Security issues with PLC, Servo, HIM software

irondesk40

Member
Join Date
Jan 2008
Location
nc
Posts
630
Has anyone on this site used the Automation Direct Sure Servo software? It is Sure servo Pro.
Reason i ask is now the company i have been working for the last 40 years has gotten real picky and concerned about Cyber Security.
Can no longer download software and install it. You have to get a copy and submit to them and they go over it for security threats. Been using the Sure Servo Pro for about 5 years and no issues but now they say its a security threat. Same thing they said about RSLogix500 and 5000. Took forever to get the right person to tell them to back off.
Here are results from a Cyber Sercurity team about the software. Anyone have any idea about the piece they said was flagged?
Thanks

Software Request Justification: This software will be used to build in the R&D Engineering Department.

Recommendation:  The evidence discovered during the evaluation of this software indicate suspicious behavior. The possible threat involved is hacktool/ Expressdownloader. Although additional sources reported a low risk reputation, I believe we should not discard the potential threat mentioned.


References:

Hash: fa07eeabe6dc625c92894a62137f8c2cfb445b8e3daddd19ee3c44c00a84a708

JoeSandbox: Suspicious

https://www.joesandbox.com/analysis/657215#engines

Virustotal:  Low 0/70 
https://www.virustotal.com/gui/file...c2cfb445b8e3daddd19ee3c44c00a84a708/detection
MetaDefender: 1 Threats Detected
https://metadefender.opswat.com/res...xVlFiS0VUVGpjdy1KU3o/regular/overview?lang=en
Fidelis: Low 0/40
https://f6309e1.fideliscloud.com/j/alert/main.html?#/alerts/detail/Console-9793017 [/COLOR]
 
What a racket. I can’t comment on wether or not it’s safe or not but you can find security vulnerabilities in ANY software. Hell most hacks happen thought the security software itself.

Some big companies can’t get out of their own way. It’s a simple thing to resolve, they should assign you an engineering laptop that has special software then isolate it from specific networks.
 
An IT department isn't working properly unless they disrupt and screw with at least one perfectly functioning and profitable part of the business, once a week. Pretty sure it'll be some guys KPI.

Anyway, reading the summary version of that threat analysis report from the Cloud Sandbox service:

Sample drops PE files which have not been started, submit dropped PE samples for a secondary analysis to Joe Sandbox

Sample is looking for USB drives. Launch the sample with the USB Fake Disk cookbook

So basically the installer did its job and installed a bunch of other executables which it didn't start. Duh.

And it is looking for what drives are on the PC. Pretty standard installer activity.

Your IT guy should maybe read the report detail before making a call like this. He should be testing the actual installation files and not just the installer. They really haven't put any effort into this.
 

Similar Topics

All, we have been given a proposed plan, but would be interested to know your views on potential security issues or otherwise. There are 2...
Replies
27
Views
6,652
Is anyone aware of any recent Rockwell Software security issues that require version upgrades to mitigate? I'm talking over the past 2 months.
Replies
1
Views
712
Good Evening everyone, I am new here but thought I would post this, perhaps it has been posted before, but has anyone been following the recent...
Replies
5
Views
4,392
Hello Friends I have a backup that I am trying t open in mi PC (RSLogix 17.01) and I get this message. I have read many posts and done many...
Replies
1
Views
157
After a recent revision of code in my system on both the HMI and the HC900 PLC, I now get a popup requesting me to login when I click on the...
Replies
2
Views
506
Back
Top Bottom