DEF CON 32 - Exposing the Occultations in Large Off-Grid Solar Systems - Dan Berte & Alexandru Lazar

DEF CON 32 - Exposing the Occultations in Large Off-Grid Solar Systems - Dan Berte & Alexandru Lazar

Source: YouTube · DEFCONConference · published Oct 16, 2024 · 18:07

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

The video exposes severe cybersecurity flaws in solar energy management platforms, putting 3.5 million users and over 330,000 businesses at risk of unauthorized access and potential grid manipulation 10:00-11:11.

Key Takeaways:
• A hardcoded credential ("123456") in the SolarMan app allows unauthorized access to user data and devices across all connected systems 7:07-8:18.
• Attackers can exploit a predictable access point naming scheme (e.g., "apore") to gain remote access to solar inverters via the logger’s SSID and hardcoded credentials 8:02-8:49.
• A token forgery vulnerability enables attackers to create valid access tokens by altering user ID and email, potentially taking over up to 1.5 million accounts 11:02-12:50.
• The SolarMan platform serves approximately one-fifth of the world’s solar generation capacity, making it a high-value target for cyberattacks 16:00-16:14.

These findings challenge the long-standing belief that power grids are secure due to natural threats like squirrels, highlighting that solar infrastructure now faces significant cyber risks.

Sources:

  • 10:00-11:11 Detailed analysis of solar platform vulnerabilities and user exposure.
  • 7:07-8:18 Discovery of hardcoded credentials and access point exploitation.
  • 8:02-8:49 Attack methodology using serial number-based access points.
  • 11:02-12:50 Token forgery vulnerability enabling mass account takeover.
  • 16:00-16:14 Impact

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

it didn't warm me it was going to be bright so um we still got people coming in but um so this is going to start doing a little bit of the intro we're talking about so while everybody comes in we'll we'll get to the meat of it so uh welcome hope everybody's having a great great convention thanks for showing up uh this is fantastic we're really excited to talk about um some of this stuff because it's fresh off the presses so uh we're going to be talking about um um photo voltaics uh and some of the findings that are um recent for us so I have um here with me um Alexander lozer as one of a um senior gury researchers uh we both work for a company called bid Defender uh you may have heard of um I added a link here to uh our work so you can uh refer to it later uh some of the um vulnerability r…