What the Tech logo
Welcome! Register for a free account (or login) > How does it work?
  1. Quickly register. It will only take 60 seconds.
  2. Start a new topic. Ask your question. Wait for an email reply.
  3. Is your system infected? Begin reading the malware removal guide.
register button
 
Reply to this topicStart new topic
> Citect SCADA ODBC service exploit published
AplusWebMaster
post Sep 8 2008, 06:29 PM
Post #1


AplusWebMaster
*****

Group: Authentic Member
Posts: 4,573
Joined: 30-December 03
From: USA
Member No.: 1,643
Operating System: XP/SP3



FYI...

- http://isc.sans.org/diary.html?storyid=4997
Last Updated: 2008-09-08 23:45:34 UTC ...(Version: 5) - "In June we talked about a SCADA buffer overflow vulnerability discovered by CORE that affected the CitectSCADA product. It could allow a remote un-authenticated attacker to force DoS or to execute arbitrary code on vulnerable systems. The patch was available at that time, so if you have not patched or taken extreme security precautions and countermeasures yet, you have another reason to do so today! This weekend, Kevin Finisterre has published a working exploit in the form of a Metasploit (MSF) module that demosntrates how critical this vulnerability aginst the ODBC service is. The original CORE advisory* details the vulnerability ( http://web.nvd.nist.gov/view/vuln/detail?v...d=CVE-2008-2639 )... our DShield service shows a peak in the wild associated to the target vulnerable port (TCP/20222)**."
* http://www.coresecurity.com/content/citect...e-vulnerability

** http://www.dshield.org/port.html?port=20222

"...a Snort signature to detect the SCADACitect ODBC exploit has been released ..."
- http://www.digitalbond.com/index.php/2008/...or-citect-vuln/

lookaround.gif
Go to the top of the page
 
+Quote Post

Reply to this topicStart new topic

 

Collapse

> Similar Topics

    Topic Title Replies Topic Starter Views Last Action
No New Posts   7 Skandranon 291 20th February 2010 - 12:47 PM
Last post by: Skandranon
No New Posts   2 HellsGate 176 31st January 2010 - 01:04 AM
Last post by: HellsGate
No New Posts 1 Jason Pr0 184 25th January 2010 - 03:08 AM
Last post by: paws
No New Posts   1 saddler64 343 13th December 2009 - 03:31 PM
Last post by: Ztruker

RSS Time is now: 19th March 2010 - 11:57 AM
Advertisements do not imply our endorsement of that product or service. The forum is run by volunteers who donate their time and expertise. We make every attempt to ensure that the help and advice posted is accurate and will not cause harm to your computer. However, we do not guarantee that they are accurate and they are to be used at your own risk.
Member site: Alliance of Security Analysis Professionals | UNITE Against Malware
Memory Forums | Auto Repair Forum
© Geeks to Go, Inc. | All Rights Reserved | Privacy Policy