Section 5. System Overview
71
5.1.10.1 Vulnerabilities
While "security through obscurity" may have provided sufficient protection in the
past, Campbell Scientific dataloggers increasingly are deployed in sensitive
applications. Devising measures to counter malicious attacks, or innocent
tinkering, requires an understanding of where systems can be compromised and
how to counter the potential threat.
Note
Older CR800 operating systems are more vulnerable to attack than recent
updates. Updates can be obtained free of charge at
www.campbellsci.com
.
The following bullet points outline vulnerabilities:
CR1000KD Keyboard Display
•
Pressing and holding the "Del" key while powering up a CR800 will cause it
to abort loading a program and provide a 120 second window to begin
changing or disabling security codes in the settings editor (not
Status
table)
with the keyboard display.
•
Keyboard display security bypass does not allow telecommunications access
without first correcting the security code.
•
Note
These features are not operable in CR1000KDs with serial numbers
less than 1263. Contact Campbell Scientific for information on upgrading the
CR1000KD operating system.
LoggerNet:
•
All datalogger functions and data are easily accessed via RS-232 and Ethernet
using Campbell Scientific datalogger support software.
•
Cora command
find-logger-security-code
.
Telnet:
•
Watch IP traffic in detail. IP traffic can reveal potentially sensitive
information such as FTP login usernames and passwords, and server
connection details including IP addresses and port numbers.
•
Watch serial traffic with other dataloggers and devices A Modbus capable
power meter is an example.
•
View data in the
Public
and
Status
tables.
•
View the datalogger program, which may contain sensitive intellectual
property, security codes, usernames, passwords, connection information, and
detailed or revealing code comments.
FTP:
•
Send and change datalogger programs.
•
Send data that have been written to a file.
HTTP:
•
Send datalogger programs.
•
View table data.
Содержание CR850
Страница 2: ......
Страница 4: ......
Страница 6: ......
Страница 26: ...Table of Contents 26...
Страница 30: ...Section 2 Cautionary Statements 30...
Страница 32: ...Section 3 Initial Inspection 32...
Страница 35: ...Section 4 Quickstart Tutorial 35 Figure 2 Wiring panel...
Страница 55: ...Section 4 Quickstart Tutorial 55 Figure 24 PC200W View data utility...
Страница 78: ...Section 5 System Overview 78...
Страница 80: ...Section 6 CR800 Specifications 80...
Страница 95: ...Section 7 Installation 95 Figure 35 DevConfig OS download window Figure 36 Dialog box confirming OS download...
Страница 104: ...Section 7 Installation 104 Figure 43 Include File settings via DevConfig Figure 44 Include File settings via PakBusGraph...
Страница 267: ...Section 7 Installation 267 Figure 84 Running average signal attenuation...
Страница 268: ...Section 7 Installation 268...
Страница 384: ...Section 8 Operation 384 Figure 113 Using the keyboard display...
Страница 385: ...Section 8 Operation 385 8 8 1 Data Display Figure 114 Displaying data with the keyboard display...
Страница 387: ...Section 8 Operation 387 Figure 116 Real time custom...
Страница 388: ...Section 8 Operation 388 8 8 1 3 Final Storage Tables Figure 117 Final storage tables...
Страница 389: ...Section 8 Operation 389 8 8 2 Run Stop Program Figure 118 Run Stop Program...
Страница 390: ...Section 8 Operation 390 8 8 3 File Display Figure 119 File display...
Страница 396: ...Section 8 Operation 396...
Страница 402: ...Section 9 Maintenance 402...
Страница 450: ...Section 11 Glossary 450...
Страница 504: ...Appendix A CRBasic Programming Instructions 504...
Страница 526: ...Appendix B Status Table and Settings 526...
Страница 530: ...Appendix C Serial Port Pinouts 530...
Страница 536: ...Appendix E FP2 Data Format 536...
Страница 550: ...Appendix F Other Campbell Scientific Products 550...
Страница 564: ...Index 564 WriteIO 464 Writing Program 108 X XML 448 XOR 473 Y Y intercept 141 142 Z Zero 155 166 Zero Basis 151...
Страница 565: ......