
Nmap NSE scripts for ICS/SCADA discovery and enumeration—BACnet, EtherNet/IP, CoDeSys, Fox, Modicon, Omron, S7—using protocol queries for security assessments.
#Redpoint
###Digital Bond's ICS Enumeration Tools
Redpoint is a Digital Bond research project to enumerate ICS applications and devices.
We use our Redpoint tools in assessments to discover ICS devices and pull information that would be helpful in secondary testing. A portion of those tools will be made available as Nmap NSE scripts to the public in this repository.
The Redpoint tools use legitimate protocol or application commands to discover and enumerate devices and applications. There is no effort to exploit or crash anything. However many ICS devices and applications are fragile and can crash or respond in an unexpected way to any unexpected traffic so use with care.
Each script is documented below and available in a .nse file in this repository.
BACnet-discover-enumerate.nse - Identify and enumerate BACnet devices
codesys-v2-discover.nse - Identify and enumerate CoDeSys V2 controllers
enip-enumerate.nse - Identify and enumerate EtherNet/IP devices from Rockwell Automation and other vendors
fox-info.nse - Identify and enumerate Niagara Fox devices
modicon-info.nse - Identify and enumerate Schneider Electric Modicon PLCs
omron-info.nse - Identify and enumerate Omron PLCs
pcworx-info.nse - Identify and enumerate PC Worx Protocol enabled PLCs
proconos-info.nse - Identify and enumerate ProConOS enabled PLCs
s7-enumerate.nse - Identify and enumerate Siemens SIMATIC S7 PLCs
==
###BACnet-discover-enumerate.nse
![BACnet-discover-enumerate Sample Output] (http://digibond.wpengine.netdna-cdn.com/wp-content/uploads/2014/03/BACnet-nse.png)
####Authors
Stephen Hilt and Michael Toecker
Digital Bond, Inc
####Purpose and Description
The purpose of BACnet-discover-enumerate.nse is to first identify if an IP connected devices is running BACnet. This works by querying the device with a pre-generated BACnet message. Newer versions of the BACnet protocol will respond with an acknowledgement, older versions will return a BACnet error message. Presence of either the acknowledgement or the error is sufficient to prove a BACnet capable device is at the target IP Address.
Second, if an acknowledgement is received, this script will also attempt to enumerate several BACnet properties on a responsive BACnet device. Again, the device is queried with a pregenerated BACnet message. Successful enumeration uses specially crafted requests, and will not be successful if the BACnet device does not support the property.
BACnet properties queried by this script are:
Vendor ID - A number that corresponds to a registered BACnet Vendor. The script returns the associated vendor name as well.
Vendor Number - A String that represents the Vendor Name that is configured on the device. This can differ from the Vendor ID as the Vendor ID is the Number registered with ASHARE.
Object Identifier - A number that uniquely identifies the device. If the Object-Identifier is known, it is possible to send commands with BACnet client software, including those that change values, programs, schedules, and other operational information on BACnet devices. This is a required property for all BACnet devices.
Firmware Revision - The revision number of the firmware on the BACnet device.
Application Software Revision - The revision number of the software being used for BACnet communication.
Object Name - A user defined string that assigns a name to the BACnet device, commonly entered by technicians on commissioning. This is a required property for all BACnet devices.
Model Name - The model of the BACnet device
Description - A user defined string for describing the device, commonly entered by technicians on commissioning
Location - A user defined string for recording the physical location of the device, commonly entered by technicians on commissioning
Broadcast Distribution Table (BDT) - A list of the BACnet Broadcast Management Devices (BBMD) in the BACnet network. This will identify all of the subnets that are part of the BACnet network.
Foreign Device Table (FDT) - A list of foreign devices registered with the BACnet device. A foreign device is any device that is not on a subnet that is part of the BACnet network, not in the BDT. Foreign devices often are located on external networks and could be an attacker's IP address.
The BDT and FDT can be large lists and may be not desired in a large Nmap scan. The basic script will not pull down the BDT and FDT. Run the command with the --script-args full=yes to pull the BDT and FDT, see the Usage section.
![BACnet-discover-enumerate Sample Output with BDT and FDT] (http://digibond.wpengine.netdna-cdn.com/wp-content/uploads/2014/08/screenshot_bacnet-1.png)
This script uses a feature added in 2004 to the BACnet specification in order to retrieve the Object Identifier of a device with a single request, and without joining the BACnet network as a foreign device. (See ANSI/ASHRAE Addendum a to ANSI/ASHRAE Standard 135-2001 for details)
####History and Background
From Wikipedia article on BACnet http://en.wikipedia.org/wiki/BACnet:
BACnet is a communications protocol for building automation and control networks. It is an ASHRAE, ANSI, and ISO standard[1] protocol. The default port for BACnet traffic is UDP/47808.
BACnet is used in building automation and control systems for applications such as heating, ventilating, and air-conditioning control, lighting control, access control, and fire detection systems and their associated equipment. The BACnet protocol provides mechanisms for computerized building automation devices to exchange information, regardless of the particular building service they perform.
####Installation
This script requires nmap to run. If you do not have Nmap download and Install Nmap based off the Nmap instructions. http://nmap.org/download.html
#####Windows
After downloading bacnet-discover.nse you'll need to move it into the NSE Scripts directory, this will have to be done as an administrator. Go to Start -> Programs -> Accessories, and right click on 'Command Prompt'. Select 'Run as Administrator'.
move BACnet-discover-enumerate.nse C:\Program Files (x86)\Nmap\scripts
#####Linux
After Downloading BACnet-discover-enumerate.nse you'll need to move it into the NSE Scripts directory, this will have to be done as sudo/root.
sudo mv BACnet-discover-enumerate.nse /usr/share/nmap/scripts
####Usage
Inside a Terminal Window/Command Prompt use one of the following commands where host is the target you wish you scan for BACNet. Use --script-args full=yes if you want the output to included the BDT and FDT.
Windows: nmap -sU -p 47808 --script BACnet-discover-enumerate <host>
Windows: nmap -sU -p 47808 --script BACnet-discover-enumerate --script-args full=yes <host>
Linux: sudo nmap -sU -p 47808 --script BACnet-discover-enumerate <host>
Linux: sudo nmap -sU -p 47808 --script BACnet-discover-enumerate --script-args full=yes <host>
To speed up results by not performing DNS lookups during the scan use the -n option, also disable pings to determine if the device is up by doing a -Pn option for full results.
nmap -sU -Pn -p 47808 -n --script BACnet-discover-enumerate <host>
####Notes