<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: SCADA/HMI Security: Vulnerabilities in GE Fanuc iFIX</title>
	<atom:link href="http://www.mcgrewsecurity.com/2009/02/01/hmi-security-vulnerabilities-in-ifix/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.mcgrewsecurity.com/2009/02/01/hmi-security-vulnerabilities-in-ifix/</link>
	<description></description>
	<lastBuildDate>Thu, 05 Jan 2012 11:44:23 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: DustinV</title>
		<link>http://www.mcgrewsecurity.com/2009/02/01/hmi-security-vulnerabilities-in-ifix/#comment-522</link>
		<dc:creator>DustinV</dc:creator>
		<pubDate>Mon, 02 Feb 2009 20:28:20 +0000</pubDate>
		<guid isPermaLink="false">http://www.mcgrewsecurity.com/?p=306#comment-522</guid>
		<description>At the conf., missed getting the slides! &quot;Missed it by this much&quot;!</description>
		<content:encoded><![CDATA[<p>At the conf., missed getting the slides! &#8220;Missed it by this much&#8221;!</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Liquidmatrix Security Digest &#187; McGrew On Vulnerabilities In GE Fanuc iFIX</title>
		<link>http://www.mcgrewsecurity.com/2009/02/01/hmi-security-vulnerabilities-in-ifix/#comment-521</link>
		<dc:creator>Liquidmatrix Security Digest &#187; McGrew On Vulnerabilities In GE Fanuc iFIX</dc:creator>
		<pubDate>Mon, 02 Feb 2009 17:04:36 +0000</pubDate>
		<guid isPermaLink="false">http://www.mcgrewsecurity.com/?p=306#comment-521</guid>
		<description>[...] Article Link   Tag It: [...]</description>
		<content:encoded><![CDATA[<p>[...] Article Link   Tag It: [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: admin</title>
		<link>http://www.mcgrewsecurity.com/2009/02/01/hmi-security-vulnerabilities-in-ifix/#comment-520</link>
		<dc:creator>admin</dc:creator>
		<pubDate>Mon, 02 Feb 2009 11:36:26 +0000</pubDate>
		<guid isPermaLink="false">http://www.mcgrewsecurity.com/?p=306#comment-520</guid>
		<description>Hi Erik!

I haven&#039;t used Network Miner for this specifically, however I have used it in the past for ripping files out of SMB traffic.  Excellent tool :)</description>
		<content:encoded><![CDATA[<p>Hi Erik!</p>
<p>I haven&#8217;t used Network Miner for this specifically, however I have used it in the past for ripping files out of SMB traffic.  Excellent tool <img src='http://www.mcgrewsecurity.com/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Erik H</title>
		<link>http://www.mcgrewsecurity.com/2009/02/01/hmi-security-vulnerabilities-in-ifix/#comment-519</link>
		<dc:creator>Erik H</dc:creator>
		<pubDate>Mon, 02 Feb 2009 09:47:18 +0000</pubDate>
		<guid isPermaLink="false">http://www.mcgrewsecurity.com/?p=306#comment-519</guid>
		<description>Interesting slides! My spontaneous reaction is that the GE Fanuc developers suck at authentication. And this is not the first time they screw it up. I remember that Eyal Udassin presented a vulnerability, at the S4 (Security Scientific Symposium) conference in 2008, where the Fanc system “encrypted” the password with Base64 before sending it over the network. More info here:
http://www.digitalbond.com/index.php/2008/01/26/ge-fanuc-vulnerabilities/

But sending the whole xtcompat.utl file with SMB is even worse! Have you tried sniffing the file transfer with NetworkMiner in order to automatically rebuild the transferred XTCOMPAT.UTL file to disk? You can do live sniffing or just parse a pcap file with the SMB transfer in it. More information on extracting files from pcap’s with Network Miner can be found here: http://networkminer.wiki.sourceforge.net/NetworkMiner</description>
		<content:encoded><![CDATA[<p>Interesting slides! My spontaneous reaction is that the GE Fanuc developers suck at authentication. And this is not the first time they screw it up. I remember that Eyal Udassin presented a vulnerability, at the S4 (Security Scientific Symposium) conference in 2008, where the Fanc system “encrypted” the password with Base64 before sending it over the network. More info here:<br />
<a href="http://www.digitalbond.com/index.php/2008/01/26/ge-fanuc-vulnerabilities/" rel="nofollow">http://www.digitalbond.com/index.php/2008/01/26/ge-fanuc-vulnerabilities/</a></p>
<p>But sending the whole xtcompat.utl file with SMB is even worse! Have you tried sniffing the file transfer with NetworkMiner in order to automatically rebuild the transferred XTCOMPAT.UTL file to disk? You can do live sniffing or just parse a pcap file with the SMB transfer in it. More information on extracting files from pcap’s with Network Miner can be found here: <a href="http://networkminer.wiki.sourceforge.net/NetworkMiner" rel="nofollow">http://networkminer.wiki.sourceforge.net/NetworkMiner</a></p>
]]></content:encoded>
	</item>
</channel>
</rss>

