Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista
SCADA industry debates flaw disclosure
Robert Lemos, SecurityFocus 2006-06-16

The outing of a simple crash bug has caused public soul-searching in an industry that has historically been closed-mouthed about its vulnerabilities.

Comments Mode:
SCADA industry debates flaw disclosure 2006-06-17
Dion Stempfley
NT on SCADA networks? Gee... 2006-06-19
assurbanipal (2 replies)
Re: NT on SCADA networks? Gee... 2006-06-19
Anonymous (1 replies)
Re: NT on SCADA networks? Gee... 2006-06-22
Anonymous
SCADA industry debates flaw disclosure 2006-06-19
Dion Stempfley
SCADA industry debates flaw disclosure 2006-07-26
Anonymous (1 replies)
Re: SCADA industry debates flaw disclosure 2006-08-01
Anonymous (1 replies)
Re: Re: SCADA industry debates flaw disclosure 2006-08-24
Anonymous
Everything that you have described as having done to secure your SCADA systems is no more than what is considered to be basic Best Practices for all networks. Most security specialists would probably agree that these basic Best Practices are a good start. Have you completely eliminated unencrypted data on your network? Are your servers and workstations running OS's that are still vendor supported and considered to be secure? This means no old NT, Win 95, or old SunOS boxes. Are your servers and workstations fully patched? Did the latest patches introduce any new vulnerabilies? Are there measures in place so that any router rearrangement or firewall activity will never allow outside access to your soft and chewy inside network? Are there methods of preventing unauthorized access to systems from INSIDE your network? As long as critical systems are networked, especially when there are physical connections to the internet (even if they are logically separated by firewalls, routing tables, ACL's, and the like), you are vulnerable.

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/articles/11396/34023#34023
SCADA industry debates flaw disclosure 2006-10-12
Anonymous (1 replies)







 

Privacy Statement
Copyright 2008, SecurityFocus