OWASP AppSec DC 2012/Denial of Surface

The Presentation
Are industrial systems airgapped? Some are, some aren't. Unfortunately, enough of them aren't...to suggest bigger questions. Shodan has provided us with over 10,000 proofs of ICS connectivty, and visualization is the key to this story. More importantly, this data was provided to ICS-CERT to help mitigate such exposure. That data was in turn shared globally with other CERTS and CSIRTS, and the lessons are still being learned. It's time to re-examine the fantasy of the airgap, and think of ways to do vulnerability and exposure management in vendor and owner agnostic ways. More importantly, how do you do vulnerability management at a national or international scale? This is not a story of 'I found a couple scary things in SHODAN'. This is a theory of the underlying cause for being able to find THOUSANDS of ICS devices and logins on the open internet. Complete with open source eye-candy!