Vulnerabilities / Threats
2/23/2012
02:01 PM
Connect Directly
RSS
E-Mail
50%
50%

Anonymous, NSA Square Off On Power Grid Attacks

Anonymous calls claim that it might target U.S. power grid 'ridiculous;' security expert says power grid security can already be hacked.

Anonymous: 10 Facts About The Hacktivist Group
Anonymous: 10 Facts About The Hacktivist Group
(click image for larger view and for slideshow)
Could Anonymous add "blackouts" to its list of accomplishments?

The director of the National Security Agency, Gen. Keith Alexander, has cautioned that within a couple of years, hacktivist collectives such as Anonymous could pose a threat to power grids. His warnings have been made in private White House briefings, reported the Wall Street Journal.

But the Anonops blog, a reliable source of Anonymous-related information, Tuesday disputed that the group had any inclination to crash power grids. "Ridiculous! Why should Anonymous shut off power grid? Makes no sense! They just want to make you feel afraid," read a post to the blog.

Indeed, attacking power grids wouldn't seem to square with the group's modus operandi. To date, Anonymous has focused on sowing the seeds of anarchic online mayhem largely by doxing--releasing sensitive documents--and launching distributed denial-of-service (DDoS) attacks.

[ Anonymous-linked hacktivists recently targeted stock exchanges. Read more at Anonymous-Backed Attacks Took Nasdaq Website Offline.]

To date, its targets have largely been symbolic, and its attacks seemingly designed to generate news headlines in support of Anonymous ideals. Accordingly, the group has launched DDoS attacks at payment card processors who blocked WikiLeaks funding, released an audio recording of an FBI conference call that discussed prosecutions of alleged LulzSec and Anonymous members, and regularly released documents and taken down the public websites of numerous law enforcement and intelligence agencies.

Regardless, any talk of potential Anonymous attacks on power grids completely misses the point, said control system security expert Joe Weiss, who heads Applied Control Solutions, via phone. Notably, some of the industrial control systems used to manage power grids can already be hacked into using known vulnerabilities.

"This whole thing about [how] it's going to take [Anonymous] a year or two [to hack the power grid]? Well, it doesn't just have to be Anonymous. Anybody who knows enough about how to use some of these exploits can do that now. It's a scary thought. And that part is being missed."

Notably, Weiss said, published vulnerabilities for numerous control systems are already circulating online. "One of the things that just happened--and we're talking around Valentine's Day--is there were a number of controller vulnerabilities, and exploit code for them was basically put on the Metasploit website," he said.

"The bottom line is that these systems are not secure; they were not designed to be secure," said Weiss. "Somebody who's knowledgeable can do much more damage than someone who's not knowledgeable, which sounds like a trivial thing. But someone not knowledgeable or who doesn't know what they're doing can still cause problems." Whether or not they're Anonymous.

It's no longer a matter of if you get hacked, but when. In this special retrospective of news coverage, Monitoring Tools And Logs Make All The Difference, Dark Reading takes a look at ways to measure your security posture and the challenges that lie ahead with the emerging threat landscape. (Free registration required.)

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
cuckoosnest
50%
50%
cuckoosnest,
User Rank: Apprentice
2/23/2012 | 8:11:41 PM
re: Anonymous, NSA Square Off On Power Grid Attacks
I think the NSA is right and maybe even over estimating the time it would take for Anonymous have this capability. I had the opportunity to analyze threats to a large US power grid company's SCADA gateways. These gateways provided access to the computers that manage the power grid. The bottom line is the power grid is at the mercy of the education and knowledge employees have about computer privacy and security. The most likely route to gaining control of the power grids is by getting control of an employee's computer. Anyone who uses a computer needs some basic, non-computer-geek speak knowledge about computer privacy and security.

http://rod.gs/Ecl
Register for Dark Reading Newsletters
White Papers
Flash Poll
Current Issue
Cartoon
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-1544
Published: 2014-07-23
Use-after-free vulnerability in the CERT_DestroyCertificate function in libnss3.so in Mozilla Network Security Services (NSS) 3.x, as used in Firefox before 31.0, Firefox ESR 24.x before 24.7, and Thunderbird before 24.7, allows remote attackers to execute arbitrary code via vectors that trigger cer...

CVE-2014-1547
Published: 2014-07-23
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 31.0, Firefox ESR 24.x before 24.7, and Thunderbird before 24.7 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

CVE-2014-1548
Published: 2014-07-23
Multiple unspecified vulnerabilities in the browser engine in Mozilla Firefox before 31.0 and Thunderbird before 31.0 allow remote attackers to cause a denial of service (memory corruption and application crash) or possibly execute arbitrary code via unknown vectors.

CVE-2014-1549
Published: 2014-07-23
The mozilla::dom::AudioBufferSourceNodeEngine::CopyFromInputBuffer function in Mozilla Firefox before 31.0 and Thunderbird before 31.0 does not properly allocate Web Audio buffer memory, which allows remote attackers to execute arbitrary code or cause a denial of service (buffer overflow and applica...

CVE-2014-1550
Published: 2014-07-23
Use-after-free vulnerability in the MediaInputPort class in Mozilla Firefox before 31.0 and Thunderbird before 31.0 allows remote attackers to execute arbitrary code or cause a denial of service (heap memory corruption) by leveraging incorrect Web Audio control-message ordering.

Best of the Web
Dark Reading Radio
Listen Now Botnet Takedowns: Who's Winning, Who's Losing
Sara Peters hosts a conversation on Botnets and those who fight them.