Over 100,000 open servers leave U.S. infrastructure vulnerable

Researchers say oil and gas systems, medical devices, naval ships all at potential risk of manipulation

Topics: cyberthreats, Cybersecurity, servers, infrastructure, cyber-vulnerabilities, ,

Over 100,000 open servers leave U.S. infrastructure vulnerable (Credit: Shutterstock)

Since former Defense Secretary Leon Panetta last year warned of the risks of a “cyber Pearl Habor” striking U.S. infrastructure, experts have been arguing back and forth about the scale of cyberthreats facing the U.S. This week, researchers from security firm Rapid7 said that critical infrastructure, including oil and gas systems, medical devices, naval ships faced very real risks of manipulation, owing to over 100,000 open servers used for remote access into their managing systems.

Via TechWeek:

At InfoSec 2013 today, researchers from security firm Rapid7 told TechWeekEurope they have found it easy to access and toy with critical systems… Claudio Guarnieri, researcher at Rapid7, showed TechWeekEurope how he was able to use the vulnerabilities to track nation state-owned ships, including those belonging to the military and law enforcement, and various other vessels. He could determine what kind of ship they were, and if they were part of a naval fleet, whilst a malicious hacker could send false radar information to the crew, potentially causing carnage.

He was able to track 34,000 boats, and acquired the information with just four hours of work. “This is stuff that was used by boats  originally to not crash into each other… it provides geolocation information,” Guarnieri added.

But there was also evidence oil and gas supply monitoring could be manipulated, potentially causing real-world damage by altering readings to trick those running the systems to make changes where none are needed. SCADA [supervisory control and data acquisition] systems , like those Stuxnet compromised, were found hooked up to a large number of vulnerable serial servers.

Earlier Wednesday Salon noted that cybersecurity tests on the USS Freedom — the Navy’s newest warship — found vulnerabilities in the vessel’s computer systems.

Natasha Lennard is an assistant news editor at Salon, covering non-electoral politics, general news and rabble-rousing. Follow her on Twitter @natashalennard, email nlennard@salon.com.

Next Article

Related Stories

Featured Slide Shows

The week in 10 pics

close X
  • Share on Twitter
  • Share on Facebook
  • Thumbnails
  • Fullscreen
  • 1 of 11
  • This photo. President Barack Obama has a laugh during the unveiling of the George W. Bush Presidential Center in Dallas, Tx., Thursday. Former first lady Barbara Bush, who candidly admitted this week we've had enough Bushes in the White House, is unamused.
    Reuters/Jason Reed

  • Rescue workers converge Wednesday in Savar, Bangladesh, where the collapse of a garment building killed more than 300. Factory owners had ignored police orders to vacate the work site the day before.
    AP/A.M. Ahad

  • Police gather Wednesday at the Massachusetts Institute of Technology to honor campus officer Sean Collier, who was allegedly killed in a shootout with the Boston Marathon bombing suspects last week.
    AP/Elise Amendola

  • Police tape closes the site of a car bomb that targeted the French embassy in Libya Tuesday. The explosion wounded two French guards and caused extensive damage to Tripoli's upscale al-Andalus neighborhood.
    AP/Abdul Majeed Forjani

  • Protestors rage outside the residence of Indian Prime Minister Manmohan Singh Sunday following the rape of a 5-year-old girl in New Delhi. The girl was allegedly kidnapped and tortured before being abandoned in a locked room for two days.
    AP/Manish Swarup

  • Clarksville, Mo., residents sit in a life boat Monday after a Mississippi River flooding, the 13th worst on record.
    AP/Jeff Roberson

  • Workers pause Wednesday for a memorial service at the site of the West, Tx., fertilizer plant explosion, which killed 14 people and left a crater more than 90 feet wide.
    AP/The San Antonio Express-News, Tom Reel

  • Aerial footage of the devastation following a 7.0 magnitude earthquake in China's Sichuan province last Saturday. At least 180 people were killed and as many as 11,000 injured in the quake.
    AP/Liu Yinghua

  • On Wednesday, Hazmat-suited federal authorities search a martial arts studio in Tupelo, Miss., once operated by Everett Dutschke, the newest lead in the increasingly twisty ricin case. Last week, President Barack Obama, Sen. Roger Wicker, R.-Miss., and a Mississippi judge were each sent letters laced with the deadly poison.
    AP/Rogelio V. Solis

  • The lighting of Freedom Hall at the George W. Bush Presidential Center Thursday is celebrated with (what else but) red, white and blue fireworks.
    AP/David J. Phillip

  • Recent Slide Shows

  • Share on Twitter
  • Share on Facebook
  • Thumbnails
  • Fullscreen
  • 1 of 11

Comments

0 Comments

Comment Preview

Your name will appear as username

You may use these HTML tags and attributes: <a href=""> <b> <em> <strong> <i> <blockquote>