrAK

A control system from smu.edu. Looks like power generation to me, but may be an experiment, not production

http://pastebin.com/HLNB6SAZ

Another paste, showing the (pretty good) password for a spanish water utility has since been removed. 

------

Johannes B. Ullrich, Ph.D.
SANS Technology Institute
Twitter

 

Keywords: pastebin scada
2 comment(s)
ISC StormCast for Wednesday, November 23rd 2011 http://isc.sans.edu/podcastdetail.html?id=2152
Diary Archives