Industrial protocols (Modbus)
Industrial protocols (Modbus, DNP3, S7, EtherNet/IP, Profinet) were designed decades ago for isolated, trusted networks: most have no authentication or encryption. Understanding this explains why access to the OT network is so critical: whoever reaches the network can often read and write the process directly.
The underlying problem
Section titled “The underlying problem”- designed for ISOLATED, trusted networks -> no auth, no encryption, no integrity- anyone with network access can read values and SEND commands to a PLC- "security" was physical isolation (air gap), today eroded by IT/OT convergenceModbus (the most common)
Section titled “Modbus (the most common)”Modbus TCP port 502; function codes to read/write registers and coils FC 01/02 read coils / discrete inputs FC 03/04 read holding / input registers FC 05/06 write a coil / register (a command to the process!) FC 15/16 write multiple# no authentication: a write FC from the network changes the physical stateOther protocols
Section titled “Other protocols”DNP3 utilities (energy/water); with optional Secure Authentication (rarely deployed)S7comm Siemens S7 PLCs (Stuxnet abused it)EtherNet/IP CIP (Rockwell/Allen-Bradley), port 44818Profinet automation (Siemens)BACnet/Modbus buildings (BMS)# nmap NSE and specific scripts enumerate versions/registers -> ONLY in a labEnumeration and risks (authorized lab)
Section titled “Enumeration and risks (authorized lab)”- discover devices and supported function codes (passive tools preferred)- reading registers reveals the process state; writing MANIPULATES it- an aggressive active scan can HANG a fragile PLC -> prefer passive capture- Shodan/Censys show thousands of ICS devices exposed on the Internet (don't touch)Enumeration nmap (modbus/s7/enip scripts), modbus-cli, pymodbus (prototype)Analysis Wireshark (Modbus/DNP3/S7 dissectors), passive captureMonitoring Nozomi/Claroty/Dragos (per protocol, without touching the device)Blue Team / defense
Section titled “Blue Team / defense”- Since the protocols don’t authenticate, the defense is network-based: Purdue segmentation and controlling who talks to the PLCs (SCADA / ICS).
- Allowlisting of authorized peers (only the HMI/historian talks to the PLC), not anyone.
- Passive monitoring alerting on unexpected write function codes or new peers.
- Where available, enable the secure variants (DNP3-SA, OPC UA with security); never expose :502 to the Internet.
CVEs and real-world cases
Section titled “CVEs and real-world cases”- Stuxnet manipulated S7comm to reprogram PLCs without the HMI noticing.
- Thousands of Modbus/BACnet devices exposed on the Internet (Shodan) with no authentication.
- Industroyer speaks electric protocols (IEC 60870-5-104, IEC 61850) to operate breakers.
Testing checklist
Section titled “Testing checklist”- Identify protocols in use (Modbus/DNP3/S7/EtherNet-IP)
- Passive capture to map peers and function codes (avoid active scanning in prod)
- Verify no ICS ports (502, 44818…) exposed to the Internet
- Allowlisting: only authorized peers talk to the PLCs
- Passive monitoring of unexpected writes/commands
- Enable secure protocol variants where they exist
- Tests only in a lab/authorized window