No Copy


No Right Click

Selamat Datang di Situs Belajar PLC dan SCADA

Blog gratis yang menyajikan berita seputar PLC dan SCADA.

Microsoft Windows 10

Berita seputar Microsoft Windows 10. Membahas berbagai informasi mengenai Microsoft windows terbaru.

Apple OSX

Artikel yang membahas tentang OSX terbaru dari Apple tentu sangat menarik untuk dibaca. Tak kalah serunya jika kita paham mengenai tips dan trik yang ada didalamnya.

Photography

Photography asik dan menarik jika kita mengetahuinya lebih dalam. Disini kita bisa melihat berbagai hal dari sudut pandang photo. Menarik untuk dipahami.

Saturday, December 3, 2011

EtherNet /IP to DeviceNet link

Rockwell Automation has launched The EtherNet/IP Communications Auxiliary. A new EtherNet/IP-to-DeviceNet link module has been introduced by Rockwell to allow products that sit on a DeviceNet network to easily communicate with EtherNet/IP-based scanners.

The EtherNet/IP Communications Auxiliary allows up to six DeviceNet-based units to be scanned via Implicit Messaging and can bridge explicit messaging for all nodes on a DeviceNet network. The EtherNet/IP Communications Auxiliary uses an internal web server to configure the module, the DeviceNet network and DeviceNet-connected units that fully support the Parameter Object.

The EtherNet/IP Communications Auxiliary is available as a single Ethernet port or dual Ethernet port module with RJ-45 ports to connect to Ethernet cable, meeting CAT5 or above. Rockwell Automation offers a wide variety of Allen-Bradley Ethernet patch cables with its Bulletin 1585 line of Ethernet cables.

The dual-port 193-DNENCATR Module also supports a Ring Ethernet topology in which all Ethernet nodes are wired in series with one another. It can be used in the Rockwell Automation’s Device Level Ring (DLR) as a slave device in which the EtherNet/IP network will still continue to communicate, even in the event that one of the network lines is disrupted.
Commenting at the UK launch of the product, Steve Pethick, Rockwell Automation director of components for EMEA, said: “Many of our customers, particularly in the food processing sector and in the water industry, have asked for a way to add field devices into their Integrated Architecture solution using EtherNet/IP. This device helps them to do just that; simply, quickly and cost effectively.”

Both devices support a Star Ethernet topology in which all Ethernet nodes wire back to a central Ethernet switch, hub, or router. Rockwell Automation also offers a line of managed and unmanaged Allen-Bradley Ethernet Switches with its Stratix range.

Wonderware InTouch HMI v10.1 Download

I found this links from other website, If you interesting for learn you can download it.

InTouch software provides graphic visualization which takes your operations management, control and optimization to a whole new level.  The InTouch HMI reputation stands above all the rest.  What the industry now knows as Human Machine Interface (HMI) all began with InTouch software over twenty years ago.  No other HMI can match InTouch software for industry leading innovation, architectural integrity, unequaled device integration and connectivity, uninterrupted software version migration path, and truly legendary ease of use.

All this leads to well designed standards-driven systems that maximize productivity, optimize user effectiveness, increase quality, and lower development, maintenance, and operational costs helping to make your company the best it can be.

Key Benefits
* Truly legendary ease-of-use enabling developers and operators to quickly and easily be more productive
* Unequaled device integration and connectivity to virtually every device and system
* Stunning graphic visual representation and interaction with your operation brings the right information to the right people at the right time
* History of uninterrupted software version migration path that means your HMI applications investment is protected

Key Capabilities
* Resolution independent graphics and intelligent symbols that visually bring your facility to life right on your computer screen
* Sophisticated scripting to extend and customize applications for your specific needs
* Real-time distributed Alarming with historical views for analysis
* Built-in, real-time and historical trending
* Microsoft ActiveX controls and .NET controls integration
* Extensible library of over 500 pre-designed ‘intelligent’ and customizable graphic and object symbols

HomePage: http://global.wonderware.com/EN/Pages/WonderwareInTouchHMI.aspx

Download Links: http://vndownload.org/full-software/wonderware-intouch-v10-1.html

How can the program runtime be optimized if the main memory of the CPU is too small for the runtime-relevant STEP 7 program?"

