We call SHODAN. By Viss! Prepared for Defcon 20 Thursday, July 12, 12 This is not just another shodan talk. Today we turn shodan into a gateway drug. Thursday, July 12, 12 What do people put on the internet? Routers, switches, servers, printers.. Meh. seen it. Show me something new! Thursday, July 12, 12 What's on the internet that nobody is accounting for? ... is anybody actually checking? Seriously, has anybody ever done this? Thursday, July 12, 12 Thursday, July 12, 12 A little editorial o policy.... If you can't scan yourself freely, how do you determine your level of exposure? What's the attack surface? Thursday, July 12, 12 Before we begin. Everything found here is PUBLIC No credentials required no "secure" systems. This is all "free play". Thursday, July 12, 12 Also, No systems were altered. This was a READ ONLY Exercise. Thursday, July 12, 12 Thursday, July 12, 12 Thursday, July 12, 12 Thursday, July 12, 12 Thursday, July 12, 12 T-2000 CC User Interface W [ LOGIN UserName : Password : ] ^? ) 2003 ReliOn Inc. Unit Name : Unit Date 04/17/12 Unit Location : Unit Time 23:35:53 Major Alarms : O Chassis S/N Minor Alarms : 1 Control Ler Ver 02.02.01 AGO Status : OFF 0:00 FPGA Ver 01.01.03 System Status : STANDBY Comm Card Ver 02.02.01 ReliOn 15913 E. Euclid Aye Spokane, WA 99216 Tel: +1-509-223-6500 24 Hour Support: +1-366-661-0020 techsupportOre L ion-inc .com SYSTEM MESSAGES: Alpha Text, TAB-Next Fie Ld, Enter-Select, E !SC-Abandon Thursday, July 12, 12 m.. "T-2000" ! whats a T-2000?.. relion? T-2000 CC User Interface [ LQGIPi UserName : Password : (c) 2008 ReLiOn Inc. Unit Name Unit Location Major Alarms Minor Alarms AGO Status System Status OFF 0:60 STANDBY Unit Date Unit Time 04/17/12 Chassis S/N : Controller Ver : 02.02.01 FPGA Ver : 01.01.03 Comm Card Ver : 02.02.01 ReliOn 15913 E. Euclid Ave Spokane, WA 99216 Tel: +1-509-223-6500 24 Hour Support: +1-366-661-0020 techsupportOre L ion-inc .com V3TEM MESSAGES: Alpha Text, TAB-Next Field, Enter-Select, ESC-Abandon Thursday, July 12, 12 Government Off-Grid Transportation Utility Certifications Tax Incentives Thursday, July 12, 12 I PRODUCTS & SOLUTIONS T-2000 | T-2000: 2kW Outdoor Configuration I T-2000 : -ikvV Outdoor Configuration T-2000: 6kW Outdoor Configuration I T-2000: fik'A 1 Outdoor Configuration T-2000: 12kW Outdoor Configuration T-2000® 2kW PEM Fuel Cell The fuel cell system is cesignec specifically for larger communications backup power loads within the wireless and wireline telecommunications, utility and ■government sectors. The T-2000® fuel cell uses RellOn's patentee Mocular Cartridge Technology© for hot-swappable high reliability, ease of maintenance and simplicity of design. Modular electronics cares enable scalability by providing flexible configuration from 600 Watts to a full 2,000 Watt capacity In one chassis. Or combine multiple T-2000® fuel cells to provide higher outputs for a variety of site requirements up to l2kw. Click for specifications in bnglish (19 /KB) Click for specifications In Spanish (130KB) Click