Showing posts with label Looking Back. Show all posts
Showing posts with label Looking Back. Show all posts

Saturday, August 29, 2026

Looking Back – 3-4-11 – Unusual Order Reporting

Nearly every morning I start my computer time by looking at information from Google about what happened in my blog in the previous 24 hours. Google, and blogspot.com is a Google service, provides interesting pieces of analytical data about my blog readership. One item of particular interest is the top ten blog posts each day. As you would expect, most of those posts were from the last couple of days, but with 16 years of publishing this blog, every once-in-a-while, a blog post from ancient history rises into that list. 

Today a blog post from March 2011 showed up on the list, “Unusual Order Reporting”. That post looked at a series of news stories about the preemption of a potential terrorist attack because of the reporting by both a chemical supply company and a transportation company about an order for a chemical by someone out of the ordinary; a chemical that can be used to make improvised explosive devices. 

Much of the discussion in the piece deals with the Chemical Facility Anti-Terrorism Standards (CFATS) program requirements for knowing your customers, especially when shipping chemical weapons, explosives, and precursors to both. While the shipping both chemical weapons and explosives remain regulated, with the death of the CFATS program in 2023, the regulation of precursor chemicals has disappeared from the federal arsenal. 

While I expect that most reputable chemical companies and distributors, especially those that were in the CFATS program, do make an honest effort to know their customers (and all the major industrial chemical organizations have programs that emphasize such efforts), such efforts cost time and money, and lose potential customers; corner cutting would not be unexpected. And, unfortunately, we do not have to look far (see yesterday’s post about this week’s CSB update) examples of chemical companies cutting major corners. 

CFATS is dead and buried. Someone is going to have to seriously think about what is going to cover the chemical security bases such as how to keep chemical weapon and improvised explosive precursors out of the hands of potential terrorists. 

Friday, August 21, 2026

Looking Back – 9-17-13 – Disclosure – An Opposing View

 Nearly every morning I start my computer time by looking at information from Google about what happened in my blog in the previous 24 hours. Google, and blogspot.com is a Google service, provides interesting pieces of analytical data about my blog readership. One item of particular interest is the top ten blog posts each day. As you would expect, most of those posts were from the last couple of days, but with 16 years of publishing this blog, every once-in-a-while, a blog post from ancient history rises into that list. 

Today a blog post from September 2013, “Reader Comment – 09-17-13 – Disclosure – An Opposing View”, made the list. It takes a look at the issue of coordinated (and uncoordinated) disclosures of vulnerabilities. The reader comments on the post, from respected names in the community, point out how much interest this topic has driven. The discussion holds up today; it just has gotten more complex now that AI-detected vulnerabilities have been added to the mix. 

Monday, August 10, 2026

Looking Back – 12-29-14 - Damn Vulnerable Chemical Process

Nearly every morning I start my computer time by looking at information from Google about what happened in my blog in the previous 24 hours. Google, and blogspot.com is a Google service, provides interesting pieces of analytical data about my blog readership. One item of particular interest is the top ten blog posts each day. As you would expect, most of those posts were from the last couple of days, but with 16 years of publishing this blog, every once-in-a-while, a blog post from ancient history rises into that list. 

Today a blog post from December 2014, Damn Vulnerable Chemical Process, showed up on the list. It looks at an important presentation made by a young Ukrainian [not German as I said in the post] researcher, Marina Krotofil. The original video link is, of course, dead, but there is a new You-tube video up of the presentation. Her presentation still holds up today. 

I have an interesting follow-up post about the discussion that resulted from that presentation. 

I met Marina at a meeting in Atlanta a few years ago. She was a delightful young lady and had a bright future in the OT Cybersecurity field. Unfortunately, in 2022, she found it necessary to defer her cybersecurity work, to help her homeland resist the Russian invaders. I wish her well and hope she is able to return to her international cybersecurity work. 

Friday, August 7, 2026

Looking Back – 11-13-09 – Security Fencing

Nearly every morning I start my computer time by looking at information from Google about what happened in my blog in the previous 24 hours. Google, and blogspot.com is a Google service, provides interesting pieces of analytical data about my blog readership. One item of particular interest is the top ten blog posts each day. As you would expect, most of those posts were from the last couple of days, but with 16 years of publishing this blog, every once-in-a-while, a blog post from ancient history rises into that list. 

Today, a blog post from November 13th, 2009, made the list. It takes a news story about protests at a naval nuclear weapons storge site and uses it as a launch pad about security fences. The news story link is no longer working, but the discussion is still pertinent almost 15 years later. Interestingly, for this blog, a series of reader comments lead to two more blog posts expanding on the topic. The last post leaves with a toss off comment that I am still happy with today. In talking about why security is getting easier, I make the comment that: “All we have to do is fob off the hard part to those trained and experienced to handle that chore. 