Instructions
The sections of the S7 user program relevant to the runtime are in the main memory of the CPU. These are essentially the program code and the user data. The CPU's load memory contains the complete user program including the module configuration and module parameters. The next table contains information on the topics listed below:
  • Configuring data blocks with the "Unlinked" attribute
  • Influence of the operand area on the memory requirements
  • Different load memory usage for two data blocks of the same size
  • Variable declaration in data blocks
No. Information about optimizing program sequences
1 Configuring data blocks with the "Unlinked" attribute
Since the main memory has only a limited size, for recipe management, for example, multiple data blocks can be different recipe values can only be stored in the load memory. Then, in the main memory is only a working DB that contains the current recipe.
Fig. 01
If DBs are configured with the "Unlinked" property and loaded into the CPU, then those data blocks are only available in the CPU's load memory and hence do not take up any space in the main memory. Using this method it is possible to save space in the CPU's main memory. The contents of these data blocks can only be transferred into the main memory with system functions SFC20 "BLKMOV" or SFC83 "READ_DBL". However, if you try to load the data of of these data blocks into Accu 1 with a load command, the CPU goes into STOP.

Fig. 02
Open "Object Properties" of the data block and activate the "Unlinked" attribute in the "General - Part 2" tab (Fig. 2). After the data block has been loaded into the CPU, the data block is only stored in the load memory.

Fig. 03
Using system function SFC20 you can copy the data from the load memory into the main memory (as in Fig. 03) and subsequently load it into Accu 1 using "L DB20.DBW 0", for example.
NoteIn the STL sources, this property is allocated to a data block with the key word Unlinked (between "DATA_BLOCK DB “ and the STRUCT definition of the data block).
2 Influence of the operand area on the memory requirements
The operand area has a minor influence on the memory requirements when programming:
  • With inputs and outputs the limit lies between addresses 127.7 and 128.0.
  • The limit with markers, on the other hand, lies between addresses 255.7 and 256.0.
To explain the behavior the two statements below are programmed in a function.
The statement:
U M256.0
= M0.0
requires 6 bytes in the main memory.
If you use the same statement with a smaller marker address, for example,
U M255.0
= M0.0
then only 4 bytes of main memory are required.
The empty function alone requires 38 bytes. Hence, in the main memory, the complete FC requires 38 bytes + number of bytes for the written statement.
3 Different load memory usage for two data blocks of the same size
A data block with 16 variables of the Boolean data type requires more load memory than a data block with a variable of the Word data type. One byte is required in a data block for each variable name and for each data type. This means:
  • DB with 16 variables of the Boolean data type:
    16 x 2 bytes (for name and data type) = 32 bytes
  • DB with 1 variable of the Word data type:
    1 x 2 bytes (for name and data type) = 2 bytes
4 Variable declaration in data blocks
The size of a data block is normally limited by the maximum available block size of the CPU used (for example, 64 KB with an S7-400 or 8 KB or 6 KB with an S7-300). There is yet another system limit in STEP 7 for the number of declarations in a data block. If you declare more than 32000 variables, an error message is displayed: "Declaration too long". The reason for this message is that 2 bytes per declaration are occupied in the internal 64-KB buffer (as described in point 3).
Remedy
Instead of programming the data block with numerous single variables, we recommend using arrays or multiple smaller data blocks. In addition, smaller data blocks can be opened and saved much more quickly in the editor.
Creation environment
The figures in this FAQ were created with STEP 7 V5.5.
Keywords
Integrated RAM, Memory Card, EPROM.

What settings have to be made for a PROFIBUS DP connection between a panel or a PC with WinCC flexible Runtime and an S7-200?

