Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | Re: [Full-Disclosure] Viral infection via Serial Cable |
|---|---|
| Date: | Tue, 31 Aug 2004 10:01:11 -0400 |
James Tucker wrote:
I think that we're missing something here. The workstation sends commands to the laser via the serial connection (assumed RS232 for this example and not TCP/IP based) so presumably, the win2k workstation can send whatever commands it wants to the laser via the serial cable within the bounds of its programming.Sure, but you can only move up a stack which exists.
Given that there should be no applications on the other end of the RS232 apart from the CAD/CAM control program (one would hope, this would be considered 'normal'), the only hackable device should be that program. It's not unlikely that the program in question could be set to perform destructive actions; allot of industrial software of this type is not well written and buffers certainly don't always get checked. This would require a custom hack though, I don't know of any viri which carry protocol definitions for RS232 CAD/CAM programs.
I agree with you, but when the quote is put into context, that's not what Bush meant. It was an angry response of his to an American who owned a website criticizing him."There aught to be limits to freedom!" George Bush
Not to defend the guy, he makes allot of stupid comments and decisions, however he is talking about laws and he is not wrong, there are many people in the world who need certain freedoms removed. How about they learn to remove the freedom of gun ownership.
You give the man too much credit.
-Barry
_______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.netsys.com/full-disclosure-charter.html
| Previous by Date: | RE: [Full-Disclosure] Viral infection via Serial Cable, Glenn_Everhart |
|---|---|
| Next by Date: | [Full-Disclosure] [SECURITY] [DSA 543-1] New krb5 packages fix several vulnerabilities, debian-security-announce |
| Previous by Thread: | Re: [Full-Disclosure] Viral infection via Serial Cable, James Tucker |
| Next by Thread: | RE: [Full-Disclosure] Viral infection via Serial Cable, Aditya |
| Indexes: | [Date] [Thread] [Top] [All Lists] |