Saturday, 22 November 2014

Siemens Fixes Critical Vulnerabilities in WinCC SCADA Products

Siemens has released software updates to address two critical vulnerabilities in its SIMATIC WinCC supervisory control and data acquisition (SCADA) system, one of which could be exploited remotely by an unauthenticated attacker.
The German industrial products giant has also released software updates for WinCC, PCS 7 and TIA Portal products, and said that it is working on additional updates for other versions of the affected products.
SIMATIC WinCC is used to monitor and control physical processes involved in industry and infrastructure, and is often used in industries such as oil and gas, chemical, food and beverage, water and wastewater. PCS 7 is a distributed control system (DCS) integrating SIMATIC WinCC, and TIA Portal is the company’s engineering software used for SIMATIC products.
Siemens LogoThe first vulnerability (CVE-2014-8551) within WinCC is rated as critical, with a CVSS Base Score or 10.0. The flaw could allow remote code execution for unauthenticated users if specially crafted packets are sent to the WinCC server, according to the security advisory from Siemens ProductCERT published Nov. 21.
The second vulnerability (CVE-2014-8552), also a component within WinCC, could allow an unauthenticated attacker to extract arbitrary files from the WinCC server by sending specially crafted packets to the server. However, in order to exploit this flaw, the attacker must have network access to the affected system, Siemens said.
While Siemens prepares additional software updates, the company’s ProductCERT team suggests that customers mitigate the risk of their systems by implementing the following steps:
• Always run WinCC server and engineering stations within a trusted network
• Ensure that the WinCC server and the engineering stations communicate via encrypted channels only (e.g. activate feature “Encrypted Communications” in WinCC V7.3 (PCS 7 V8.1), or establish a VPN tunnel)
• Restrict access to the WinCC server to trusted entities
• Apply up-to-date application whitelisting software and virus scanners
Late last month, ICS-CERT warned of an ongoing attack campaign targeting industrial control systems, including WinCC products, that has been ongoing since at least 2011. The campaign is using a variant ofthe BlackEnergy malware. BlackEnergy has been linked to a number of attacks, including the recently disclosed activities of the Sandworm Team.
"ICS-CERT has determined that users of HMI products from various vendors have been targeted in this campaign, including GE Cimplicity, Advantech/Broadwin WebAccess, and Siemens WinCC," according to the advisory. "It is currently unknown whether other vendor’s products have also been targeted."

Computer hijacking arrests in UK and across Europe

NCA raid  
Officers from the National Crime Agency carried out the raids on suspected computer hijackers
Fifteen people have been arrested, including four in the UK, in connection with the hijacking of computers.

Police say the individuals were using software designed to remotely control computers - allowing for the stealing of information. The other arrests were made in Estonia, France, Romania, Latvia, Italy, and Norway. The practice, which in some instances can grant access to a victim's webcam, is known as "Ratting". The phrase takes its name from the malicious software used to gain control - Remote Access Trojans (Rats). Using Rats to view people through their own webcams, without their knowledge, is becoming "increasingly common" according to the UK government-backed Get Safe Online advice website.

The National Crime Agency (NCA) said it arrested two 33-year-old men, and a 30-year-old woman, in Leed.
A 20-year-old man was arrested in Chatham, Kent, while a 19-year-old man had his home searched in Liverpool and was brought in for "voluntary questioning".

They are all accused of knowingly using Rats to spy on multiple targets.

"Victims are typically infected by being convinced to click on a link purporting to be a picture or video, or disguised as a legitimate file, but is instead an installer for the Rat," the NCA explained in a statement.

"In many cases, those who unwittingly install such trojans will have no indication that their machine is infected."
line
How to protect your webcam
Woman using webcam 
 Webcams are a great way to keep in touch - with precaution
  • Webcams can be affected by viruses so be wary of emails and social network messages from strangers
  • Make sure anti-virus and firewall protection is kept up to date
  • Avoid putting webcams in bedrooms or other private areas
  • Unplug the webcam, cover the lens or point it at a blank wall when it is not in use
  • Be sure you can trust the person you are chatting to and remember webcam footage can be recorded and potentially shared online
  • If you have been the victim of inappropriate sexual contact via webcam tell a trusted adult and report it to the police via the Child Exploitation and Online Protection centre (Ceop)
Source: ChildNet International and Ceop
line
As well as the arrests, the NCA said it was warning other users that the software was illegal, and its use would result in further action.
"The illegal use of Remote Access Trojans is a significant cybercrime threat, demanding this kind of strong, co-ordinated response from international to local UK level," said Andy Archibald, deputy director of the NCA's National Cyber Crime Unit.
"Suspected users of Rats are continuing to find that, despite having no physical contact or interaction with their victims, they can still be identified, tracked down and arrested by the NCA and its partners."
An investigation by BBC Radio 5 live in June last year looked into the growing problem of Ratting.
One victim, student Rachel Hyndman, told the station: "I was sitting in the bath, trying to relax, and suddenly someone potentially has access to me in this incredibly private moment and it's horrifying.
"To have it happen to you without your consent is horribly violating."
The investigation uncovered websites where hackers share pictures and videos of their victims.