TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Was The 3 Character Password at Hacked Water Treatment Plant A Siemens Default?

18 点作者 TheloniusPhunk超过 13 年前

6 条评论

16s超过 13 年前
I don't know the details of this specific system, but I have seen some systems that would break (utter and complete failure) upon password change. Some vendors would go so far as to threaten that support contracts would not be honored if passwords were changed. That was 12 years ago, but I imagine that some vendors still hard-code passwords and rely on them not changing. It'll take lawyers and contracts and court battles to sort those vendors out.
swdunlop超过 13 年前
"and other Internet-facing Simatic HMI systems .."<p>I love that ThreatPost wedged that one in there -- anyone who has worked with SCADA systems knows the second rule is "don't expose your HMI's." (The first rule is "don't believe the vendor.")
pavel_lishin超过 13 年前
&#62; couldn't confirm that a default, three digit password hard coded into an application used to control the company's SCADA software played a role.<p>Isn't that as good as saying "yes, the default password is always 100"?
AJ007超过 13 年前
That's not a hack, that's opening a door locked by a piece of tape.
nomdeplume超过 13 年前
should have shipped with custom password. Assuming the sysadmin could read.
faragon超过 13 年前
123
评论 #3266817 未加载