Information Security News mailing list archives

Finland a haven for vulnerable SCADA systems


From: InfoSec News <alerts () infosecnews org>
Date: Fri, 22 Mar 2013 02:06:06 -0500 (CDT)

http://www.theregister.co.uk/2013/03/22/finland_scada_vulnerabilities/

By Richard Chirgwin
The Register
22nd March 2013

Security researchers in Finland have turned up thousands of unsecured Internet-facing SCADA systems in that country, using the Shodan search engine.

The researchers, from Aalto University, ran their test in January, and found 2,915 exposed systems running functions from building automation to transport and water supply. Those responses were out of a total of 185,000 Finnish IP addresses that responded to an HTTP request.

Exposed building automation systems, the researchers claimed, included a bank, a gaol, and a hospital, according to communications and networking professor Jukka Manner. The researchers claimed that many systems were vulnerable through their remote user interfaces.

Interestingly, when the university re-ran its test in March, it found that a large number of the systems had been removed from the Internet, although 1,969 of the systems were still present. “A lot of problems can … still be hiding”, according to research assistant Seppo Tillkainen, since as much as 30 percent of the Finnish IP address space is still not mapped by Shodan.

[...]

______________________________________________
Attend #HITB2013AMS April 8th - 11th in Amsterdam.
Featuring over 42 international speakers and keynotes
by Bob Lord and Edward Schwartz http://conference.hitb.org

Current thread: