Remote code execution (RCE) on the Honeywell C300: Hacking industrial controllers. ๐จ๐ปโ๐ปใฐ๏ธ๐๐ญ๐ฅ
Security researcher Kirill Kutaev shares his research on the Honeywell C300 industrial controller, which is heavily used in critical infrastructure, and explains how to achieve remote code execution (RCE) on such a device.
The author not only analyzed the firmware itself but also examined three network protocols: CDA, EpicMo, and FTB. By combining two specially crafted FTB packets, the researcher caused an integer underflow and a large memory overwrite. From this memory corruption, the researcher achieved RCE.
Very interesting research with many details and technical insights into one of the mission-critical vendors that rarely appear in public papers. Enjoy the presentation.
More details:
Honey Well Done: Aged Vulnerabilities In The Equipment Of A Major Industrial Vendor [Youtube]: https://lnkd.in/d8m9DvXV


