An Open Source Tool for Safely Analyzing Exposed Modbus PLCs

https://hackernoon.imgix.net/images/an-abstract-industrial-network-of-interconnected-control-nodes-with-flowing-entropy-patterns-ok3s2xn0on74vi0op2lvgvad.png

Why active scanning is a liability on fragile industrial control streams, and how to fingerprint real PLCs vs. honeypots down to register entropy.


The Problem with Modbus Being on the Internet

Modbus was designed in 1979. It was built for closed, serial networks where the core architectural assumption was simple: if you could physically reach the wire, you were supposed to be there. There was no authentication. No encryption. No concept of an untrusted caller.

That assumption held for decades. Then came Ethernet encapsulation. Then came remote monitoring. Then came cloud connectivity and the slow, steady erosion of the physical air-gap that industrial engineers took for granted.

Today, you can find thousands of Modbus devices exposed on Shodan. Public IP addresses, port 502, responding to anyone who sends a valid request frame. Some of them are real Programmable Logic Controllers (PLCs) in actual facilities. Some are misconfigured building automation systems....

Copyright of this story solely belongs to hackernoon.com. To see the full text click HERE

Read more