Vulnerabilities / Threats
2/23/2012
02:01 PM
50%
50%

Anonymous, NSA Square Off On Power Grid Attacks

Anonymous calls claim that it might target U.S. power grid 'ridiculous;' security expert says power grid security can already be hacked.

Anonymous: 10 Facts About The Hacktivist Group
Anonymous: 10 Facts About The Hacktivist Group
(click image for larger view and for slideshow)
Could Anonymous add "blackouts" to its list of accomplishments?

The director of the National Security Agency, Gen. Keith Alexander, has cautioned that within a couple of years, hacktivist collectives such as Anonymous could pose a threat to power grids. His warnings have been made in private White House briefings, reported the Wall Street Journal.

But the Anonops blog, a reliable source of Anonymous-related information, Tuesday disputed that the group had any inclination to crash power grids. "Ridiculous! Why should Anonymous shut off power grid? Makes no sense! They just want to make you feel afraid," read a post to the blog.

Indeed, attacking power grids wouldn't seem to square with the group's modus operandi. To date, Anonymous has focused on sowing the seeds of anarchic online mayhem largely by doxing--releasing sensitive documents--and launching distributed denial-of-service (DDoS) attacks.

[ Anonymous-linked hacktivists recently targeted stock exchanges. Read more at Anonymous-Backed Attacks Took Nasdaq Website Offline.]

To date, its targets have largely been symbolic, and its attacks seemingly designed to generate news headlines in support of Anonymous ideals. Accordingly, the group has launched DDoS attacks at payment card processors who blocked WikiLeaks funding, released an audio recording of an FBI conference call that discussed prosecutions of alleged LulzSec and Anonymous members, and regularly released documents and taken down the public websites of numerous law enforcement and intelligence agencies.

Regardless, any talk of potential Anonymous attacks on power grids completely misses the point, said control system security expert Joe Weiss, who heads Applied Control Solutions, via phone. Notably, some of the industrial control systems used to manage power grids can already be hacked into using known vulnerabilities.

"This whole thing about [how] it's going to take [Anonymous] a year or two [to hack the power grid]? Well, it doesn't just have to be Anonymous. Anybody who knows enough about how to use some of these exploits can do that now. It's a scary thought. And that part is being missed."

Notably, Weiss said, published vulnerabilities for numerous control systems are already circulating online. "One of the things that just happened--and we're talking around Valentine's Day--is there were a number of controller vulnerabilities, and exploit code for them was basically put on the Metasploit website," he said.

"The bottom line is that these systems are not secure; they were not designed to be secure," said Weiss. "Somebody who's knowledgeable can do much more damage than someone who's not knowledgeable, which sounds like a trivial thing. But someone not knowledgeable or who doesn't know what they're doing can still cause problems." Whether or not they're Anonymous.

It's no longer a matter of if you get hacked, but when. In this special retrospective of news coverage, Monitoring Tools And Logs Make All The Difference, Dark Reading takes a look at ways to measure your security posture and the challenges that lie ahead with the emerging threat landscape. (Free registration required.)

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
cuckoosnest
50%
50%
cuckoosnest,
User Rank: Apprentice
2/23/2012 | 8:11:41 PM
re: Anonymous, NSA Square Off On Power Grid Attacks
I think the NSA is right and maybe even over estimating the time it would take for Anonymous have this capability. I had the opportunity to analyze threats to a large US power grid company's SCADA gateways. These gateways provided access to the computers that manage the power grid. The bottom line is the power grid is at the mercy of the education and knowledge employees have about computer privacy and security. The most likely route to gaining control of the power grids is by getting control of an employee's computer. Anyone who uses a computer needs some basic, non-computer-geek speak knowledge about computer privacy and security.

http://rod.gs/Ecl
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading Tech Digest, Dec. 19, 2014
Software-defined networking can be a net plus for security. The key: Work with the network team to implement gradually, test as you go, and take the opportunity to overhaul your security strategy.
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2015-2086
Published: 2015-02-26
Cross-site scripting (XSS) vulnerability in the live preview in the Panopoly Magic module before 7.x-1.17 for Drupal allows remote authenticated users to inject arbitrary web script or HTML via a pane title.

CVE-2015-2087
Published: 2015-02-26
Unrestricted file upload vulnerability in the Avatar Uploader module before 6.x-1.3 for Drupal allows remote authenticated users to execute arbitrary PHP code by uploading a file with a PHP extension, then accessing it via unspecified vectors.

CVE-2015-2088
Published: 2015-02-26
Cross-site scripting (XSS) vulnerability in unspecified administration pages in the Term Queue module before 6.x-1.1 for Drupal allows remote attackers to inject arbitrary web script or HTML via unknown vectors.

CVE-2015-2089
Published: 2015-02-26
Multiple cross-site request forgery (CSRF) vulnerabilities in the CrossSlide jQuery (crossslide-jquery-plugin-for-wordpress) plugin 2.0.5 for WordPress allow remote attackers to hijack the authentication of administrators for requests that (1) change plugin settings or conduct cross-site scripting (...

CVE-2015-2090
Published: 2015-02-26
SQL injection vulnerability in the ajax_survey function in settings.php in the WordPress Survey and Poll plugin 1.1.7 for Wordpress allows remote attackers to execute arbitrary SQL commands via the survey_id parameter in an ajax_survey action to wp-admin/admin-ajax.php.

Dark Reading Radio
Archived Dark Reading Radio
How can security professionals better engage with their peers, both in person and online? In this Dark Reading Radio show, we will talk to leaders at some of the security industry’s professional organizations about how security pros can get more involved – with their colleagues in the same industry, with their peers in other industries, and with the IT security community as a whole.