Open cardosec

Case DF0795 · Famous breaches · L3 Applied

Stuxnet

Practise as: Explain it · Deep dive
  1. 01 What is it?
  2. 02 How is it abused?
  3. 03 How do you stop it?
What a strong answer covers

Try it out loud first. Then check yourself:

  1. Discovered 2010; targeted Siemens S7-315/417 PLCs controlling centrifuges at Iran's Natanz enrichment plant
  2. Crossed the air gap via USB, using 4 Windows zero-days including the LNK flaw CVE-2010-2568
  3. Drivers signed with stolen Realtek and JMicron certificates to look legitimate
  4. Altered centrifuge rotor speeds while replaying normal sensor values to operators
  5. Widely attributed to the US and Israel; first known cyber weapon causing physical damage

If the interviewer pushes back

  • Why is 'air gapped' not a security control on its own? Use Stuxnet to argue it.

cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.