"Shodan"

This too shall pass.
Post Reply
AzariLoveIran

"Shodan"

Post by AzariLoveIran »

.


Over the past two years, Shodan has gathered data on nearly 100 million devices, recording their exact locations and the software systems that run them.


.

Homeland security officials have warned that the obscurity that had protected many industrial control systems was fast dis­appearing in a flood of digital light.

“This means that these delicate [control computers] are potentially reachable from the Internet by malicious and skilled adversaries,” a Department of Homeland Security paper concluded in 2010.

The number of intrusions and attacks in the United States is rising fast. From October to April, the DHS received 120 incident reports, about the same as for all of 2011. But no one knows how often breaches have occurred or how serious they have been. Companies are under no obligation to report such intrusions to authorities.

.

well

people who live in glass houses should not throw rocks

really stupid


.
User avatar
Typhoon
Posts: 27436
Joined: Mon Dec 12, 2011 6:42 pm
Location: 関西

Re: "Shodan"

Post by Typhoon »

AzariLoveIran wrote:.

Over the past two years, Shodan has gathered data on nearly 100 million devices, recording their exact locations and the software systems that run them.
.

Homeland security officials have warned that the obscurity that had protected many industrial control systems was fast dis­appearing in a flood of digital light.

“This means that these delicate [control computers] are potentially reachable from the Internet by malicious and skilled adversaries,” a Department of Homeland Security paper concluded in 2010.

The number of intrusions and attacks in the United States is rising fast. From October to April, the DHS received 120 incident reports, about the same as for all of 2011. But no one knows how often breaches have occurred or how serious they have been. Companies are under no obligation to report such intrusions to authorities.

.
well

people who live in glass houses should not throw rocks

really stupid

.
Well, 20/20 hindsight does have its benefits.

Have to wonder how much complexity and cost new security measures will add to all these industrial processes.
May the gods preserve and defend me from self-righteous altruists; I can defend myself from my enemies and my friends.
User avatar
monster_gardener
Posts: 5334
Joined: Fri Dec 23, 2011 12:36 am
Location: Trolla. Land of upside down trees and tomatos........

Thank You & This was happening long before Stuxnet

Post by monster_gardener »

AzariLoveIran wrote:.


Over the past two years, Shodan has gathered data on nearly 100 million devices, recording their exact locations and the software systems that run them.


.

Homeland security officials have warned that the obscurity that had protected many industrial control systems was fast dis­appearing in a flood of digital light.

“This means that these delicate [control computers] are potentially reachable from the Internet by malicious and skilled adversaries,” a Department of Homeland Security paper concluded in 2010.

The number of intrusions and attacks in the United States is rising fast. From October to April, the DHS received 120 incident reports, about the same as for all of 2011. But no one knows how often breaches have occurred or how serious they have been. Companies are under no obligation to report such intrusions to authorities.

.

well

people who live in glass houses should not throw rocks

really stupid


.

Thank you VERY Much for your post, Azari.

Good article...... Thanks again.
people who live in glass houses should not throw rocks

really stupid
Per the article that boat had sailed long ago......

Long before StuxNet...

Uz doing it to the Soviets........

Soviets doing it to the Estonians (Not in the article)

Chinese doing it to Uz (Not in the article)

That JackAss in Oz doing it to the local Sewer Plant :roll:

For that matter, it was a part of an episode of "24" several seasons ago where IIRC Muslim terrorists with rogue Russian help did it to Uz..........

It's a classic warfare problem....... Harder to defend than to attack.... Have to maintain discipline...

This time the convenience of flash drives over-riding the security of the air gap.....
For the love of G_d, consider you & I may be mistaken.
Orion Must Rise: Killer Space Rocks Coming Our way
The Best Laid Plans of Men, Monkeys & Pigs Oft Go Awry
Woe to those who long for the Day of the Lord, for It is Darkness, Not Light
User avatar
monster_gardener
Posts: 5334
Joined: Fri Dec 23, 2011 12:36 am
Location: Trolla. Land of upside down trees and tomatos........

"Shodan" Security Cost Data Point.... Vitek Bodan

Post by monster_gardener »

Typhoon wrote:
AzariLoveIran wrote:.

Over the past two years, Shodan has gathered data on nearly 100 million devices, recording their exact locations and the software systems that run them.
.

Homeland security officials have warned that the obscurity that had protected many industrial control systems was fast dis­appearing in a flood of digital light.

“This means that these delicate [control computers] are potentially reachable from the Internet by malicious and skilled adversaries,” a Department of Homeland Security paper concluded in 2010.

The number of intrusions and attacks in the United States is rising fast. From October to April, the DHS received 120 incident reports, about the same as for all of 2011. But no one knows how often breaches have occurred or how serious they have been. Companies are under no obligation to report such intrusions to authorities.

.
well

people who live in glass houses should not throw rocks

really stupid

.
Well, 20/20 hindsight does have its benefits.

Have to wonder how much complexity and cost new security measures will add to all these industrial processes.
Thank you Very Much for your post, Typhoon.
Have to wonder how much complexity and cost new security measures will add to all these industrial processes.
Since you asked......... Here is one data point.....
Since the attack, Maroochy Water Service has spent upwards of $55,309 changing every physical lock for pumping stations; it has also implemented strict access key controls and adopted further auditing procedures.
http://www.computerworld.com/s/article/ ... geNumber=2


Boden had waged a three-month war against the SCADA (Supervisory Control and Data Acquisition) system of Maroochy Water Services in Australia beginning in January 2000, which saw millions of gallons of sewage spill into waterways, hotel grounds and canals around the Sunshine Coast suburb. He was caught only after a team of private investigators hired by Maroochy Water Services alerted police to his location. ..................

"When police went to intercept him, he did a runner; the police then ran him off the road and found a car full of proprietary gear. No one had seen him hack our systems, but from his laptop we were able to find the last recorded event and messages sent which exactly matched our SCADA radio monitoring systems."

Vitek Boden was arrested, charged and found guilty on 30 charges of computer hacking, theft and causing environmental damage and jailed for just over two years.
The JackAss only got 2 years for doing this......... Was angry he didn't get hired..... *


Here is a Japanese link with what I believe is a photo of the perp :evil: ..........

Image

Please let me know if this is not Vitek Boden...........

http://tech.qq.com/a/20101204/000116_1.htm

Google Translated.........
http://translate.google.com/translate?s ... 0116_1.htm


* Note: Perhaps something extra might have been in order........ Besides the jail time.....

Remembering the end of John M. Ford's "Web of Angels".......

Perhaps being forbidden to use a computer for about 5 years.... No cell phones etc...... Have to get someone else to access the web for him... Get caught with a smart phone or at a computer keyboard and back to prison for another 1 or 2 years......

http://www.amazon.com/Web-Angels-John-M ... 391&sr=1-2
For the love of G_d, consider you & I may be mistaken.
Orion Must Rise: Killer Space Rocks Coming Our way
The Best Laid Plans of Men, Monkeys & Pigs Oft Go Awry
Woe to those who long for the Day of the Lord, for It is Darkness, Not Light
Post Reply