Stuxnet the SCADA worm

Author: Kacper Wysocki
Contact: kwy@redpill-linpro.com
Date: October 1, 2010

Overview

SCADA systems

Who uses SCADA?

How does SCADA work?

Roughly:

What is Stuxnet ?

Stuxnet facts

Attack techniques

Targeted attack

PLC attack

Clues

Speculation

More speculation

Questions?

Thanks!

References

http://www.langner.com/en/index.htm http://www.zdnet.com/blog/security/ms-ships-temporary-fix-it-for-windows-shortcut-zero-day-attacks/6916 http://www.symantec.com/connect/blogs/w32stuxnet-network-information http://www.securelist.com/en/blog/2291/Myrtus_and_Guava_Episode_MS10_061 http://threatpost.com/en_us/blogs/stuxnet-attack-shows-signs-nation-state-involvement-experts-say-080410 http://www.zdnet.com/blog/security/as-attacks-escalate-microsoft-ships-emergency-windows-patch/7027 http://www.upi.com/News_Photos/Features/The-Nuclear-Issue-in-Iran/1581/1/ http://norman.com/security_center/security_center_archive/2010/92360/en