news4geeks.net
26Apr/120

Backdoor in industrial networking hardware



ROS is designed for service with electricity suppliers and in the transport and defence sectors The Rugged Operating System (ROS), an operating system created by the developers at RuggedCom, contains an undocumented backdoor. RuggedCom, a Siemens subsiduary, specialises in industrial grade networking equipment for "harsh environments" and recommends its switches and servers for use in power plants, oil refineries, military environments and traffic monitoring systems. 

A posting on a security mailing list has now documented that all ROS systems have a "factory" user account that, the author says, cannot be disabled. Its password is derived from the hardware address of the network interface; a small Perl script demonstrates how a MAC address of00-0A-DC-00-00-00 turns into a password called 60644375.

A user on the same network as the system will have no problem finding out the MAC address. As a workaround until a fix has been released, the US-CERT recommends that the affected systems' Telnet and RSH services be disabled; however, it is unclear whether the backdoor account is also accessible via SSH or HTTPS services.

The timeline of this incident is particularly troubling for customers concerned about timely fixes, as RuggedCom appears to have been contacted by the discoverer of the backdoor over a year ago. Apparently, the company confirmed knowledge of this backdoor but didn't show any willingness to fix it. After the US-CERT was notified and communicated with the Siemens affiliate, also it appears without success, the issue was publicly disclosed by US-CERT. Siemens fully acquired Canadian firm RuggedCom for almost $400 million earlier this year.

(Source: h-online.com)

 

Software engineers can finally switch lights on and off, and change their colour, without resorting to hardware controls - thanks to the Philips Hue SDK and its RESTful ...
READ MORE
Best browser: which should you be using?
Competition among browsers is more fierce than ever. Chrome and Firefox release 72 new versions every week, Microsoft has redesigned Internet Explorer to make it finger-friendly, and ...
READ MORE
Is it an Apple advert, a commercial for insurance, or an episode of Glee? No, it’s the first Surface commercial from Microsoft. Hot on the heels of Microsoft’s Windows 8 ad ...
READ MORE
Acer CEO issues warning as Microsoft staffs up Surface team
Despite the recent bashing in the press from its partners, Microsoft continues to forge ahead with plans to turn a profit by making its own hardware, as ...
READ MORE
Floodgates to open for Windows RT tablets in January
Got your scorecard ready? The road to Windows RT has been filled with speculation about the software (we're still faced with many unanswered questions), but the hardware ...
READ MORE
Philips pushes out SDK for multicolour Zigbee LED
Best browser: which should you be using?
Microsoft Surface ad targets preppy, Glee-watching youngsters
Acer CEO issues warning as Microsoft staffs up
Floodgates to open for Windows RT tablets in

Comments (0) Trackbacks (0)

No comments yet.


Leave a comment

Trackbacks are disabled.

Tags

Categories

Calendar

April 2012
M T W T F S S
« Mar   May »
 1
2345678
9101112131415
16171819202122
23242526272829
30