for specifications in Portuguese (213KB) Click for specifications In Chinese (595KB) Features: * Output: to 2,000 Watts - 24 or 46 VDC nominal output • 23 " Rack Mountable (Incoors) p Multiple Outdoor Configurations - Remote Monitoring Capability ■ Pimcrsicrs: Zb"h x 21 "w x Zl.b "c (66cm x S3cm x ^.4, 6cm) rP oks industria Field Trial Prototype ■ Relion's modular cartridge approach normally operates with six cartridges connected to a common BUS. Each cartridge supplies a nominal power of 200W. ■ In case a cartridge is damaged, the replacement procedure can be performed in a few seconds while the fuel cell continues to provide power to the load. Figure 2 -Relion's T-1000 hydrogen fuel cell MTS a/istrearL i Gets DOE/DOD Back-Up Power Demonstration Site kW Req'd Buildings Backed-up Fuel Cell Units Used Aberdeen Proving Ground 15; 20; S Energy Management Building. Range Control and Coordination, DPW Conservation Branch (3} IdaTech ElectraGen 5; Hyrogenics HyPM Rack 20; ReliOnT-2000 SkW Fort Bragg 15 Training Range Control Building ,>=,<> or : Displaying 1-25 of 576 result(s}. Seltime &timezone LGZ1 293 1286 LGZ1 2957680 LGZ129S7679 LGZ12892452 LGZ12930536 LGZ1 2892402 LGZ1 2931256 LGZ12892426 LGZ12930523 LGZ.1 293 1595 LGZ1 2892564 LGZ1 2892561 :LG2:2892455 : .C,l.2S92343 i .CZ12S37642 JLGZ12892580 ILGZ12B92419 | .02:2892566 GZ 2892547 LGZ 12 892453 LGZ12892532 .0212692163 .CZL2892S23 ! .CZ12S31571 j LGZ12892485 049895210935 049895210981 049895210972 049895144158 C49S9 32 10895 049895144189 049895210932 049895144223 049895210123 049895210707 C4989311122^ C4989 314 4222 1049895144328 049895144299 iC498932H052 1049895144260 1049895144162 1049895144323 C4989 31113D7 !C49895144163 !049895144186 C49S93111322 C49893144283 C 4989 32 1 07 19 C4989 314 4232 ;} at the beginning of each of your search ualLes to specify r dia the comparison should be done. Installation status INSTALLED INSTALLED INSTALLED INSTALLED INSTALLED INSTALLED INSTALLED INSTALLED INSTALLED INSTALLED INSTALLED INSTALLED INSTALLED INSTALLED INSTALLED INSTALLED INSTALLED INSTALLED INSTALLED INSTALLED INSTALLED INSTALLED INSTALLED INSTALLED INSTALLED j REG REG REG Treg j NEW REG REG Ireg REG REG REG REG IRlC REG Ireg ALL. FLEX ALL FLEX ALL FLEX ALL , FLEX ALL. FLEX ALL. FLEX ALL FLEX ALL . FLEX ALL. FLEX ALL FLEX ALL . FLEX ALL . FLEX ALL FLEX REG REG REG ALL FLEX ALL FLEX ALL r ^3X ALLFLEX '"" I ALL , -_EX ALL FLEX ALL FLEX j ALL ELK \ REG REG I REG ALL FLEX i ALL FLEX ALL FLEX i&LLEklx. jPP j.PP_ PP |pp [PP ;PP {PP jPP j.P_P PP PP ;PP PP IPP Ipp Ipp Ipp ipp [p p |pp Ipp pp_ pp jpp Go to page: < Previous Q [T] H [7] [jj] [T] | 10 | [ Thursday, July 12, 12 Larger industrial system SIEMENS Synco™ Central communication unit OZW775 V2.0 with integrated web server -function Commissioning instructions knx Thursday, July 12, 12 Thursday, July 12, 12 Thursday, July 12, 12 Thursday, July 12, 12 Level One: Simple recon Thursday, July 12, 12 Region: Massachusetts. [G| PageRank: No Data © Rank: No Data Google Trends ^ McAfee Site Ad visor Q WOT: