Vulnerabilities / Threats
02:01 PM

Anonymous, NSA Square Off On Power Grid Attacks

Anonymous calls claim that it might target U.S. power grid 'ridiculous;' security expert says power grid security can already be hacked.

Anonymous: 10 Facts About The Hacktivist Group
Anonymous: 10 Facts About The Hacktivist Group
(click image for larger view and for slideshow)
Could Anonymous add "blackouts" to its list of accomplishments?

The director of the National Security Agency, Gen. Keith Alexander, has cautioned that within a couple of years, hacktivist collectives such as Anonymous could pose a threat to power grids. His warnings have been made in private White House briefings, reported the Wall Street Journal.

But the Anonops blog, a reliable source of Anonymous-related information, Tuesday disputed that the group had any inclination to crash power grids. "Ridiculous! Why should Anonymous shut off power grid? Makes no sense! They just want to make you feel afraid," read a post to the blog.

Indeed, attacking power grids wouldn't seem to square with the group's modus operandi. To date, Anonymous has focused on sowing the seeds of anarchic online mayhem largely by doxing--releasing sensitive documents--and launching distributed denial-of-service (DDoS) attacks.

[ Anonymous-linked hacktivists recently targeted stock exchanges. Read more at Anonymous-Backed Attacks Took Nasdaq Website Offline.]

To date, its targets have largely been symbolic, and its attacks seemingly designed to generate news headlines in support of Anonymous ideals. Accordingly, the group has launched DDoS attacks at payment card processors who blocked WikiLeaks funding, released an audio recording of an FBI conference call that discussed prosecutions of alleged LulzSec and Anonymous members, and regularly released documents and taken down the public websites of numerous law enforcement and intelligence agencies.

Regardless, any talk of potential Anonymous attacks on power grids completely misses the point, said control system security expert Joe Weiss, who heads Applied Control Solutions, via phone. Notably, some of the industrial control systems used to manage power grids can already be hacked into using known vulnerabilities.

"This whole thing about [how] it's going to take [Anonymous] a year or two [to hack the power grid]? Well, it doesn't just have to be Anonymous. Anybody who knows enough about how to use some of these exploits can do that now. It's a scary thought. And that part is being missed."

Notably, Weiss said, published vulnerabilities for numerous control systems are already circulating online. "One of the things that just happened--and we're talking around Valentine's Day--is there were a number of controller vulnerabilities, and exploit code for them was basically put on the Metasploit website," he said.

"The bottom line is that these systems are not secure; they were not designed to be secure," said Weiss. "Somebody who's knowledgeable can do much more damage than someone who's not knowledgeable, which sounds like a trivial thing. But someone not knowledgeable or who doesn't know what they're doing can still cause problems." Whether or not they're Anonymous.

It's no longer a matter of if you get hacked, but when. In this special retrospective of news coverage, Monitoring Tools And Logs Make All The Difference, Dark Reading takes a look at ways to measure your security posture and the challenges that lie ahead with the emerging threat landscape. (Free registration required.)

Comment  | 
Print  | 
More Insights
Newest First  |  Oldest First  |  Threaded View
User Rank: Apprentice
2/23/2012 | 8:11:41 PM
re: Anonymous, NSA Square Off On Power Grid Attacks
I think the NSA is right and maybe even over estimating the time it would take for Anonymous have this capability. I had the opportunity to analyze threats to a large US power grid company's SCADA gateways. These gateways provided access to the computers that manage the power grid. The bottom line is the power grid is at the mercy of the education and knowledge employees have about computer privacy and security. The most likely route to gaining control of the power grids is by getting control of an employee's computer. Anyone who uses a computer needs some basic, non-computer-geek speak knowledge about computer privacy and security.
Register for Dark Reading Newsletters
White Papers
Current Issue
Five Emerging Security Threats - And What You Can Learn From Them
At Black Hat USA, researchers unveiled some nasty vulnerabilities. Is your organization ready?
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
Published: 2015-10-15
The Direct Rendering Manager (DRM) subsystem in the Linux kernel through 4.x mishandles requests for Graphics Execution Manager (GEM) objects, which allows context-dependent attackers to cause a denial of service (memory consumption) via an application that processes graphics data, as demonstrated b...

Published: 2015-10-15
netstat in IBM AIX 5.3, 6.1, and 7.1 and VIOS 2.2.x, when a fibre channel adapter is used, allows local users to gain privileges via unspecified vectors.

Published: 2015-10-15
Cross-site request forgery (CSRF) vulnerability in eXtplorer before 2.1.8 allows remote attackers to hijack the authentication of arbitrary users for requests that execute PHP code.

Published: 2015-10-15
Directory traversal vulnerability in QNAP QTS before 4.1.4 build 0910 and 4.2.x before 4.2.0 RC2 build 0910, when AFP is enabled, allows remote attackers to read or write to arbitrary files by leveraging access to an OS X (1) user or (2) guest account.

Published: 2015-10-15
Cisco Application Policy Infrastructure Controller (APIC) 1.1j allows local users to gain privileges via vectors involving addition of an SSH key, aka Bug ID CSCuw46076.

Dark Reading Radio
Archived Dark Reading Radio
According to industry estimates, about a million new IT security jobs will be created in the next two years but there aren't enough skilled professionals to fill them. On top of that, there isn't necessarily a clear path to a career in security. Dark Reading Executive Editor Kelly Jackson Higgins hosts guests Carson Sweet, co-founder and CTO of CloudPassage, which published a shocking study of the security gap in top US undergrad computer science programs, and Rodney Petersen, head of NIST's new National Initiative for Cybersecurity Education.