TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Show HN: OpalOPC – OPC UA Vulnerability Scanner

2 点作者 ValtteriL超过 1 年前
Hiya HN,<p>A client in the automation sector was looking for a tool to test the security of their OPC UA servers. All I could find was either mere PoCs or otherwise hard to grasp and use for an OT person in a corporate setting [0-3].<p>Therefore I set to create one myself. First, I invented different things to check in servers, categorized them, and approximated a CVSS score for each. Then I created an easy-to-use scanner program that does the checking and outputs a pretty HTML report.<p>The scanner contains both GUI and CLI. It is free for non-commercial use and for commercial use if your organization&#x27;s yearly turnover is less than $1M.<p>It is still early in development, and I got multiple new checks and other things to add to it. There may be bugs lurking in there as well.<p>You can try it on a practice target I setup for that purpose (Try not to hammer on the server too hard): opc.tcp:&#x2F;&#x2F;scanme.opalopc.com:53530<p>All feedback welcome and encouraged. Thanks! :)<p>[0] <a href="https:&#x2F;&#x2F;github.com&#x2F;scy-phy&#x2F;OPC-UA-attacks-POC">https:&#x2F;&#x2F;github.com&#x2F;scy-phy&#x2F;OPC-UA-attacks-POC</a> [1] <a href="https:&#x2F;&#x2F;github.com&#x2F;abirke&#x2F;opcuapen">https:&#x2F;&#x2F;github.com&#x2F;abirke&#x2F;opcuapen</a> [2] <a href="https:&#x2F;&#x2F;github.com&#x2F;secure-software-engineering&#x2F;opcua-scanner">https:&#x2F;&#x2F;github.com&#x2F;secure-software-engineering&#x2F;opcua-scanner</a> [3] <a href="https:&#x2F;&#x2F;github.com&#x2F;COMSYS&#x2F;msf-opcua">https:&#x2F;&#x2F;github.com&#x2F;COMSYS&#x2F;msf-opcua</a><p>Nmap was a source of inspiration for the CLI version.

暂无评论

暂无评论