Trust Wo rth i n e ss: n/a * i Vendor Reliability: n/a ° Privacy: n/a *j Child Safety: n/a Optpns Thursday, July 12, 12 Thursday, July 12, 12 Thursday, July 12, 12 ompany name leads to address evel Two: Interactions DISCLAIMER: I didn't have any idea this happened until someone showed me a gallery of screencaps... Thursday, July 12, 12 Thursday, July 12, 12 Thursday, July 12, 12 evel Three: Remember the movie Live Free or Die Hard? Thursday, July 12, 12 Thursday, July 12, 12 ough this depiction Was an insanely successful Social Engineering campaign, overall. xcept, I m not shooting down helicopters with cars. Thursday, July 12, 12 Thursday, July 12, 12 Some scada keeps logs! ■ l3-Apr- Il3-Apr- Il3-Apr- Il3-Apr- Il3-Apr- Il3-Apr- Il3-Apr- Il3-Apr- Il3-Apr- Il3-Apr- Il3-Apr- Il3-Apr- 127:16: 12 7:23: 12 7:24: 12 7:25: 12 7:23: 127:31: 127:31: 12 7:56: 129:19: 12 9:22: 12 9:24: 12 9:24: 15 AM MDT 07 AM MDT 40 AM MDT 19 AM MDT 09 AM MDT 53 AM MDT 54 AM MDT 51 AM MDT 37 AM MDT 55 AM MDT 02 AM MDT 04 AM MDT fox fox fox fox fox fox fox fox fox fox sys history, db Opened: 165 <- Opened: 166 <- Opened: 167 <- Closed: 166 <- : Closed: 167 <- : Closed: 165 <- : Opened: 163 <- 1 Closed: 163 <- 1 : Opened: 169 <- Closed: 169 <- : Saving station... Saved history archive (494ms) : WbApplet [guest] @ Owner-PC : WbApplet [admin] @ Denniss-MacBook-Pro. local : WbApplet [admin] @ Denniss-MacBook-Pro. local WbApplet [admin] @ Denniss-MacBook-Pro. local WbApplet [admin] @ Denniss-MacBook-Pro. local WbApplet [guest] @ Owner-PC : WbApplet [guest] @ Owner-PC WbApplet [guest] @ Owner-PC :: WbApplet [admin] @ Denniss-MacBook-Pro. local ; WbApplet [admin] @ Denniss-MacBook-Pro. local Thursday, July 12, 12 B£i Liebert €3 Control MENU \$CJ UPS Monitoring g^ES UPS Management |1|j UPS Configuration (j) UPS Control @ UPS Battery Test UPS Battery Test Schedule |jj UPS Shutdown Weekly Schedule (j=| Special Day Schedule |^j EMD Configuration EpO Liebert Management □ O UPS History • H UPS History Log - [ffi UPS Extended Log fffj UPS Events Log ■ [ffl Liebert Events Log [ffj Clear & Save Log Data ED-Q Language Selection ^^^^^ Comprehensive View On -Line 197.3 Output Voltage (Vo/fJ 230.7 Output Load f%J 14 Battery Capacity Remaining |%) 1DD Current Battery Voltage (Volt) 110.4 UPS Temperature fCJ 31.5 Input Frequency (Hertz) 49.5 UPS Next Off Time (hh:mm dd/mm/yyyy) UPS Next On Time (hh:mm dd/mm/yyyy) Liebert System Date (dd/mm/yyyy) 17/04/2012 Liebert System Time (hh:mm:ss) 04:35:12 Liebert Up Time (days hh:mm:ss) Odays 16:19:11 Thursday, July 12, 12 Thursday, July 12, 12 w V ay okay.. Its a little Freaky, but it's no "firesale"... Thursday, July 12, 12 id id id id id id id id id id fd fd fd fd fd fd fd fd (3(3(3(3 (3(3(3(3 (R) id id id id id ■3 (aetata @@@@ (aetata (3(3(3(3(3 (3(3(3(3 id id id id id (3(3(3(3(3(3(3(3(3(3(3(3(3 (3(3(3(3(3(3 (3(3(3(3 <3<3<3(3 @@@@@ @@@@ "3"3i3"3 (3(3(3(3(3(3(3 (3(3(3(3 @@@@ (a (a (a (a (a 13131313 (3(3(3(3 (3(3(3(3(3(3(3(3(3(3(3(3(3 id id id id id @@@@ (3(3(3(3 (3(3(3(3(3(3(3(3(3(3(3(3(3 @@@@ @@@@@ id id id id (d (d (d (d (3 (3 (3 (3 @ (3 (3 (3 (3 @ (3 (3 (3 13131313 @@@@@ @@@@ (3(3(3(3 (3(3(3(3 (3(3(3(3(3(3(3(3 @@@@ @@@@@ @@@@ (3(3(3(3 (3(3(3(3 (3(3(3(3(3(3(3 13131313 ^^^^^^^^^^^^^^ (3(3(3(3(3(3(3(3(3(3(3(3(3 (3(3(3(3 (3(3(3(3(3(3 @@@@ 131313 <3<3(3(3(3(3(3(3(3(3(3(3(3(3 id id id id id id id id id id id id id (3(3(3(3 (3(3(3(3(3 tatatata 131313 ^^^^^^^^^^^^^^ (3(3(3(3(3(3(3(3(3(3(3(3(3 (3(3(3(3 (3(3(3(3 i.LON SmartSer ^/er Copyright (c) Echelon Corporation 1999-2009. ALL rights reserved. Software provided herein may c □ntain or be derive d from portions of materials provided to Echelon under License by a third party supplier. NOTE: Use 'Logout' or Escape C haracter to exit Carver> ??| Thursday, July 12, 12 ts stackable! Like devo hats! /.LOW SmartServer POWERED BY — ECHELON ATP_SktPaulsGa/Channel 1/iLON App/AN_Omega: Configure + + e M E^ _ El ^ E^ Etf> E^ E^ Ei^ E^ E^ E^ E^ E^ E E^ E^ Navigate General O Driver Ep) AN Omega E In] PL Omega E $ I Nq PJgrwnrlf Tnrprfana fTr E DM5. Control Hardware > Vanguard v4 Co ntrol Software x Professional > Standard TRANSPORTATION BLOG TRANSPORTATION ISO 9001:2008 REGISTERED QUALITY MANAGEMENT SYSTEM - DaJctroncs -* Products & Savices -* Products -* Software & G&nrtrollHS -* DMG Software & GonrtiollMS -* Vangjarc wmm 45 45 Vanguard Professional Message Scheduler vanguard Professional Display Monitor ' TRAVEL TIME Vanguard Professional Content Studio Vanguard® v4 Professional Software Vanguard Professional enacts powerful control over large DMS networks from traffic management centers. Professional includes all the monitoring, message creation, and Thursday, July 12, 12 Thursday, July 12, 12 ow about some current events? Ruggedcom? Other stuff thats fun? Thursday, July 12, 12 N4-DLC Passwords Thursday, July 12, 12 N4-DLC Thursday, July 12, 12 Thursday, July 12, 12 Satellite systems UfOM TECH Vi^H EF DATA M CDD-564L Demod 1 IP Routing Statistics Ethorn&t I IP I Wj IP Routing Statistics - Sentf Received - Automatically Updates Every 10 Seconds Total IP Packets from Satellite Total IP Packets from Ethernet Total IGMP Packets Received [ IP Options Packets Received IP Routing Statistics - Dropped - Automatically Updates Every 10 Seconds TTL Expired - Dropped QH No ARP Entry - Dropped fT*T*l Bac! I Idrr GhkSum - Cropped Bad Buffer Leng.tr - Cropped No Route - Dropped EH Bad IP Version - Dropped Thursday, July 12, 12 storage arrays Thursday, July 12, 12 aserWash" Car Wash Systems AbortyR&cov&rv Options Door Settings Dryer Settings Freeze Protection Installed Options Machine Dimensions Machine Offsets Timers Water and Chemical Thursday, July 12, 12 Massive Humidifiers STEEM Vapor- log ic4 STATUS System Status 44.9% Auto TANK STATUS Soiling Alarms active alarms > View Alarms Messages active messages > View Messages DIAGNOSTICS SETUP Wed Jul 11 2012 22:26:31 GMT-0700 (PDT) Dala stream is LIVE View all humidifier settings below. Some settings can be changed here. Go to the Setup tab to change settings that cannot be changed from this page, TANK STATUS: Run Mode