Stories
Slash Boxes
Comments

SoylentNews is people

SoylentNews is powered by your submissions, so send in your scoop. Only 11 submissions in the queue.
posted by martyb on Friday February 12 2021, @05:51AM   Printer-friendly
from the best-practices-for-insecurity dept.

Breached water plant employees used the same TeamViewer password and no firewall:

The Florida water treatment facility whose computer system experienced a potentially hazardous computer breach last week used an unsupported version of Windows with no firewall and shared the same TeamViewer password among its employees, government officials have reported.

After gaining remote access [...] the unknown intruder increased the amount of sodium hydroxide—a caustic chemical better known as lye—by a factor of 100. The tampering could have caused severe sickness or death had it not been for safeguards the city has in place.

According to an advisory from the state of Massachusetts, employees with the Oldsmar facility used a computer running Windows 7 to remotely access plant controls known as a SCADA—short for “supervisory control and data acquisition”—system. What’s more, the computer had no firewall installed and used a password that was shared among employees for remotely logging in to city systems with the TeamViewer application.

Massachusetts officials wrote:

The unidentified actors accessed the water treatment plant’s SCADA controls via remote access software, TeamViewer, which was installed on one of several computers the water treatment plant personnel used to conduct system status checks and to respond to alarms or any other issues that arose during the water treatment process. All computers used by water plant personnel were connected to the SCADA system and used the 32-bit version of the Windows 7 operating system. Further, all computers shared the same password for remote access and appeared to be connected directly to the Internet without any type of firewall protection installed.

[....] The revelations illustrate the lack of security rigor found inside many critical infrastructure environments.

It was a 32-bit computer; so they wisely had Windows 7 instead of XP.

See also:
recent SoylentNews article about this, attempt to poison the water supply of residents in Oldsmar, Forida.


Original Submission

 
This discussion has been archived. No new comments can be posted.
Display Options Threshold/Breakthrough Mark All as Read Mark All as Unread
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
  • (Score: 3, Insightful) by DECbot on Friday February 12 2021, @05:15PM (1 child)

    by DECbot (832) on Friday February 12 2021, @05:15PM (#1112003) Journal

    No. You constantly have to constantly encourage managers not to meddle when things are working fine. As once preached by the BOFH, a 10,000V difference should be observed between the server chassis and the floor of the server room so any manager that thinks they can simply reboot a server when a service is down will get a reminder of why it is not wise to piss on an electric fence. A well trained manager will not act until you tell him what to do. Next time, he will wait for you to tell him the cattle fence is off and it is safe to press the reset switch instead of him rebooting a server while you're ssh'ed in and editing broken firewall config.

    --
    cats~$ sudo chown -R us /home/base
    Starting Score:    1  point
    Moderation   +1  
       Insightful=1, Total=1
    Extra 'Insightful' Modifier   0  
    Karma-Bonus Modifier   +1  

    Total Score:   3  
  • (Score: 3, Insightful) by DannyB on Friday February 12 2021, @05:48PM

    by DannyB (5839) Subscriber Badge on Friday February 12 2021, @05:48PM (#1112013) Journal

    If an unqualified manager has access to the physical server, then you have a physical security problem.

    --
    The Jupiter 2 is headed into a region of highly energized saran wrap.