If you want to connect a WinCC flexible operator panel to an S7-200, make sure that the S7-200 can only be operated as DP slave.
The panel or PC must be implemented as DP master on the PROFIBUS DP network and the S7-200 as DP slave.
The following settings must therefore be made in the WinCC flexible configuration:
  • In WinCC flexible you configure a controller connection to the S7-200 via
    Project > Communication > Connections.

Fig. 1: Select controller protocol
  • To be able to set up communication between the S7-200 as DP slave and the PC as DP master, you must set a check mark to enable "Only master on the bus". 

Fig. 2: Only master on the bus
Example:  Five PCs with WinCC flexible Runtime and PROFIBUS DP communicate with an S7-200. One PC is the DP master, i.e. the check mark for "Only master on the bus" is set only for this PC. There is no check mark for "Only master on the bus" set for the other PCs.

Now, if the master PC fails, all communication on the PROFIBUS DP network is interrupted, because there is then no other master available on the bus. As soon as the master PC comes back online (WinCC flexible Runtime is started and the controller connection is enabled), the other PC stations can set up a connection again to the S7-200. 
Recommendation:
Declare all the PCs to be master by setting a check mark for "Only master on the bus" for all of them, because then communication does not depend on just one PC.

The other settings for the PROFIBUS DP connection are to be entered accordingly.

Fig. 3: Other settings
Note: 
On a PC the PG/PC interface must be set as "S7ONLINE --> PROFIBUS".

Fig. 4: PG/PC interface
STEP 7 - Micro/WIN
With STEP 7-Micro/WIN the interface of the the S7-200 must be configured according to the parameters used in WinCC flexible.
Notes:
  • For a PROFIBUS DP communication at a baud rate > 187.5 kbaud you need a DP interface on the S7-200.
  • For the S7-22x without integrated DP interface you need an EM277 module for the PROFIBUS DP communication (baud rate > 187.5 kbaud).
  • More information on OP communication with S7-200 is available in "S7-200 and HMI Components" in Entry ID: 14188898.

How can you increase the performance of Siemens HMI devices?

