Democratic Underground Latest Greatest Lobby Journals Search Options Help Login
Google

Potential of Nuclear Power Plant Network to Worm Infection

Printer-friendly format Printer-friendly format
Printer-friendly format Email this thread to a friend
Printer-friendly format Bookmark this thread
This topic is archived.
Home » Discuss » Archives » General Discussion (Through 2005) Donate to DU
 
Kellanved Donating Member (1000+ posts) Send PM | Profile | Ignore Wed Sep-03-03 04:51 AM
Original message
Potential of Nuclear Power Plant Network to Worm Infection
Edited on Wed Sep-03-03 04:57 AM by Kellanved
--snip
The Nuclear Regulatory Commission staff has issued an Information Notice to alert nuclear power plant operators to a potential vulnerability of their computer network server to infection by the Microsoft SQL Server worm.
The vulnerability was demonstrated by a January event at the shutdown Davis-Besse nuclear power plant. The worm infection increased data traffic in the site’s network, resulting in the plant’s Safety Parameter Display System and plant process computer being unavailable for several hours. Neither of those systems, however, affects the safe operation of a nuclear plant. NRC regulations require safety-related systems to be isolated or have send-only communication with other systems. Public health and safety were never impacted during the incident.

FirstEnergy Nuclear, the licensee at Davis-Besse, investigated the incident and found a contractor established an unprotected computer connection to its corporate network, through which the worm reached the plant network. The investigation also found plant computer engineering personnel were unaware of a security patch that prevented the worm from working. Corrective actions include requiring documentation of all external connections to the internal network, installing an additional layer of security software, and ensuring computer personnel review new security patches and install them promptly.

Information Notice 2003-14, “Potential of Plant Computer Network to Worm Infection,” will be available electronically on the NRC’s web site at this address: http://www.nrc.gov/reading-rm/doc-collections/gen-comm/info-notices/2003/.
--snap
from:
http://www.nrc.gov/reading-rm/doc-collections/news/2003/03-108.html


Now that meakes me feel safe... :scared:
Printer Friendly | Permalink |  | Top
JM Donating Member (1000+ posts) Send PM | Profile | Ignore Wed Sep-03-03 06:43 AM
Response to Original message
1. To quote...
...the sqlsecurity.com website

"there is no patch for stupidity"

the SQL worm could have been prevented simply by having a password on the master account. SQL 7.0 out of the box didn't have a password on the master account.

Later,
JM

Printer Friendly | Permalink |  | Top
 
Kellanved Donating Member (1000+ posts) Send PM | Profile | Ignore Wed Sep-03-03 03:48 PM
Response to Reply #1
5. stupidity and nuclear power plants
That mixture almost guarantees a disaster.
Printer Friendly | Permalink |  | Top
 
htuttle Donating Member (1000+ posts) Send PM | Profile | Ignore Wed Sep-03-03 07:51 AM
Response to Original message
2. I dont' know which is more lame...
...That nobody at the plant knew about the patch, or that they had an external network connection from their LAN to a contractor AND DIDNT' KNOW IT!?!?

Printer Friendly | Permalink |  | Top
 
Kellanved Donating Member (1000+ posts) Send PM | Profile | Ignore Wed Sep-03-03 09:36 AM
Response to Reply #2
3. That they didn't use the connection to download the patch
Of course they did not know about either :shrug:


Printer Friendly | Permalink |  | Top
 
Generic Other Donating Member (1000+ posts) Send PM | Profile | Ignore Wed Sep-03-03 10:18 AM
Response to Original message
4. They only used the patch if they wanted to quit smoking
Isn't it a known fact that the incidence of brain tumors and other serious cancers is much higher at nuclear facilities?
Printer Friendly | Permalink |  | Top
 
Brian Sweat Donating Member (1000+ posts) Send PM | Profile | Ignore Wed Sep-03-03 03:51 PM
Response to Original message
6. BFD
Core physics isn't automated.
Printer Friendly | Permalink |  | Top
 
DU AdBot (1000+ posts) Click to send private message to this author Click to view 
this author's profile Click to add 
this author to your buddy list Click to add 
this author to your Ignore list Fri Dec 27th 2024, 04:03 AM
Response to Original message
Advertisements [?]
 Top

Home » Discuss » Archives » General Discussion (Through 2005) Donate to DU

Powered by DCForum+ Version 1.1 Copyright 1997-2002 DCScripts.com
Software has been extensively modified by the DU administrators


Important Notices: By participating on this discussion board, visitors agree to abide by the rules outlined on our Rules page. Messages posted on the Democratic Underground Discussion Forums are the opinions of the individuals who post them, and do not necessarily represent the opinions of Democratic Underground, LLC.

Home  |  Discussion Forums  |  Journals |  Store  |  Donate

About DU  |  Contact Us  |  Privacy Policy

Got a message for Democratic Underground? Click here to send us a message.

© 2001 - 2011 Democratic Underground, LLC