Press Releases

New Metasploit Module to Exploit GE PLC SCADA Devices

New Security Issues Threaten Critical Infrastructure

Miami Beach, FL, and Boston, MA — January 19, 2012

Digital Bond and Rapid7 announced today at the S4 Conference the release of a new Metasploit module to exploit the GE D20 PLC, and a partnership to move additional Project Basecamp PLC exploits to the Metasploit Framework. There are additional GE D20 modules in QA, and plans to move the Basecamp exploits of Rockwell Automation, Schneider Modicon, and Koyo/Direct LOGIC exploits into Metasploit modules. PLCs are the components in SCADA networks that control critical infrastructure, including power plants, pipelines, chemical manufacturing, water treatment, etc.

Dale Peterson, founder of Digital Bond, said, "We felt it was important to provide tools that showed critical infrastructure owners how easy it is for an attacker to take control of their system with potentially catastrophic results. These attacks have existed in theory for a while, but were difficult to demonstrate to a Plant Manager. By creating exploit modules for the most widely used exploit framework - Metasploit - we hope that security professionals in critical infrastructure companies, consultants, and penetration testers will prod vendors to add basic security measures to PLCs after decades of neglect."

A collaboration between the open source community and Rapid7, Metasploit software helps security and IT professionals identify security issues, verify vulnerability mitigations, and manage expert-driven security assessments, providing true security risk intelligence. Metasploit editions - ranging from a free edition to professional enterprise editions - are all based on the Metasploit Framework, an open source software development kit with the world's largest, public collection of quality-assured exploits. The Framework is currently downloaded more than one million times per year and used and enhanced further by over 125,000 security community members.

"The Basecamp modules show the flexibility of the Metasploit Framework," said HD Moore, Metasploit Chief Architect and CSO of Rapid7. "While most Metasploit modules exploit traditional workstations and servers, these modules are exploiting special purpose devices and will even demonstrate the ability to provide interactive control of a critical system, turning things on and off."

Project Basecamp and the resulting tools were presented at Digital Bond's S4 Conference in Miami Beach. A team of six researchers assessed the security of six widely used PLCs in critical infrastructure in front of an audience of leading SCADA security researchers from around the world.

About Digital Bond

Digital Bond is a SCADA and DCS security consulting and research practice that began working on control systems in 2000. Digitalbond.com is the most popular site for SCADA security information and free SCADA security tools. For more information about Digital Bond email info@digitalbond.comor call 954-315-4633.

About Rapid7

Rapid7, Inc. (NASDAQ: RPD) is on a mission to create a safer digital world by making cybersecurity simpler and more accessible. We empower security professionals to manage a modern attack surface through our best-in-class technology, leading-edge research, and broad, strategic expertise. Rapid7’s comprehensive security solutions help more than 11,000 global customers unite cloud risk management and threat detection to reduce attack surfaces and eliminate threats with speed and precision. For more information, visit our website, check out our blog, or follow us on LinkedIn or X.

Rapid7 Press Contact

Alice Randall
Director, Global Corporate Communications
+1 857—216—7804
press@rapid7.com

Rapid7 Investor Contact

Elizabeth Chwalk
Vice President, Investor Relations
+1 617—865—4277
investors@rapid7.com