Hello 

Create Profile

Creating your profile will enable you to submit photos and stories to get published on News24.


Please provide a username for your profile page:

This username must be unique, cannot be edited and will be used in the URL to your profile page across the entire 24.com network.

Settings

Location Settings

News24 allows you to edit the display of certain components based on a location. If you wish to personalise the page based on your preferences, please select a location for each component and click "Submit" in order for the changes to take affect.









Facebook Sign-In

Hi News addict,

Join the News24 Community to be involved in breaking the news.

Log in with Facebook to comment and personalise news, weather and listings.

 
 

Software security flaw exposed

2008-06-11 14:36
line

San Francisco - Attackers could gain control of countries' water treatment plants, natural gas pipelines and other critical utilities because of a vulnerability in the software that runs such facilities, security researchers reported on Wednesday.

Experts with Boston-based Core Security Technologies, who discovered the deficiency and described it exclusively to The Associated Press before they issued a security advisory, said there is no evidence anyone else found or exploited the flaw.

Security experts say the finding highlights the possibility that hackers could cut the power to entire cities, poison a water supply by disrupting water treatment equipment, or cause a nuclear power plant to malfunction by attacking the utility's controls.

Citect Pty Ltd, which makes the software program called CitectSCADA, patched the hole last week, five months after Core Security first notified Citect of the problem.

But the vulnerability could have counterparts in other so-called supervisory control and data acquisition, or SCADA, systems. And it is not clear whether all Citect clients have installed the patch.

SCADA systems remotely manage computers that control machinery, including water supply valves, industrial baking equipment and security systems at nuclear power plants.

Customers that use CitectSCADA include natural gas pipelines in Chile, major copper and diamond mines in Australia and Botswana, a large pharmaceutical plant in Germany and water treatment plants in Louisiana and North Carolina.

For an attack involving the vulnerability that Core Security revealed on Wednesday to occur, the target network would have to be connected to the internet. That goes against industry policy but does happen when companies have lax security measures, such as connecting control systems' computers and computers with internet access to the same routers.

'It's not a very elaborate problem'

A rogue employee could also access the system internally.

The possibility of sabotage has grown in recent years as more utility systems are connected to the internet.

The Citect vulnerability is of a common type. Called a "buffer overflow", it allows a hacker to gain control of a program by sending a computer too much data.

"It's not a very elaborate problem," Ivan Arce, Core Security's chief technology officer, said. "If we found this thing - and this was not that hard - it would be easy for someone else to do it."

Citect is a subsidiary of French power-equipment giant Schneider Electric SA. Company representatives did not return repeated calls for comment.

Citect said in a statement included in Core Security's advisory that customers should isolate their SCADA systems entirely from the internet or make sure they use firewalls and other technologies to prevent the systems from talking to the outside world.

Normally, the facilities that use SCADA systems fix flaws privately and very little is revealed publicly about any problems.

What's clear is that such control systems are increasingly vulnerable to internet-borne threats, since viruses and worms have disrupted service in power plants, automobile factories and gasoline pipelines - even when those facilities were not targeted.

Alan Paller, director of research for the SANS Institute, which operates the internet Storm Centre, an early warning system for computer attacks, said Core Security Technologies' discovery shows many major facilities may remain vulnerable.

"It dashes the defence of, 'We're different, we don't have that kind of problem,"' Paller said. "That's why this is significant."

- AP

inside news24

 
1 of 10

140
1

Latest comment in Sci-Tech

JPWhiteHome says... Looking upstream to find pollution in the generation of electricity is a valid analysis. I am left to wonder if the researchers also accounted for the electric it takes to refine oil into gasoline, or the fuel to transport it half way round the world, cost of transporting refined gas to the gas stations. I find it hard to believe there is more pollution from electric generation than oil activities such as exploring, drilling, transporting, refining, transporting, pumping and burning. Not to mention the fuel expended to wage war to protect the supply of oil. Read the article...

 
Traffic
Lottery
 
  • Friday Carletonville - 10:01 AM
    Road name: N14
    ROAD CLOSED due to a large sink-hole between the two Carletonville exits - traffic is diverted onto a local bypass route
  • Sunday Volksrust - 07:33 AM
    Road name: N11 Both Ways
    Stop / go controls for construction works at Majuba Pass - expect delays between Volksrust and Newcastle
  • Monday Centurion - 15:41 PM
    Road name: Jean Avenue
    ROAD CLOSED between Rabie Street and Gerhard Street for sink hole repair works
 
More traffic reports...
 

Jobs [change area]

Cars[change area]

FORD

Figo 1.4 Ambiente 5-dr
2011
R 99,899.00

HONDA

Civic 1.8 LXi AT
2009
R 154,950.00

FORD

Fiesta 1.6 Titanium 3-dr MY10
2009
R 154,950.00

Property [change area]

Travel - Look, Book, Go!

Romance at the President

Spend two nights at the Protea Hotel President in Cape Town from R2601 per person sharing. Includes return flights, taxes, car hire and accommodation. Book Now!

Kalahari.com - shop online today

The Big Mama Sale

The Big Mama Sale is now on. Get up to 80% off Books, Music, DVDs, Games, Electronics, Toys & Gifts. Shop now.

Electronics on Sale

Up to 80% off electronics + 24hr delivery. Shop now.

50% Off Educo toys

Join the Big Mama Sale madness at kalahari.com and get 50% off all Educo toys for your kids. Terms and conditions apply. Shop now.

Books on Sale

Up to 80% off books & 1000s Of books to choose from. First come, first served. While stocks last. Shop now.

Blu-ray special offer

Buy 10 blu-rays and get a free Sony blu-ray player. Offer valid while stocks last. Shop now.

OLX Free Classifieds [change area]

Drain & Pipe Inspection System

For Sale, Garage Sale in South Africa, Gauteng, Johannesburg. Date January 21

2011 Mazda 2 1.5 Dynamic

Vehicles, Cars in South Africa, Gauteng, Johannesburg. Date January 22

Estimator

Jobs, Engineering Jobs - Architecture Jobs in South Africa, Gauteng, Johannesburg. Date January 21

Apple iPad 2 Black 16GB 9.7" Tablet With WiFi & 3G

Two cameras for FaceTime and HD video recording. The dual-core...

From R5849.00

I'm shopping for:

A local community where you can meet people, upload photos, videos and loads more...
There are new stories on the homepage. Click here to see them.