Interview with SCADA hacker pr0f about the state of infrastructure security
Last week I wrote a story on the compromise of an industrial control system in Illinois that destroyed a pump at a water processing facility. The same day a hacker came forward and posted internal information on pastebin.com from another compromised utility in South Houston, Texas.
Within hours of publication I was contacted by the hacker involved in the Texas incident and I was able to ask him a few questions via email about the state of critical infrastructure security.
In his original message to Naked Security he noted that he was able to access the systems at the South Houston facilities through two methods. Real VNC logoFirst he was able to connect to a variant of VNC that is accessible from the internet to capture the screenshots he posted. He also was able to access a web administration portal, which he claims he can still access.