Search: Home Bugtraq Vulnerabilities Mailing Lists Jobs Tools Vista
Slammer worm crashed Ohio nuke plant network
Kevin Poulsen, SecurityFocus 2003-08-19

The Slammer worm penetrated a private computer network at Ohio's Davis-Besse nuclear power plant in January and disabled a safety monitoring system for nearly five hours, despite a belief by plant personnel that the network was protected by a firewall, SecurityFocus has learned.

Comments Mode:
Slammer worm crashed Ohio nuke plant network 2003-08-20
JeiAr (1 replies)
Slammer worm crashed Ohio nuke plant network 2003-08-20
Dmitriy <maniac (at) angrycube (dot) com [email concealed]> (4 replies)
Slammer worm crashed Ohio nuke plant network 2003-08-20
Anonymous (1 replies)
Slammer worm crashed Ohio nuke plant network 2003-08-21
Anonymous System Administrator (1 replies)
Slammer worm crashed Ohio nuke plant network 2003-08-24
Anonymous, System Administrator
Slammer worm crashed Ohio nuke plant network 2003-08-21
Anonymous (1 replies)
Slammer worm crashed Ohio nuke plant network 2003-08-20
Anonymous (1 replies)
Slammer worm crashed Ohio nuke plant network 2003-08-20
Anonymous (1 replies)
Slammer worm crashed Ohio nuke plant network 2003-08-21
Anonymous System Administrator
Slammer worm crashed Ohio nuke plant network 2003-08-20
Homer (1 replies)
Slammer worm crashed Ohio nuke plant network 2003-08-22
Anonymous M$ Basher
Slammer worm crashed Ohio nuke plant network 2003-08-20
Anonymous (1 replies)
Unbelieveably Irresponsible 2003-08-21
Anonymous (1 replies)
Unbelieveably Irresponsible 2003-08-21
Gallomimia (1 replies)
True. Anyone who uses an Operating System on a computer that does anything with machinery at all should know what that OS does. Microsoft OS's are vulnerable as a newborn kitten without proper protection.

In addition to those steps I would implement software-firewalls with reporting on all computer systems in the plant, as well as force all IP communications to go through a router with reporting and packet filtering. Having a 2nd router for redundancy should suffice to keep that from inhibiting operations in the event of a failure in the system.

As well, if connecting the plant network to the internet is ABSOLUTLEY necissary, put another firewall in between it and the office network. And then, do the same thing as I described above to the office network. At this time, any leased line should first go through an approval process described by a previous poster, and even then, any connection to the network should be outside the firewall. Any ports that need be open from that connection should be included in the approval process. (And the person doing the approval should make sure they don't approve anything that says "open this port so SQL slammer can spread to your corporate network." Just making sure because I can imagine a beurocrat doing that.)

But above all, don't use MS SQL.

[ reply ]

Link to this comment: http://www.securityfocus.com/comments/articles/6767/21723#21723
Unbelieveably inexperienced with these systems 2003-08-22
Anonymous System Administrator
MS Windows in a nuke plant? 2003-08-21
Ross Currie (1 replies)
"Office for Home Security" Huh? 2003-08-22
Anonymous
Slammer Worm? Guess Again 2003-08-30
Anonymous
Slammer worm crashed Ohio nuke plant network 2007-05-19
mg (at) alienmicro (dot) com [email concealed]







 

Privacy Statement
Copyright 2008, SecurityFocus