Auto | CHANGE | Input signal 4,5 VDC Steam output 44,9% Steam production 3 Ibs/hr Duct HL switch Closed Tank temperature 2ia°F Tank temp signal L745 Ohms DI low water switch Water Fill valve Open Drain valve Closed Airflow switch Flow Interlock switch Closed H20 until service L163 lbs © Copyright 2D ID DRI-5TEEM Corporation. All rights reserved. Vapor-logic is a registered trademark of DRI-STEEM Corporation. Thursday, July 12, 12 Aztek SOOOS aztekH Slot A Status: Mode: Monitoring Operation merit Alarm s Logs Call Detail Record Lock Mode NETWORKS Logout Provisioning Configuration m Date/Time Severity Object Type Object ID Location Category Description 1970/02/02 ■ 20:10:19 Minor SWUPDATE_SERVICE CTA n Slot Equipment Dial Plan download fault 19 70/01 AH - 00:00:19 Minor RESOURCE_SERVICE CTA A Slot Equipment ACTS time fault Refresh this page every 30 seconds. | Clear the Failed Dial Plan Download alarm | Thursday, July 12, 12 //**************************************************************** // You are free to copy the "Folder-Tree' 1 script as long as you // keep this copyright notices / / Script found in: http s / /www. geocities. com/mar celino_mar tins/ folder tree . html // Authors Marcelino Alves Martins { http s //www. nunar tins . coin) // 1557—2001. //**************************************************************** // Log of changes: // 10 Aug 01 // // 17 Feb // // 27 Jan 98 // Support for Netscape 6 Fix initialization flashing problem with Netscape Root folder starts open) support for USETEXTL1NKS; make the ftien4 a js file // Definition of class Folder // ************************** Thursday, July 12, 12 Thursday, July 12, 12 |~o~ ■ g 74.101.128.141 (Mark_Hotel_Wine. ■ fjS] Device Networks - ^ N2 Network - □ 1-FX07-01 ^) Points - □ 1-FX07-02 Niagara Network ^ Schedule Manager ^ Link Manager E^J Point Groups EcJ Global Point Extension Manager Alarm Console £^2 Point Histories ■ Administration + Q Files El Custom Control + (0 AlarmService - EmailService 1^1 EmailRecipient ^ OutgoingAccount + History Container View f^l Point Extension Defaults Egi BackupService £ Users (3 Time Sync § Platform DIP Web Service Serial Port Configuration j^h Dialup Configuration Name Long Name Type Out Network Point Type Netwo O Temp Champagne T3 Numeric Point 76.0 °F {ok} Analog Data Float 1 O Humidity Champagne H3 Numeric Point 58,3 %RH {ok} Analog Data Float 4 O Setpoint Temp Champagne StpT3 Numeric Writable 44.0 °F -(overridden)- @ 8 Analog Data Float 17 O Diff Temp Champagne DiffT3 Numeric Writable 3.0 i°F -(overridden)- @ 8 Analog Data Float 18 O Alarm Diff Champagne ReferenceShiftT3Avg Numeric Writable 15.0 A°F -(overridden)- @ 8 Analog Data Float 20 O Alarm Delay Champagne DelayTimeAlT3vg Numeric Writable 3600.0 s {ok} @def Analog Data Float 21 O Cooling Champagne SV3 Enum Point Off {okf Binary Data L. O Avg Temp Bar Right AvgT4 Numeric Point 53.0 °F {ok} Analog Data Float O Temp Bar Right Left T4A Numeric Point 52.7 °F {ok} Analog Data Float O Temp Bar Right Right T4B Numeric Point 53.2 °F {ok} Analog