DEF CON 32 - Unlocking the Gates  Hacking a secure Industrial Remote Access Solution - Moritz Abrell

DEF CON 32 - Unlocking the Gates Hacking a secure Industrial Remote Access Solution - Moritz Abrell

Source: YouTube · DEFCONConference · published Oct 16, 2024 · 18:23

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

Security researcher Moritz Sauer demonstrates hacking the Ewon Co+ industrial remote access Gateway, bypassing hardware security to potentially compromise over 500,000 devices worldwide 0:19.

Key Takeaways:
• XSS vulnerability in FTP logging allowed stealing admin credentials to execute root commands 5:22-5:52
• HSM implementation weakness allowed reverse-engineering encryption to decrypt passwords with hardcoded keys 8:30-8:57
• Certificate signing vulnerability allowed obtaining certificates for other devices by requesting with different serial numbers 14:01-14:47
• Attack impacts over 500,000 devices worldwide, potentially compromising critical infrastructure like energy plants 16:12-16:22

The research highlights how vulnerabilities in remote access solutions can create widespread security risks across critical infrastructure sectors.

Sources:

  • 0:19 Introduction to research on industrial remote access Gateway
  • 5:22-5:52 Exploit chain description
  • 8:30-8:57 HSM encryption bypass details
  • 14:01-14:47 Certificate signing vulnerability
  • 16:12-16:22 Impact scale - 500,000+ devices affected

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

[Applause] so hi Devcon thanks for having me here today also many thanks for those who made it to a Sunday 10:00 a.m. Defcon talk I really appreciate it my name is Mor AA and I am super excited to present my research unlocking the gates hacking a secure industrial remote access Gateway in this session we will delve deep into an industrial remote access Gateway uncover vulnerabilities and exploit them to affect critical infrastructure worldwide but first of all a few words about myself my name is m sael I'm working as a senior it security consultant and penetration tester at the German company sus so I love breaking stuff and I also regularly conduct security research and the results has been presented at various security conferences such as blackhead or Devcon so how does an industrial rem…