admin 发表于 2022-11-26 20:29:11

转载ATTACKING PLCS BY PLC IN DEEP

<p style="margin-top:0cm;margin-right:0cm;margin-bottom:15.0pt;margin-left:0cm;background:white;vertical-align:baseline;">
        <span style="color:#777777;font-size:10.5pt;">在<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">Black Hat 2016<span style="color:#777777;font-size:10.5pt;">,<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">Ralf Spenneberg<span style="color:#777777;font-size:10.5pt;">等人在他们的报告《<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">PLC-Blaster: A Worm Living Solely in the PLC<span style="color:#777777;font-size:10.5pt;">》中介绍了一种不依赖于计算机,只通过西门子<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">PLC<span style="color:#777777;font-size:10.5pt;">设备来进行传播和感染的工控蠕虫病毒。该病毒可以通过一台被感染的<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">PLC<span style="color:#777777;font-size:10.5pt;">来接入整个系统,接下来会通过复制传播到更多的<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">PLC<span style="color:#777777;font-size:10.5pt;">中,并且能在不影响已存在的<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">PLC<span style="color:#777777;font-size:10.5pt;">程序的前提下被执行。<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">2018<span style="color:#777777;font-size:10.5pt;">年在瑞典斯德哥尔摩举行的<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">CS3<span style="color:#777777;font-size:10.5pt;">工控安全会议中,绿盟科技格物实验室团队在参考<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">PLC-Blaster<span style="color:#777777;font-size:10.5pt;">的基础上,演示了使用一台<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">PLC<span style="color:#777777;font-size:10.5pt;">攻击其他不同厂家<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">PLC<span style="color:#777777;font-size:10.5pt;">的方法。<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;"></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span>
</p>
<h2 style="margin:0cm;background:white;vertical-align:baseline;font-weight:inherit;outline:0px;transition:all 0.3s ease 0s;font-variant-ligatures:normal;font-variant-caps:normal;orphans:2;text-align:start;widows:2;-webkit-text-stroke-width:0px;text-decoration-style:initial;text-decoration-color:initial;word-spacing:0px;">
        <span style="font-style:inherit;font-weight:inherit;outline:0px;" id="PLC%E7%AE%80%E4%BB%8B"><span lang="EN-US" style="font-family:&quot;color:#1E1E1E;"><span style="font-style:inherit;font-weight:inherit;outline:0px;" id="more-13877">PLC<span style="color:#1E1E1E;">简介<span lang="EN-US" style="font-family:&quot;color:#1E1E1E;"><span style="font-style:inherit;font-weight:inherit;outline:0px;"></span></span></span></span></span></span>
</h2>
<p style="margin:0cm;background:white;vertical-align:baseline;outline:0px;font-variant-ligatures:normal;font-variant-caps:normal;orphans:2;text-align:start;widows:2;-webkit-text-stroke-width:0px;text-decoration-style:initial;text-decoration-color:initial;word-spacing:0px;">
        <span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">PLC<span style="color:#777777;font-size:10.5pt;">全称为<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">Programmable<span lang="EN-US" style="color:#777777;font-family:Cambria,serif;font-size:10.5pt;">&nbsp;<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">Logic<span lang="EN-US" style="color:#777777;font-family:Cambria,serif;font-size:10.5pt;">&nbsp;<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">Controller<span style="color:#777777;font-size:10.5pt;">,即可编程逻辑控制器,是一种采用一类可编程的<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;"><a href="http://baike.baidu.com/view/87697.htm" style="font-style:inherit;font-weight:inherit;outline:none 0px;cursor:pointer;transition:all 0.3s ease 0s;"><span lang="EN-US" style="border:none windowtext 1.0pt;color:#1EAAF1;font-family:宋体;padding:0cm;text-decoration:none;text-underline:none;"><span lang="EN-US">存储器</span></span></a><span style="color:#777777;font-size:10.5pt;">,用于其内部存储程序,执行逻辑运算、顺序控制、定时、计数与算术操作等面向用户的指令,并通过数字或模拟式输入<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">/<span style="color:#777777;font-size:10.5pt;">输出控制各种类型的机械或生产过程。