Data Float O Setpoint Temp Bar Right StpT4 Numeric Writable 44.0 °F {ok)- @ def Analog Data Float 22 O DiffAlarmT3Avg DiffAlarmT3Avg Numeric Writable 2.0 °F {ok)- @ def Analog Data Float 19 O Diff Temp Bar Right DiffT4 Numeric Writable 3,0 A°F -(overridden)- @ 8 Analog Data Float 23 O Alarm Diff Bar Right ReferenceShiftT4 Numeric Writable 10.0 i°F {ok} @ def Analog Data Float 24 O DiffAlarmT4 DiffAlarmT4 Numeric Writable 2.0 °F {ok}- @ def Analog Data Float I 9 Alarm Delay Bar Right AlarmDelayT4 Numsric Writsbls 3600.0 s {ok} @def Analog Data Float O Cooling Bar Right SV4 Enum Point Off {ok} Binary Data O Alarm Bar Right Boolean Point Normal {ok} Binary Data O Alarm Alarm Enum Point Alarm {okj- Binary Data \ • OffsetT3 OffsetT3 Numeric Writable 0.0 °F {ok}- @ def Analog Data Float # OffsetT4A OffsetT4A Numeric Writable 0.0 °F {ok}- @ def Analog Data Float # OffsetT4B OffsetT4B Numeric Writable 0.0 °F {ok} @ def Analog Data Float 15 • OffsetH3 OffsetH3 Numeric Writable 0.0 % {ok} @ def Analog Data Float 16 O RemoteValueAIl RemoteValueAIl Numeric Writable 0.0 °F -{fault)- @ def Analog Data Float 6 O RemoteValueAI2 RemoteValueAI2 Numeric Writable 0.0 °F {Fault)- @ def Analog Data Float 7 O RemoteValueAI3 RemoteValueAI3 Numeric Writable 0.0 °F {Fault}-® def Analog Data Float 8 Thursday, July 12, 12 Thursday, July 12, 12 Thursday, July 12, 12 /ION SmartServer View - Data Points t*)G«*f*l DfWtf |B rtrtAtAlArfn5mrlih_2 |» ■ ,t<-,:. v -j vf'b >: QitimJ£i ! ~:i:>; -"lUcr;, b( ridugriELtuti | ndhrEndUed ■JnahrTine ■j nri§w*tfiEn6fcted !■..!,.-...: . m |B nrtAeUijtf 'tor |> rt**Btfet?urirt ]B nwH.ampYnlue2 • ^: ^n.-.t-li-.r B 2? Funk 3 - t^-3»- ■ & LfrS Hamrofh interface ma* *a:iui H ik er the trending? Of imhmfllt'Tirul' IJA**JLl|i[«/lljunLkcAjrr: - .. i£wa\ F-H L« ErifV: 2012-0*- 17 02:43: LB 1.5 G-jant-jrrv'OTiinnel L/Wrt-nfl'vgBnhirMcMferi/ntiSwUP IHI.MU7.1M9 LSHvrjwkcii G-i*nOjrT*/CK»anf>tl L/*r*na.'.] .; >"C jrlcoi « n/nvoAttlgn no" m.»ajo.am 17 (.. -v.vi' ,rr.':; - niir-rl 1/Arc nn.' 5 ?-->nl jt l;r At Vrvof .irrr il'lrrnc 133.163.37. L9.B2 SMTT.Uiint G-jtmUjrTV'CKmnr*! 1 /* rtno ■' 9«*6 n bu m 1 c e A ft- n/ n vo De boo nee 193 LU 1.37 19 Vi SWT_llmc. ice Cfl»nt»jiWCh»nrH-l L..Arin.^ y.-vl jt !< rA-r v/i-vtil J-i ■ jiV.Hur : 133.163.37. L9:B2 [wwm 4 G ssnr jT/C--snr«-l l».lU,l7,l«r«2 Cfl«nt,jrtv'<; runnel : .-Ar? ■i.i.i; y.vl jt I-: r A -c -/i-vtil J.T ^V.ihir 1 133.163.37. L9:fl2 [ awijiuii : U* L6fl Entry: 20L24H-17 -B2HS:]7 T . ASCII LharKtSI string ASCII (hinrtrr Wring CHUNG Thursday, July 12, 12 Since scanning the whole internet is getting easier, we can take measurements! Thursday, July 12, 12 ow about some Measurable Results? Thursday, July 12, 12 Thursday, July 12, 12 Original Blogpost: Jan 10 My blogpost: Jan 24 (560 cameras) BBC Article: Feb 7 A retest: April 3 ( 464 cameras) US Media picks it up: mid April Second Retest: May 24 ( 465 cameras) Third Retest: July 12 (490 cameras) Thursday, July 12, 12 Thursday, July 12, 12 anna stalk me atenlabs.com/blog @viss Thursday, July 12, 12