Monday, August 3, 2026

Looking Back – 12-16-21 – Log4Shell, do Something Now

 Nearly every morning I start my computer time by looking at information from Google about what happened in my blog in the previous 24 hours. Google, and blogspot.com is a Google service, provides interesting pieces of analytical data about my blog readership. One item of particular interest is the top ten blog posts each day. As you would expect, most of those posts were from the last couple of days, but with 16 years of publishing this blog, every once-in-a-while, a blog post from ancient history rises into that list. 

Today a blog post from December 16th, 2021, Reader Comment – Log4Shell Do Something Now, jumped into the list. This post looked at some of the response issues related to the Log4 vulnerabilities. These vulnerabilities were the first time (and looking back, the only time) that the OT vendor community jumped on a 3rd party vulnerability with any sort of unanimity. That response was both quick and flawed; to be fair, a combination that is frequently seen in emergency situations. 

The problem was that there was no problem. The world did not end. There were no massive takeovers of vulnerable systems. The OT world chugged along pretty much the same as it did before Log4Hell. I am afraid that the lesson learned can be summed up in a phrase I learned many years ago (damn, close to 40 now) that I learned in French Commando School; “No sweat, no safety.” 

We can see this reflected today in the industry response to the Iranian (probably) water system hacks of last month; “What? Me Worry?” Nothing crashed and burned; product was still delivered, no safety issues, and you want water facilities to change their operating scheme? “Bother me next week.” 

NOTE: With me taking the weekends off now, more of these older posts are showing up in analytical data on Monday’s, I will continue to use these posts for Monday morning fodder if they have some relevancy to current conditions. 

Monday, July 27, 2026

Looking Back – 3-8-2011 – KingView Exploit

Nearly every morning I start my computer time by looking at information from Google about what happened in my blog in the previous 24 hours. Google, and blogspot.com is a Google service, provides interesting pieces of analytical data about my blog readership. One item of particular interest is the top ten blog posts each day. As you would expect, most of those posts were from the last couple of days, but with 16 years of publishing this blog, every once-in-a-while, a blog post from ancient history rises into that list. 

Today, a blog post from March 8th, 2011, ICS-CERT Alert for WellinTech KingView, made the list. The ICS Alert briefly describes a vulnerability in the WellinTech KingView v6.53. Not much in the way of details about the vulnerability beyond the fact that it affected KVWebSvr.dll and an exploit was available. Interestingly, neither the alert nor the follow-up advisory provide a CVE for the vulnerability.  

It turns out that the supporting CVE (CVE-2011-3142) was not published until August 16th, 2011, and MITRE was the CNA not ICS-CERT (they became a CNA in 2012). Two separate exploits are listed in the NVD.NIST.gov record, but neither link works. In fact, none of the links referenced on the NVD site work. Ancient history, so I guess it really is not important.... 

Wednesday, July 22, 2026

Looking Back – 10-10-24 – 21 Advisories

Nearly every morning I start my computer time by looking at information from Google about what happened in my blog in the previous 24 hours. Google, and blogspot.com is a Google service, provides interesting pieces of analytical data about my blog readership. One item of particular interest is the top ten blog posts each day. As you would expect, most of those posts were from the last couple of days, but with 16 years of publishing this blog, every once-in-a-while, a blog post from ancient history rises into that list. 

Today a blog post from October 10th, 2024, Review – 21 Advisories Published 10-10-24, made the list; actually, it has made the list for the last four days. This was a post about the CISA NCCIC-ICS control system security advisories for the Thursday after Cyber Tuesday. That is the reason for the 21 advisories being covered; including six for products from Rockwell and 13 for products from Siemens. Nothing unusual here, at least until I looked at the companion post over on CFSN Detailed Analysis. That post included the following comment about the Siemens SIMATIC S7-1500 CPUs advisory: 

“NOTE: This advisory is a good example of the reason that CISA no longer covers Siemens updates. Of the products listed as being affected by this vulnerability, 88 of them are currently listed on the Siemens Advisory as “Currently no fix is available”. I suspect that fixes for those products will be completed in batches with multiple updates needed to keep customers advised. There is no telling how long that will take, or how many updates will be required.” 

Looking back at the latest version of the Siemens Advisory, they published seven updates through October 14th, 2025. That left them with one product, SIMATIC S7-1500 Software Controller Linux V2, with no fix planned. That product is apparently no longer supported. I listed that update in the Bulk Updates – Siemens section of my Public ICS Disclosures – Week of 10-11-25 – Part 2 post. 

 
/* Use this with templates/template-twocol.html */