Free Republic
Browse · Search
General/Chat
Topics · Post Article

Skip to comments.

Advantech industrial serial-to-Internet gateways wide open to unauthorized access
IDG News Service ^ | Jan 19, 2016 4:40 AM PT | Lucian Constantin

Posted on 01/19/2016 7:35:57 PM PST by Utilizer

Internet-connected industrial devices could be accessible to anyone, with no password, thanks to a coding error by a gateway manufacturer.

Taiwanese firm Advantech patched the firmware in some of its serial-to-IP gateway devices in October to remove a hard-coded SSH (Secure Shell) key that would have allowed unauthorized access by remote attackers.

But it overlooked an even bigger problem: Any password will unlock the gateways, which are used to connect legacy serial devices to TCP/IP and cellular networks in industrial environments around the world.

Researchers from security firm Rapid7 discovered the vulnerability in the revised firmware, version 1.98, released for the Advantech EKI-1322 Internet protocol (IP) gateway which can connect serial and Ethernet devices to a cellular network.

The firmware contains an open-source SSH server called Dropbear that has been heavily modified. As a result of these modifications, it no longer enforces authentication, allowing any user to connect to it with any public key and password, the Rapid7 researchers said in an advisory.

(Excerpt) Read more at csoonline.com ...


TOPICS: Computers/Internet
KEYWORDS: ics; infosec; internet; networks; passwords; scada; security; ssh
Another net-tech security flaw...
1 posted on 01/19/2016 7:35:57 PM PST by Utilizer
[ Post Reply | Private Reply | View Replies]

To: Utilizer

Coding “error”.


2 posted on 01/19/2016 7:38:54 PM PST by Squeako (Trump: The Red Kool-Aid to Obama's Blue Kool-Aid. (See home page for Rules For Trumpicals))
[ Post Reply | Private Reply | To 1 | View Replies]

To: Utilizer

All your robot are belong to crackers. ;-)


3 posted on 01/19/2016 8:19:33 PM PST by familyop ("Welcome to Costco. I love you." --Costco greeter in "Idiocracy")
[ Post Reply | Private Reply | To 1 | View Replies]

To: familyop

Thank you, Reverant Al! (Just kidding, mate! :) )


4 posted on 01/19/2016 8:28:56 PM PST by Utilizer (Bacon A'kbar! - In world today are only peaceful people, and the muzrims trying to kill them)
[ Post Reply | Private Reply | To 3 | View Replies]

To: Utilizer

LOL! I’m a linguistic Luddite.

For folks who didn’t “hack” circa mid-1990s and before, a hacker is one who tries risky code modifications, trial and error to get some package or feature working. A cracker is one who covets, sodomizes and violates the systems of others.


5 posted on 01/19/2016 8:47:20 PM PST by familyop ("Welcome to Costco. I love you." --Costco greeter in "Idiocracy")
[ Post Reply | Private Reply | To 4 | View Replies]

To: Utilizer

NetBSD is a great embedded system, by the way, for anyone with more time, less money and high reliability standards and security standards for industrial controls.

http://netbsd.org/


6 posted on 01/19/2016 8:51:47 PM PST by familyop ("Welcome to Costco. I love you." --Costco greeter in "Idiocracy")
[ Post Reply | Private Reply | To 1 | View Replies]

To: Utilizer

ICS SCADA information security Ping.


7 posted on 01/19/2016 9:16:09 PM PST by MarchonDC09122009 (When is our next march on DC? When have we had enough?)
[ Post Reply | Private Reply | To 1 | View Replies]

To: familyop

Maybe you can explain the difference between KNOS secure desktop and Tails ..... if ya have time.


8 posted on 06/23/2017 6:21:43 AM PDT by Squantos (Be polite, be professional, but have a plan to kill everyone you meet ...)
[ Post Reply | Private Reply | To 5 | View Replies]

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
General/Chat
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson