Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

It's important to understand that VNC is an open standard implemented by hundreds of different client and server packages. VNC does specify a password-authentication mechanism, but whether or not it's used, or how it's used, is entirely up to the implementation. Likewise with whether or not clients have control of the mouse and keyboard.

Historically, open VNC servers have been relatively difficult to find. I don't really mean difficult, just that you had to put some concerted effort into it and very few people did. It's a reasonably modern phenomenon that things like Shodan and other large-scale network scans (including accidental ones, like Google sometimes) can be used to quickly find them, and it's quite recent that someone has nicely packaged it into a website. So this is a problem with very little visibility until today. And it still doesn't really have that much visibility in the right place, which is the somewhat insular ICS industry (and a couple dozen other industries to a lesser extent).

SCADA HMIs and other ICS systems of that sort do often expose a VNC interface with no mouse and keyboard control - effectively a 'read-only' interface as you say. This is certainly less of a concern than allowing people on the internet control, but it is a significant and unnecessary security exposure. The kind of information revealed there can be very helpful to an adversary in finding a way to gain control.

In most cases, access to change configuration is protected, although it's often not protected well. I expect common vandalism against internet-exposed ICS to become more and more common going forward. In most cases it doesn't really have the potential to cause permanent damage, only reduced productivity or mere irritation to the real operators. This is not always the case, though. Idaho National Laboratories conducted a notable demonstration of causing permanent and disabling damage to a diesel generator via unauthorized access to a SCADA interface (the Aurora demonstration).



FYI: Websites like this have actually existed since late 2013 when Paul McMillan scanned the Internet for VNC images live during his talk and made the results available via a website in real-time. He did it again in 2014 at Defcon together with Dan Tentler and Rob Graham. Later that year people at CCC released a VNC roulette and they did the same again in 2015. And Shodan has been grabbing VNC images as well since 2014, made available at https://images.shodan.io


I consider this timeframe to be quite recent, for the reason that most of these systems, in ICS especially, have been installed for quite a bit longer. One of the biggest problems in that industry, as I'm sure you're aware, is the relatively very long lifecycle of equipment, and low rate of in-the-field updates.


Yes, you're right. Compared to how long these systems have actually been connected to the Internet it's only recently that we've started measuring the extent of their exposure.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: