Showing posts with label TAGS: Chemical Facility Security. Show all posts
Showing posts with label TAGS: Chemical Facility Security. Show all posts

Thursday, December 22, 2011

New ICS-CERT Monitor and 2 Advisories

Yesterday the DHS Industrial Control System Cyber Emergency Response Team (ICS-CERT) published the December edition of their Monthly Monitor and two new Advisories for control system vulnerabilities affecting WellinTech’s KingView and 7-Technologies IGSS SCADA systems.

Monthly Monitor


ICS-CERT continues to produce a brief but valuable monthly newsletter that should be widely read in the control system community. The latest issue contains:

• A neat new logo (okay that’s not so important, but it is good graphics design);

• Another overview of the ‘Water System Hack’;

• A good summary of generic malware analysis and mitigation techniques;

• A summary of the ‘latest’ Gleg Agora SCADA release (probably more appropriate here than as an alert)

• A lengthier listing of control system security articles and blog posts (including one by SCADAHacker, a nice response to my comment last month about the lack of bloggers); and

• Their standard listing of Alerts and Advisories and plug for Coordinated Vulnerability Disclosure

WellinTech


This Advisory describes a heap based buffer overflow vulnerability reported by Luigi through ZDI (so it was coordinated) in the WellinTech KingView system. It appears to be a common remotely exploitable vulnerability that allows execution of arbitrary code by an attacker with an intermediate skill level. WellinTech has a patch available. The CVE number provided in the Advisory is not yet active.

Two interesting things here. First ICS-CERT includes a link to the Chinese language instructions for the patch in addition to the English language instructions (multiculturalism at its best). More importantly the Advisory notes that there are no known exploits available. Luigi typically develops and publishes exploit code, though I can’t find a reference to this vulnerability on his web page. Since this is part of the ZDI project I wonder if he provided them with the code and they just haven’t released it.

7-Technologies


7-Technologies seems to be catching it this week. Earlier there was an advisory for their data server and yesterday a new advisory for similar buffer overflow vulnerability discovered by a separate researcher Celil Unuver (SignalSEC LLC). It appears that the same product update will solve both problems. The CVE file on this vulnerability is also not yet active.

Tuesday, April 7, 2009

Port Truckers Exempted from TWIC?

Lots of people are taking notice of the recent Coast Guard advanced notice of proposed rule making (ANPRM) on potential requirements for electronic readers to verify the authenticity of Transportation Workers Identification Credentials (TWIC). I ran across an interesting article on the issue over on TTNews.com, a trucker related site. The thing that makes this article interesting is the comment that: “In the March 27 proposal, truckers who carry shipments to or from container ships that carry consumer goods and manufactured products would not have to obtain the biometric card.” Now I certainly did not read that in the ANPRM, so I read the article a little more closely to see if I could determine how they came to this conclusion. It quickly became evident that Mr. Rip Watson, the article author, misread section IV E (Facility and Vessel Risk Groups) of the ANPRM. In the article he describes the vessel conditions for being placed into categories, but fails to address the similar conditions for facilities covered by the MTSA. Apparently missing the facility descriptions, he assumed that TWIC would not be required for personnel servicing facilities. The Coast Guard ANPRM does nothing to change the requirements for workers in MTSA covered facilities or vessels to have a TWIC to be able to have unescorted access to security areas. All it does is address how those facilities and vessels will have to incorporate the use of TWIC Readers to verify worker identities.
 
/* Use this with templates/template-twocol.html */