Description
Through continual innovation the performance of controllers has increased by five to ten fold in the past three years. The cycle times of the controllers became increasingly shorter. The cycle times of the S7-300 controllers, for example, now frequently lie between 9ms and 16ms.
The time left for the CPU to communicate with the HMI devices is therefore becoming ever shorter, because only a certain percentage of the total cycle time is available for communication. The percentage of the time the CPU uses for communication is a minimum of about 3.5% of a cycle time of 15ms.
The FC630 function is for improving the performance of HMI services. An SFC is called in the FC630, which increases the time assignment for the HMI services according to the value of the parameter TSx:
  • TSx = 0: restores the initial status
  • TSx = 1: default setting
  • TSx = 8: increases the CPU cycle time by approx. 50%
The TSx value increases the CPU cycle time by 6.25% per unit.
Evaluation of RET_VAL:
  • 0000: no error, time factor is valid and accepted.
  • 800x: error, the block must be restarted.
The valid factor is effective without any further modification until the power is switched off.
The "HMI" taskThe CPU program is executed in different tasks ("subprograms"). In the "HMI" task, the CPU communication with the HMI devices is controlled by the operating system (data acquisition, data processing, data transfer and data fetching). The "HMI" task has a certain portion of the cycle time allotted to it. If this time expires, the "HMI" task is interrupted and the CPU continues with its cyclic program processing. The "HMI" task can be interrupted by higher-priority tasks. Higher-priority tasks include time interrupts and delay interrupts, for example.
NoteThe FC630 cannot be used in S7-400 CPUs because there is not the requisite firmware support. Furthermore, HMI response times cannot be shortened because the "HMI" task already has the second highest priority in the S7-400 CPUs.
Difference between FC630 and the setting in the CPU properties (cycle load through communication)In the CPU properties there is also the "Cycle load through communication" parameter. This parameter only affects the CPU message traffic. The FC630 comes into effect early on at data acquisition and in processing the data, which is why the S7-300 CPU's cycle time can greatly extend itself if the FC630 is not handled properly.
Bus protocols for which you can use the FC630You can use the FC630 for communication via
  • MPI
  • PROFIBUS
  • PROFINET
Requirements before using FC630Since incorrect use of the FC630 can lead to malfunctions, in particular the CPU cycle time might increase enormously, you should check the following before using the FC630.
  • How high are the cycle times of your CPU? It is particularly useful to operate with cycle times of between 9ms and 16ms, because the percentage of the time used for communication is a minimum of about 3.5% of a cycle time of 15ms. The percentage of the time used for communication with a cycle time of about 32ms is again a minimum of approx. 4.8%. This is why it is useful to implement the FC630 also with cycle times of between 25ms and 32ms. It is not generally useful to implement the FC630 for cycle times greater than 50ms. However, whether or not it is useful to implement the FC630 always depends on your system (number of HMI devices, number of tags polled ...).
Note Via STEP 7 under "PLC > Diagnostics/Setting > Module status > Cycle time" you can read out of your module the longest, shortest and current cycle time since transition from STOP to RUN.
Via the local data of the OB1 you can also read out the runtime of the previous cycle, the minimum cycle time since the last start and the maximum cycle time since the last start.
  • Are there time critical subprocesses in the system that do not permit an increase in cycle time? If this is the case, you can also check whether the time critical subprocesses could be controlled via a cyclic interrupt. You should note here that cyclic interrupts interrupt the "HMI" task when called and thus influence HMI performance.
You can implement the FC630 function with S7-300 CPUs and C7 devices. Whether the FC630 can be implemented depends on the CPU type and the firmware version. The function described is valid for the CPU-31x modules as from firmware versions V2.3.2, V2.1.6 and V2.0.10.
The FC630 can also be used for the CPU319-3 PN/DP modules as from firmware version V3.2. However, the firmware version V3.2 contains an improved HMI Turbo that only works for the acyclic HMI services.
  • This does not speed up the cyclic HMI services, so the FC630 continues to be need to improve performance.
  • The new function - "Prioritized OCM communication" - has been introduced in all devices as from firmware version V3.2, but it can only be configured in the CPU315F-2 PN/DP modules onwards.
  • The HMI Turbo is only hidden for the modules CPU312 to 315-2DP and can be configured with the new function FC2551.
More information about "Prioritized OCM communication" is available in Entry ID: 49749632.
The attached download contains an archived sample STEP 7 project with the FC630 described above. Use of the FC630 is described in detail in the document below.
Description_Performance_FC630 ( 93 KB )
Performance_FC630.zip ( 30 KB )
Keywords WinCC, ProTool, Panel, HMI, Operate, Monitor, Performance

Which ports are used by WinCC flexible?

Configuration Notes:The Ethernet ports are assigned by the IANA (Internet Assigned Numbers Authority). When using a firewall you must enable all the ports specified in the table. All the services listed are handled via the TCP/IP protocol, except archiving via UDP.
The following ports are used in WinCC flexible Runtime:
 
  Service Port
Web server Access to internal HTML pages (HTTP) 80
Access to internal HTML pages (HTTPS) 443 (SSL)
Sm@rtServer Connection with the Sm@rtServer
(access to the Sm@rtServer for downloading the Java applets with the Internet Explorer)
5800
Connection with the Sm@rtServer (access to the Sm@rtServer with Internet Explorer for remote monitoring and operation) 5900
OPC
OPC via DCOM
Server Connection setup: 135
Communication dynamic 1)
Client Communication dynamic 1)
OPC via XML  (Client <=> Server) 80
Printing Printing of Windows CE panels via Ethernet 1032
Archiving Archiving on a server 2) UDP 137, 138
TCP 139
Miscellaneous Transfer via Ethernet Configuration PC dynamic 1)
Panel 2308 and 50523
Communication between S7 controller 102
Panel dynamic 1)
PROFINET IO communication 3) 34964
E-mail (SMTP server) 25
Modicon controller (Modicon channel MODBUS TCP/IP) 502
1) Dynamic port:
The Microsoft Windows operating system automatically assigns the relevant service a free port that can be between Port 1024 and 65534. You must enable this area when using a firewall.
2) Archiving:
Requirement for archiving via an Ethernet network is that the server is enabled.
3) PROFINET
Communication via PROFINET must be activated in the "Control Panel", in the "PROFINET" Settings dialog.
Note:If you change the ports of the Sm@rtServer, you must change the links accordingly in the HTML pages used. More information on changing HTML pages is available in the Help system of WinCC flexible under "Example: Configuring an integrated web server".

How do you integrate a WinCC flexible project in STEP 7?

DescriptionThe following points are described below:
  1. Integration of a WinCC flexible project in STEP 7.
  2. Possible causes of error when it is not possible to integrate a WinCC flexible project in STEP 7.
Instructions
 
No. Integration of a WinCC flexible project in STEP 7
1 Proceed as follows to integrate a WinCC flexible project in STEP 7.
  1. Open the WinCC flexible configuration.
  2. Select the menu command "Project > Integrate in STEP 7...".
    The "Integrate in STEP 7 projects" dialog opens.
  3. Select the relevant STEP 7 project in the dialog box.
    If the project you desire is not listed, navigate via the search field to the folder in which the STEP 7 project is located.
    Integration is executed once you select the STEP 7 project.

Fig. 01
Note
The STEP 7 project does not have to be open for this.
2 Parameterization of the connection / communication partnerIn the "Stand alone" mode you have set all the connection parameters to the controller manually.
In the "Integration" mode you can define the station via which the communication partner is to be addressed using the selection menu. The addresses are then transferred automatically.
Furthermore, using this measure with the tags, you can access the symbolic connection.
  1. Open the STEP 7 project in which you previously integrated the WinCC flexible project.
  2. Mark the HMI station and double-click to open the "Configuration" of the HMI station.
  3. Open the "Properties" of the operator panel's interface and define the interface and address.

Fig. 02
  1. Switch to the WinCC flexible configuration and open the "Connections" in the project tree via "Communication > Connections".
  2. Select the relevant station under the "Station".
    The "Partner" and all the other parameters are transferred automatically.
This completes integration of the WinCC flexible project.
Possible causes of error when it is not possible to integrate a WinCC flexible project in STEP 7.
If the function for integrating the WinCC flexible project is grayed out or not available, this might be due to the following reasons.
  • You must install WinCC flexible Integration, because WinCC flexible was installed before STEP 7.

    Instructions
  1. Via the Control Panel you call the WinCC flexible Setup and change the installation.
    Control Panel/Software/SIMATIC WinCC flexible  Button: Change/Delete
  2. Activate the integration of STEP 7.
    The "WinCC flexible Integration" and "STEP 7" check boxes must be checked.
    (You need the WinCC flexible installation CD for this.)
Note
If you install the STEP 7 software before installing WinCC flexible, the WinCC installation routine recognizes the installation of STEP 7 and automatically installs support for integration in STEP 7.
If making a custom installation of WinCC flexible, make sure to activate the option "Integration in STEP 7".
  • If STEP 7 is already installed and you make an update for STEP 7, e.g. by installing a Service Pack, then you have to reinstall STEP 7 Integration in WinCC flexible.

    Instructions
  1. Via the Control Panel you call the WinCC flexible Setup and change the installation.
  2. Deactivate the integration of STEP 7.
  3. Then restart the Setup and activate the integration of STEP 7.
    (You need the WinCC flexible installation CD for this.)
You cannot integrate Micro Panels, e.g. a TP177micro, into STEP 7.

How do you configure an S7-300 CPU as DP slave to a CP 342-5 as DP master?

