Black Hat USA 2018 - Deep Dive into an ICS Firewall, Looking for the Fire Hole @HackersOnBoard
Black Hat USA 2018 - Deep Dive into an ICS Firewall, Looking for the Fire Hole  @HackersOnBoard
Uploaded October 2019 | Updated September 2026, 5 days ago
Industrial control systems (ICS) security has become a serious concern over the past years. Indeed, threat to ICS systems has become reality and real world attacks have been observed. Many systems driving critical functions cannot be stopped to receive security upgrades, protecting those very sensitive assets is thus a tough challenge.

As ICS security market is growing fast, dedicated firewalls have appeared to address this problem by inspecting and filtering industrial control protocols. But what are those solutions worth? Are they really different from standard network firewalls? What are exactly their attack surfaces and what kind of bugs may we find there?

We propose to answer those questions on the Tofino Xenon case. We will present a methodology we used to reverse engineer equipment which uses a custom and encrypted administration protocol and has fully encrypted firmware. From reverse engineering a rich client to obtaining root shell on the appliance. Then we will cover the firewall internals, the attack surface it offers and the security features it provides to vulnerable ICS equipments. Finally, we will present the vulnerabilities we found (CVE-2017-11400, CVE-2017-11401 and CVE-2017-11402), their impact and the attack scenarios to exploit them.
Black Hat USA 2018 - Deep Dive into an ICS Firewall, Looking for the Fire HoleDEF CON 27 - Can You Track Me Now? Why The Phone Companies Are Such A Privacy DisasterBlack Hat USA 2018 - How I Learned to Stop Worrying and Love the SBOMBlack Hat USA 2018 - Remotely Attacking System FirmwareBlack Hat USA 2018 - Windows Offender Reverse Engineering Windows Defenders Antivirus EmulatorDEF CON 27 - Joshua Maddux - API-Induced SSRF How Apple Pay Scattered Vulnerabilities Across the WebDEF CON 27 - The Dark Tangent - Closing CeremoniesOver-the-Air: How we Remotely Compromised the Gateway, BCM, and Autopilot ECUs of Tesla CarsBlack Hat USA 2018 - Outsmarting the Smart CityBlack Hat USA 2018 - Meltdown Basics, Details, ConsequencesBlack Hat USA 2018 - An Attacker Looks at Docker Approaching Multi Container ApplicationsBlack Hat USA 2018 - Every ROSE has its Thorn The Dark Art of Remote Online Social Engineering
HackersOnBoard |

Black Hat USA 2018 - Deep Dive into an ICS Firewall, Looking for the Fire Hole

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER