
SCADA EXPLOITS - Hex00010 - Water - Power Plant
By: a guest on
Jan 30th, 2012 | syntax:
None | size: 1.21 KB | hits: 4,253 | expires: Never
Found 2 Exploits in 2 major SCADA production Software
#1. Software allows File upload
I was able to upload a .exe file and with a RPC injected code i was able to inclde a backdoor in there
I was able to open up metasploit ans start sniffing the network then running the auto attack - gaining further access - i was able to install and hide my detection
It also allows SQL Injection against the SCADA Database
The second exploit
Allows you to edit all System logs , Shut Down SCADA Server , Modify Data , Etc etc etc
I will be writing a script for you that will help you out even more
I am able to identify thousands of these systems around the world right now - i have created a script that allows me to detect systems around the world
If you are interested in these Exploits please message on the twitter status below
Thanks
Hex00010
NOTE: This was done on a test product machine as well
Also other SCADA systems around the world including
Water Power Plants as well are using it
Proof Here: http://i41.tinypic.com/5pihc7.png