Sanctioned to Hack: Your SCADA HMIs Belong to Us!

By Aditya K Sood on 05 Nov 2015 @ Groundzerosummit
πŸ”— Link
We need help to complete this entry! Missing: presentation, Video
I can help!
#ics-security #web-security #firmware-analysis #hmi #scada
Focus Areas: πŸ”§ Hardware Security , πŸ” Application Security , 🏭 Industrial Control Systems Security , πŸ“‘ IoT Security , πŸ”¬ Reverse Engineering , 🌐 Web Application Security

Abstract

Human Machine Interfaces (HMIs) have direct access to SCADA databases including critical software programs. The majority of SCADA systems have web-based HMIs that allow the humans to control the SCADA operations remotely through Internet. This talk will unveil various flavors of undisclosed vulnerabilities in web-based SCADA HMIs including but not limited to remote or local file inclusions, insecure authentication through clients, weak password hashing mechanisms, firmware discrepancies, hardcoded credentials, insecure web-services, weak cryptographic design, cross-site request forgery, and many others.