Overview
Syllabus
Intro
Before we start...
Previous work
Industrial systems are used as weapons
Traditional ICS networks
Industrial Things?
Industrial Control Gateways
Industrial gateways on the internet
Low barrier of access
Network segmentation
Equipment needed
Finding potential targets...
Moxa W2150A - Firmware
Moxa W2150A: libupgrade Firmware
Moxa W2150A - Hardware
Moxa W2150A - Finding vulnerabilities
Moxa W2150A - Custom protocol
Fuzzing
Fixing vulnerabilities...
Advantech EKI-1522: edgserver
Advantech EKI-1522: Hardware
EKI-1522: Finding vulnerabilities
Lantronix EDS2100: Firmware
EDS2100: Finding vulnerabilities
EDS2100: Webinterface
Schneider PowerLogic EGX100
VPN vulnerabilities
Some other devices are even worse
Summary
Taught by
Black Hat