Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

Gas Stations Urged To Secure Internet-Exposed Fuel Tank Devices
Dark Reading ^ | 1-26-2015 | Kelly Jackson Higgins

Posted on 01/30/2015 1:18:58 AM PST by Citizen Zed

Some 5,800 automated tank gauges, which monitor for fuel leaks and other problems with the tanks as well as fuel levels, recently were found sitting wide open on the Internet without password protection, leaving more than 5,000 gas stations in the US vulnerable to attackers who could remotely alter the alarm thresholds to simulate a leak, disrupt the fuel tank operations, and worst-case, wreak havoc by shutting down the gas stations altogether, researchers say.

Rapid 7 chief research officer HD Moore says his team scanned for the vulnerable devices after getting a heads up from Jack Chadowitz, president and CEO of Kachoolie and BostonBase Inc., who first detected the problem. "He wasn't sure if it was a serious problem" that went beyond his own clients, Moore says, so he reached out to Rapid 7, which conducted an Internet-wide scan for the devices with TCP port 10001 open to the Net.

Moore and his team sent a "get in-tank inventory report" request to all of the IPv4 addresses with an open TCP port 10001: In response, they got station names, addresses, numbers of fuel tanks, tank levels, and fuel types. While the overall discovery of vulnerable devices at 5,300 gas stations represents a mere 3% of the around 150,000 gas stations in the US, the finding is yet another example of the potential physical dangers of industrial systems and other devices exposed on the Internet.

"By swapping a metric [in the gauge], it would be easy for someone to cause some sort of havoc," Moore says.

Chadowitz, whose company provides monitoring services for gas stations and other businesses, says Vedeer-Root is the main vendor of these gauges, so it wouldn't take much for an attacker to wage a widespread assault.

(Excerpt) Read more at darkreading.com ...


TOPICS: Chit/Chat
KEYWORDS: computers; computing; energy; network
Imagine the damage Ed Bagley Jr. could do if he knew how to surf the net.
1 posted on 01/30/2015 1:18:58 AM PST by Citizen Zed
[ Post Reply | Private Reply | View Replies]

To: Citizen Zed

It’s a good thing they are pointing it out publicly.../s


2 posted on 01/30/2015 6:41:38 AM PST by Moltke ("The Press, Watson, is a most valuable institution if you only know how to use it.")
[ Post Reply | Private Reply | To 1 | View Replies]

To: Citizen Zed

It’s a good thing they are pointing it out publicly.../s


3 posted on 01/30/2015 6:42:37 AM PST by Moltke ("The Press, Watson, is a most valuable institution if you only know how to use it.")
[ Post Reply | Private Reply | To 1 | View Replies]

To: Citizen Zed; COUNTrecount; Nowhere Man; FightThePower!; C. Edmund Wright; jacob allen; ...
The Internet of Things

What could possibly go wrong?

Nut-job Conspiracy Theory Ping!

To get onto The Nut-job Conspiracy Theory Ping List you must threaten to report me to the Mods if I don't add you to the list...

4 posted on 01/30/2015 7:15:52 AM PST by null and void (The aggregate effect of competitive capitalism is indistinguishable from magic)
[ Post Reply | Private Reply | To 1 | View Replies]

To: null and void

nicely played


5 posted on 01/30/2015 7:37:11 AM PST by Nifster
[ Post Reply | Private Reply | To 4 | View Replies]

To: Citizen Zed

IOW, the main vendor of these gauges has the list of all those who don’t use his product and knows how to shut them down. Uh, huh.


6 posted on 01/30/2015 8:09:00 AM PST by bgill (CDC site, "we still do not know exactly how people are infected with Ebola")
[ Post Reply | Private Reply | To 1 | View Replies]

To: null and void

7 posted on 01/30/2015 8:47:07 AM PST by smoothsailing
[ Post Reply | Private Reply | To 4 | View Replies]

To: Citizen Zed

Sorry, but it’s PRETTY DAMN FUNNY if someone in Russia could hack-in and make a gas station owner dig out his tanks.

...perhaps people should become a bit more skeptical of “technology”, especially when they’ll end up in Chapter 7, should they get hacked.


8 posted on 01/30/2015 3:54:24 PM PST by BobL (REPUBLICANS - Fight for the WHITE VOTE...and you will win.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: smoothsailing
Here's four of 'em feeding into one another:


9 posted on 01/30/2015 6:54:16 PM PST by dayglored (Listen, strange women lying in ponds distributing swords is...sounding pretty good about now.)
[ Post Reply | Private Reply | To 7 | View Replies]

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson