Security Issues In Compiled PLC Logic (CoDeSys & ProConOs)
Автор: S4 Events
Загружено: 2023-02-27
Просмотров: 1290
Reid Wightman on S4x23's Technical Deep Dive Stage looks at two popular, used in 100's of different PLCs, runtime logic packages: CoDeSys and ProConOs. After some background Reid asks the key question he will address at the 5:00 mark:
Can we install a logic rootkit without root privileges? The answer of course is yes since Reid is on stage.
One of the key problems: applications have write access to have almost all areas of memory in the runtime. Key quote: "The logic runtime is basically the sole mechanism of interfacing with the PLC AND the logic runtime has the ability to have all kinds of data tampered with from the program logic."
Reid then goes into detailed examples, and ends with some suggestions for the CoDeSys and ProConOs vendors, 3rd party vendors that use these runtimes, and asset owners.
Доступные форматы для скачивания:
Скачать видео mp4
-
Информация по загрузке: