Threat Level: green Handler on Duty: Didier Stevens

SANS ISC: SCADA hacks published on Pastebin - SANS Internet Storm Center SANS ISC InfoSec Forums

Watch ISC TV. Great for NOCs, SOCs and Living Rooms:

Sign Up for Free!   Forgot Password?
Log In or Sign Up for Free!
SCADA hacks published on Pastebin has become a simple platform to publish evidence of various attacks. Lenny a few months back already noted that it may be useful for organizations to occasionally search pastebin for data leakage. Recently, an individual using the alias of pr0f published evidence of attacking the South Houston water system.

This made me look for other "pastes" by pr0f. What I found:

More Simatic HTML (not clear were it comes from)

A Vacuum gauge configuration file from Caltech

A control system from Looks like power generation to me, but may be an experiment, not production

Another paste, showing the (pretty good) password for a spanish water utility has since been removed. 


Johannes B. Ullrich, Ph.D.
SANS Technology Institute


I will be teaching next: Application Security: Securing Web Apps, APIs, and Microservices - SANS London June 2022


4479 Posts
ISC Handler
Nov 23rd 2011
do you meant this one?
This is scary news... just imagine the damage that could be done with this info.

12 Posts

Sign Up for Free or Log In to start participating in the conversation!