Description
This entry explains the configuration of an S7-300 CPU as DP slave to a CP 342-5 as DP master as well as the programming of data exchange between DP master and DP slave.
Proceed as follows to configure an S7-300 CPU as DP slave to a CP 342-5 as DP master and program data exchange between DP master and DP slave.
6518938_configuration_en.pdf ( 1267 KB )
Download The STEP 7 project contains a sample program for calling FC1 "DP_SEND" and FC2 "DP_RECV" in the user program of the DP master. The load and transfer commands are used for data transfer in the user program of the DP slave. The load and transfer commands support consistent transfer of a maximum of 4 bytes.
non_consistent.zip ( 635 KB )
The STEP 7 project contains a sample program for calling FC1 "DP_SEND" and FC2 "DP_RECV" in the user program of the DP master and a sample program for calling system functions SFC14 "DPRD_DAT" and SFC15 "DP_WR_DAT" in the DP slave. You use these system functions for transferring more than 4 bytes consistently.
consistent.zip ( 636 KB )
KeywordsConsistent data transfer, Master-slave communication

Update for SIMATIC PDM V6.0 to V6.0 + SP5

Service Pack 5 (SP5) is now available for SIMATIC PDM V6.0 (see entry ID 35125626). New shipments of SIMATIC PDM V6.0 already include the SP5. At the end of this bulletin you can separately download the complete SIMATIC PDM V6.0 + SP5 software (CD1) and the current Device Library 01/2009 (CD2). This enables you to upgrade existing installations of SIMATIC PDM V6.0, V6.0 + SP1, V6.0 + SP2, V6.0 + SP3 or V6.0 + SP4 to V6.0 + SP5 free of charge. Alternatively you can also purchase the current SIMATIC PDM Demo V6.0 demonstration software with integrated SP5, order no. 6ES7 658-3GX06-0YC8, and use that to upgrade your SIMATIC PDM installations.

Download software
The download software for upgrading to SIMATIC PDM V6.0 + SP5 consists of two separate files:
  • CD 1: SIMATIC PDM V6.0 + SP5 software
              PDMV605_CD1.zip ( 264036 KB )
  • CD 2: current Device Library 01/2009
             PDMV605_CD2.zip ( 554082 KB )
Your previously purchased licenses remain valid. If you should require additional optional packages for which you have no license as yet, please order them from your SIMATIC contact at your local Siemens office.
Download:
Please note:
  • The size of the PDMV605_CD1.zip file is approx. 265 MByte.
  • The size of the PDMV605_CD2.zip file is approx. 555 MByte.
  • The time for downloading depends on the speed of your Internet connection.
  • Downloading usually takes more than 10 minutes.

Virus inside S7-PLC, Step7, WinCC. DB 890 and DB 8062

http://www.langner.com/en/index.htm
Stuxnet logbook, Sep 16 2010, 1200 hours MESZ

With the forensics we now have it is evident and provable that Stuxnet is a directed sabotage attack involving heavy insider knowledge. Here is what everybody needs to know right now.

Fact: As we have published earlier, Stuxnet is fingerprinting its target by checking data block 890. This occurs periodically every five seconds out of the WinCC environment. Based on the conditional check in code that you can see above, information in DB 890 is manipulated by Stuxnet.

Interpretation: We assume that DB 890 is part of the original attacked application. We assume that the second DWORD of 890 points to a process variable. We assume that this process variable belongs to a slow running process because it is checked by Stuxnet only every five seconds.

Fact: Another fingerprint is DB 8062. Check for the presence of DB 8062 in your project.

Fact: Stuxnet intercepts code from Simatic Manager that is loaded to the PLC. Based on a conditional check, original code for OB 35 is manipulated during the transmission. If the condition matches, Stuxnet injects Step7 code into OB 35 that is executed on the PLC every time that OB 35 is called. OB 35 is the 100 ms timer in the S7 operating environment. The Step7 code that Stuxnet injects calls FC 1874. Depending on the return code of FC 1874, original code is either called or skipped. The return code for this condition is DEADF007 (see code snipplet).

