Section 8. Operation
437
Note All security features can be subverted through physical access to the
CR3000. If absolute security is a requirement, the physical CR3000 must be kept
in a secure location.
8.7.1 Vulnerabilities
While "security through obscurity" may have provided sufficient protection in the
past, Campbell Scientific dataloggers increasingly are deployed in sensitive
applications. Devising measures to counter malicious attacks, or innocent
tinkering, requires an understanding of where systems can be compromised and
how to counter the potential threat.
Note Older CR3000 operating systems are more vulnerable to attack
than recent updates. Updates can be obtained free of charge at
www.campbellsci.com.
The following bullet points outline vulnerabilities:
•
CR1000KD Keyboard/Display
o
Pressing and holding the Del key while powering up a CR3000 will
cause it to abort loading a program and provides a 120 second
window to begin changing or disabling security codes in the settings
editor (not Status table) with the keyboard display.
o
Keyboard display security bypass does not allow comms access
without first correcting the security code.
•
LoggerNet
o
All datalogger functions and data are easily accessed via RS-232
and Ethernet using Campbell Scientific datalogger support software.
o
Cora command find-logger-security-code
•
Telnet
o
Watch IP traffic in detail. IP traffic can reveal potentially sensitive
information such as FTP login usernames and passwords, and server
connection details including IP addresses and port numbers.
o
Watch serial traffic with other dataloggers and devices. A Modbus
capable power meter is an example.
o
View data in the Public and Status tables.
o
View the datalogger program, which may contain sensitive
intellectual property, security codes, usernames, passwords,
connection information, and detailed or revealing code comments.
Summary of Contents for CR3000 Micrologger
Page 2: ......
Page 3: ......
Page 4: ......
Page 6: ......
Page 30: ......
Page 34: ......
Page 36: ......
Page 96: ......
Page 485: ...Section 8 Operation 485 8 11 2 Data Display FIGURE 110 Keyboard and Display Displaying Data ...
Page 487: ...Section 8 Operation 487 FIGURE 112 CR1000KD Real Time Custom ...
Page 491: ...Section 8 Operation 491 FIGURE 116 Keyboard and Display File Edit ...
Page 496: ......
Page 502: ......
Page 564: ...Section 11 Glossary 564 FIGURE 126 Relationships of Accuracy Precision and Resolution ...
Page 566: ......
Page 594: ......
Page 598: ......
Page 600: ......
Page 602: ......
Page 624: ......
Page 642: ......
Page 643: ......