Version: 2008

Comments on: Security hole found in software used by power plants

New Scientist reports that security firm has found serious security vulnerability in software used to automate power stations, oil refineries, and production lines.

Add a Comment (Log in or register) (7 Comments)
  • prev
  • 1
  • next
by AppleSuxLeo May 18, 2008 1:25 PM PDT
Doh !
Reply to this comment
by timber2005 May 18, 2008 2:35 PM PDT
Glad they've patched it before some company went public with it.
It's funny though, I've got a neighbor who works for Progress Energy in the carolinas, and as I've heard you'd be surprised that if a major computer failure were to occur, we CAN overide it. Even if we think the computers are wrong *cough* three mile island *cough* humans remain in full control.
Yes, some systems might begin automatic shutdown procedures, but after a few hours everything could be back online. Like the recent Flordia blackout.
Reply to this comment
by Boid May 18, 2008 6:57 PM PDT
i have worked with this software for over 10 years. Systems such as these are behind firewalls and are not exposed directly to the Internet. Hackers would first have to penetrate a perimeter firewall to even try to find the SCADA systems.

If they can do this, they can exploit any of the well known Windows flaws. They will probably be totally unaware that Suitelink is running and that there is a specific exploit for it.

This article is trying to build hype but is short on facts and reality.
Reply to this comment
by jollyruss May 19, 2008 9:31 AM PDT
It's scary to know that mission-critical systems such as electrical power plants, heating systems, gas plants, etc. are being managed and controlled with software that runs on Windows...
Reply to this comment
by amigabill May 19, 2008 9:57 AM PDT
Why are these things even on the public net?
Reply to this comment
by amigabill May 19, 2008 9:58 AM PDT
Why are these things even on the public net?
Reply to this comment
by Kgaines May 20, 2008 9:44 AM PDT
Amazing... I work Tech Support for Wonderware. This vulnerability was discovered in February, and a patch released in March. This "Core Security" group are a little late to the game. I sincerely hope large companies don't rely on them for important security bulletins. Needless to say, as Boid has stated, any IT/Network manager worth their salt would not have a critical production environment exposed to the internet...
Reply to this comment
(7 Comments)
  • prev
  • 1
  • next
advertisement

15 sites that went kaput in 2009

Web sites launch all the time, but they also shut their doors. We highlight 15 that bit the dust this year.

Top 10 news stories of the decade

Let the debate begin: Was the iPhone more important than iTunes? Was anything bigger than Google finding a great business model? CNET offers its list of the 10 most important stories of the '00s.

About News Blog

Recent posts on technology, trends, and more.

Add this feed to your online news reader

advertisement
advertisement