西门子、施耐德、罗克韦尔这三个厂家的<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">PLC<span style="color:#777777;font-size:10.5pt;">目前在市场占有率中处于领先。本文使用西门子<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">S7-300 PLC<span style="color:#777777;font-size:10.5pt;">、<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">S7-1200 PLC<span style="color:#777777;font-size:10.5pt;">,施耐德<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">Pentium 140 PLC<span style="color:#777777;font-size:10.5pt;">以及罗克韦尔<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">Micrologix 1400 PLC<span style="color:#777777;font-size:10.5pt;">为例进行介绍。<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;"></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span>
</p>
<h2 style="margin:0cm;background:white;vertical-align:baseline;font-weight:inherit;outline:0px;transition:all 0.3s ease 0s;font-variant-ligatures:normal;font-variant-caps:normal;orphans:2;text-align:start;widows:2;-webkit-text-stroke-width:0px;text-decoration-style:initial;text-decoration-color:initial;word-spacing:0px;">
        <span style="font-style:inherit;font-weight:inherit;outline:0px;" id="Replay_Attack"><span lang="EN-US" style="font-family:&quot;color:#1E1E1E;">Replay Attack</span></span>
</h2>
<p style="margin-top:0cm;margin-right:0cm;margin-bottom:15.0pt;margin-left:0cm;background:white;vertical-align:baseline;outline:0px;font-variant-ligatures:normal;font-variant-caps:normal;orphans:2;text-align:start;widows:2;-webkit-text-stroke-width:0px;text-decoration-style:initial;text-decoration-color:initial;word-spacing:0px;">
        <span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">Replay Attack<span style="color:#777777;font-size:10.5pt;">常用于如<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">PLC<span style="color:#777777;font-size:10.5pt;">、<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">DCS<span style="color:#777777;font-size:10.5pt;">、<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">SIS<span style="color:#777777;font-size:10.5pt;">等工控设备的攻击,获取操控工控设备的数据包,并将获取的数据包进行修改调整,再将其发送给相关工控设备,该工控设备会接收数据包并执行进行相应的命令。由于工控系统设计之初更多的考虑实时性,而对数据包通信的安全考虑相对甚少,因此使用<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">Repaly Attack<span style="color:#777777;font-size:10.5pt;">是最简单且有效的攻击工控设备的方法。<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;"></span></span></span></span></span></span></span></span></span></span></span>
</p>
<h2 style="margin:0cm;background:white;vertical-align:baseline;font-weight:inherit;outline:0px;transition:all 0.3s ease 0s;font-variant-ligatures:normal;font-variant-caps:normal;orphans:2;text-align:start;widows:2;-webkit-text-stroke-width:0px;text-decoration-style:initial;text-decoration-color:initial;word-spacing:0px;">
        <span style="font-style:inherit;font-weight:inherit;outline:0px;" id="%E8%A5%BF%E9%97%A8%E5%AD%90PLC%E9%80%9A%E4%BF%A1%E5%8D%8F%E8%AE%AE"><span style="color:#1E1E1E;">西门子<span lang="EN-US" style="font-family:&quot;color:#1E1E1E;">PLC<span style="color:#1E1E1E;">通信协议<span lang="EN-US" style="font-family:&quot;color:#1E1E1E;"></span></span></span></span></span>
</h2>
<p style="margin-top:0cm;margin-right:0cm;margin-bottom:15.0pt;margin-left:0cm;background:white;vertical-align:baseline;outline:0px;font-variant-ligatures:normal;font-variant-caps:normal;orphans:2;text-align:start;widows:2;-webkit-text-stroke-width:0px;text-decoration-style:initial;text-decoration-color:initial;word-spacing:0px;">
