Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista
Slammer worm crashed Ohio nuke plant network
Kevin Poulsen, SecurityFocus 2003-08-19

The Slammer worm penetrated a private computer network at Ohio's Davis-Besse nuclear power plant in January and disabled a safety monitoring system for nearly five hours, despite a belief by plant personnel that the network was protected by a firewall, SecurityFocus has learned.

Comments Mode:
Slammer worm crashed Ohio nuke plant network 2003-08-20
JeiAr (1 replies)
Slammer worm crashed Ohio nuke plant network 2003-08-20
Dmitriy <maniac (at) angrycube (dot) com [email concealed]> (4 replies)
Slammer worm crashed Ohio nuke plant network 2003-08-20
Anonymous (1 replies)
Slammer worm crashed Ohio nuke plant network 2003-08-21
Anonymous System Administrator (1 replies)
Slammer worm crashed Ohio nuke plant network 2003-08-24
Anonymous, System Administrator
Slammer worm crashed Ohio nuke plant network 2003-08-21
Anonymous (1 replies)
Slammer worm crashed Ohio nuke plant network 2003-08-20
Anonymous (1 replies)
Slammer worm crashed Ohio nuke plant network 2003-08-20
Anonymous (1 replies)
Slammer worm crashed Ohio nuke plant network 2003-08-21
Anonymous System Administrator
Slammer worm crashed Ohio nuke plant network 2003-08-20
Homer (1 replies)
Slammer worm crashed Ohio nuke plant network 2003-08-22
Anonymous M$ Basher
Slammer worm crashed Ohio nuke plant network 2003-08-20
Anonymous (1 replies)
Unbelieveably Irresponsible 2003-08-21
Anonymous (1 replies)
First of all, why were critical monitoring systems on the same network that was used for Internet access (presumably email, web browsing, etc.)?

Second, a firewall does no good if there are other routes with no protection. All modems, leased lines, etc. should go through an approval process. Ideally the number of Internet and inter-organization connections would be kept to a minimum.

Third, why were they dependant on the external firewall for protection of critical systems? Those systems should have been on a dedicated network with little or no connectivity with the rest of the company. If they wanted to be able to monitor from their PCs, a serial cable or one-way Ethernet connection could be used.

Then you must consider that there are many ways a worm can get around a firewall. If you have employees with laptops, they may become infected at home, and then plug into the company network. Many worms are also able to spread when people view web pages on an infected server. This means the systems should be hardened even if they are "protected".

Critical systems should be:

a) separated from the normal network

b) kept patched

c) not run services they are not using

d) be monitored for suspicious use or traffic patterns

e) should have backup systems which use different software (they did this)

f) should have disaster recovery plans

Really it's just a lack of security-in-depth and awareness of the threat.

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/articles/6767/21717#21717
Unbelieveably Irresponsible 2003-08-21
Gallomimia (1 replies)
Unbelieveably inexperienced with these systems 2003-08-22
Anonymous System Administrator
MS Windows in a nuke plant? 2003-08-21
Ross Currie (1 replies)
"Office for Home Security" Huh? 2003-08-22
Anonymous
Slammer Worm? Guess Again 2003-08-30
Anonymous
Slammer worm crashed Ohio nuke plant network 2007-05-19
mg (at) alienmicro (dot) com [email concealed]







 

Privacy Statement
Copyright 2007, SecurityFocus