Archive for 'Nessus SCADA Plugins'
Nessus DirectFeed Gets a New Name and Goes on Sale
Since we just can’t seem to stop talking about naming issues related to the Bandolier project (Audit File vs. Template, Categories, Severity Ratings), here’s one more: Tenable is changing their Nessus DirectFeed product to ProfessionalFeed. This annual subscription service is a prerequisite for using the Bandolier audit files. Among other things, it also gives you [...]
Author: Jason Holcomb
Posted: June 25th, 2008 under Bandolier, Nessus SCADA Plugins, Security Vendor, The Rack.
Comments: 2
Introducing Bandolier: Vulnerability Scanner Audit Files
We had all our asset owner and vendor partners in the Dept. of Energy research project rightly say we need names for the forthcoming tools. So let us introduce the first: Bandolier.
Bandolier will be a set of security audit templates that you will run on Nessus and other popular vulnerability scanners to compare control system [...]
Author: Dale Peterson
Posted: February 4th, 2008 under Bandolier, DoE Research Project, Nessus SCADA Plugins.
Comments: 6
DoE Project Part 1 – Auditing with Nessus
A few friends have pointed out we need to come up with a project name or acronym for our DoE research contract project. Suggestions would be welcome. There are three parts to this project, and all are described in more detail in the Project Narrative.
Part 1 – Compliance Auditing with Nessus
The Nessus Vulnerability Scanner [...]
Author: Dale Peterson
Posted: October 30th, 2007 under Bandolier, DoE Research Project, Nessus SCADA Plugins.
Comments: 1
OPC AppID List for Audit Tool
We mentioned AppID’s in our introduction of the OPC Security .audit files for use in compliance testing with the Nessus Vulnerability Scanner.
While it is not difficult to find the AppID for your OPC server, we have started a SCADApedia page with the AppID’s to help you out. A lot of this information came from Lluis [...]
Author: Dale Peterson
Posted: September 24th, 2007 under Nessus SCADA Plugins, OPC, The Rack.
Comments: none
OPC Audit Tool for Nessus
Part 3 of the recently released OPC Security whitepaper series provided step by step instructions for implementing the available security measures for OPC clients and servers. It is complex, and we wondered if there was a simple way to audit OPC servers compliance with Part 3. We still are wondering, but we have a partial [...]
Author: Dale Peterson
Posted: September 20th, 2007 under Nessus SCADA Plugins, OPC, The Rack.
Comments: 3
Important New Nessus Plugin for ICCP Users
This is an interesting case study post for most readers and important for ICCP users.
In 2006, Matt Franz at Digital Bond discovered a vulnerability in the SISCO stack used in a large percentage of ICCP servers. Following our responsible disclosure process, we reported this to the vendor and US-CERT /CERT. On January 17, 2007, US-CERT [...]
Author: Dale Peterson
Posted: March 1st, 2007 under ICCP, Nessus SCADA Plugins, The Rack.
Comments: 2
Dale Peterson Interview on Tenable Site
I was interviewed yesterday by Ron Gula about SCADA security issues, active and passive scanning of control systems, and the SCADA plugins for Nessus.
Download and listen to the MP3 interview
Check out the Tenable Network Security Blog for the latest tips on how to use Nessus.
Author: Dale Peterson
Posted: December 21st, 2006 under Nessus SCADA Plugins.
Comments: none
SCADA Plugins For Nessus Are Released
Digital Bond has spent the last few months developing SCADA plugins for the very popular Nessus vulnerability scanner in a research project funded and assisted by Tenable Network Security. We are proud to announce the first set of plugins is now released and available in Tenable’s Direct Feed.
Tenable Network Security has a detailed blog entry that [...]
Author: Dale Peterson
Posted: December 12th, 2006 under Nessus SCADA Plugins, The Rack.
Comments: none
Nessus OPC Checks
Similar to my 2nd blog on Nessus ICCP Checks, here are some screen shots from the OPC checks we’ve been developing with Tenable for Nessus 3.
The first shows the output of the base OPC Detection plugin that identifies OPC applications and CLSIDs installed on the host. The security note would show up along side any [...]
Author: Matt Franz
Posted: November 8th, 2006 under Nessus SCADA Plugins, OPC.
Comments: 2
More Nessus ICCP
A while back I blogged a bit about one of the plugins we wrote for for Nessus. Here I’ll add some screenshots that better show how it might be used.
By clicking port 102 we can quickly see all the ICCP server on our network and which have security holes and notes. We can then drill [...]
Author: Matt Franz
Posted: November 2nd, 2006 under ICCP, Nessus SCADA Plugins.
Comments: none