The known variations of the malware are specifically directed at Siemens WinCC and PCS7 Products.
Over the weekend of July 17-18, news broke on the “Computerworld” technology Web site about a virus attacking industrial automation giant Siemens’ WinCC and PCS7 industrial control human-machine interface/supervisory control and data acquisition (HMI/SCADA) systems.
The virus exploited Microsoft Windows operating systems when Universal Serial Bus (USB) memory sticks are inserted in a host computer and automatically loaded.

In response to a query from Automation World, Siemens Industry Inc. (http://www.usa.siemens.com/industry) spokesperson Michael Krampe issued the following statement:

"Siemens was notified about the virus that is affecting its Simatic WinCC SCADA (Supervisory Control and Data Acquisition) systems on July 14. The company immediately assembled a team of experts to evaluate the situation. Siemens is taking all precautions to alert its customers to the potential risks of this virus.

"Siemens is reaching out to its sales team and will also speak directly to its customers to explain the circumstances. We are urging customers to carry out an active check of their computer systems with WinCC installations and use updated versions of antivirus software in addition to remaining vigilant about IT security in their production environments."

Well-known industrial cyber-security expert Eric Byres and his team conducted a weekend analysis, and Byres has issued a statement and is offering a White Paper analysis. Here is his analysis:

“Over the weekend my team has been investigating a new family of threats called Stuxnet that appear to be directed specifically at Siemens WinCC and PCS7 products via a previously unknown Windows vulnerability. At the same time I also became aware of a concerted Denial of Service attack against a number of the SCADA information networks such as SCADASEC and ScadaPerspective mailing lists, knocking at least one of these services off line.

“As best as I can determine, the facts are as follows:
• This is a zero-day exploit against all versions of Windows including Windows XP SP3, Windows Server 2003 SP 2, Windows Vista SP1 and SP2, Windows Server 2008 and Windows 7.
• There are no patches available from Microsoft at this time (There are work arounds which I will describe later).
• This malware is in the wild and probably has been for the past month.
• The known variations of the malware are specifically directed at Siemens WinCC and PCS7 Products and hardware PLC S7-315 and S7-417.
• The malware is propagated via USB key. It may be also be propagated via network shares from other infected computers.
• Disabling AutoRun DOES NOT HELP! Simply viewing an infected USB using Windows Explorer will infect your computer.
• The objective of the malware appears to be industrial espionage and sabotage; i.e. to steal intellectual property from SCADA and process control systems. Specifically, the malware uses the Siemens default password of the MSSQL account WinCCConnect to log into the PCS7/WinCC database and extract process data and possibly HMI screens.
• The malware is infected PLC S7-315 and S7-417 via modified S7 DLLs.

• The only known work arounds are:
• NOT installing any USB keys into any Windows systems, regardless of the OS patch level or whether AutoRun has been disabled or not
• Disable the displaying of icons for shortcuts (this involves editing the registry)
• Disable the WebClient service

“My team has attempted to extract and summarize all the relevant data (as of late Saturday night) and assemble it in a short white paper called “Analysis of Siemens WinCC/PCS7 Malware Attacks” which I have posted on my website in a secured area that can be accessed from http://www.tofinosecurity.com/professio ... cc-malware .

“If you would like to download the white paper, you will need to register on the web site and I will approve your registration as fast as I can. I have chosen to keep the whitepaper in a secure area as I do not want this information to be propagated to individuals that do not need to know and might not have our industries’ best interests at heart. People who are already http://www.tofinosecurity.com web members do not need to reregister.”

ttp://www.eset.com/press-center/article/eset-analysis-worm-win32stuxnet-targets-supervisory-systems-in-the-us-and-iran/7609
ESET Analysis: Worm Win32/Stuxnet Targets Supervisory Systems in the U.S. and Iran
#