        <span style="color:#777777;font-size:10.5pt;">西门子<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">S7-300 PLC<span style="color:#777777;font-size:10.5pt;">使用西门子私有通信协议<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">S7Comm<span style="color:#777777;font-size:10.5pt;">进行通信,西门子<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">S7-1200 PLC<span style="color:#777777;font-size:10.5pt;">使用西门子私有通信协议<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">S7CommPlus<span style="color:#777777;font-size:10.5pt;">进行通信。<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">S7Comm<span style="color:#777777;font-size:10.5pt;">协议以及<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">S7CommPlus<span style="color:#777777;font-size:10.5pt;">协议都基于<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">TCP/IP<span style="color:#777777;font-size:10.5pt;">,通过<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">102<span style="color:#777777;font-size:10.5pt;">端口进行通信。<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">S7Comm<span style="color:#777777;font-size:10.5pt;">协议设计较早,该协议没有任何加密验证等安全措施。一些开源网站甚至有支持<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">S7Comm<span style="color:#777777;font-size:10.5pt;">协议的小工具,使用这些工具可以对使用<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">S7Comm<span style="color:#777777;font-size:10.5pt;">协议的西门子设备进行远程操控。<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">S7CommPlus<span style="color:#777777;font-size:10.5pt;">协议使用了西门子私有的加密算法,该算法较为复杂,在<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">2017<span style="color:#777777;font-size:10.5pt;">年<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">Defcon<span style="color:#777777;font-size:10.5pt;">以及<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">Black Hat<span style="color:#777777;font-size:10.5pt;">会议中,绿盟格物实验室团队发表演讲《<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">The Spear to Break the Security Wall of S7CommPlus<span style="color:#777777;font-size:10.5pt;">》,将该加密算法破解。<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;"></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span>
</p>
<p style="margin-top:0cm;margin-right:0cm;margin-bottom:15.0pt;margin-left:0cm;background:white;vertical-align:baseline;outline:0px;font-variant-ligatures:normal;font-variant-caps:normal;orphans:2;text-align:start;widows:2;-webkit-text-stroke-width:0px;text-decoration-style:initial;text-decoration-color:initial;word-spacing:0px;">
        <span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">S7Comm<span style="color:#777777;font-size:10.5pt;">以及<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">S7CommPlus<span style="color:#777777;font-size:10.5pt;">协议具有相类似的通信时序,如图<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">1<span style="color:#777777;font-size:10.5pt;">所示。<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;"></span></span></span></span></span></span></span>
</p>
<p style="margin-top:0cm;margin-right:0cm;margin-bottom:15.0pt;margin-left:0cm;background:white;vertical-align:baseline;outline:0px;font-variant-ligatures:normal;font-variant-caps:normal;orphans:2;text-align:start;widows:2;-webkit-text-stroke-width:0px;text-decoration-style:initial;text-decoration-color:initial;word-spacing:0px;">
        <span lang="EN-US" style="color:#777777;font-family:Lato,sans-serif;font-size:10.5pt;"><img width="554" height="347" src="https://www.2k8.org/content/uploadfile/202211/26/fb57f8ac.png" alt="" style="vertical-align:middle;" /><span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;"></span></span>
</p>
<p align="center" style="margin-top:0cm;margin-right:0cm;margin-bottom:15.0pt;margin-left:0cm;text-align:center;background:white;vertical-align:baseline;outline:0px;font-variant-ligatures:normal;font-variant-caps:normal;orphans:2;widows:2;-webkit-text-stroke-width:0px;text-decoration-style:initial;text-decoration-color:initial;word-spacing:0px;">
        <span style="color:#777777;font-size:10.5pt;">图<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">1 <span style="color:#777777;font-size:10.5pt;">西门子<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">PLC<span style="color:#777777;font-size:10.5pt;">协议通信时序<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;"></span></span></span></span></span></span>
</p>
<h2 style="margin:0cm;background:white;vertical-align:baseline;font-weight:inherit;outline:0px;transition:all 0.3s ease 0s;font-variant-ligatures:normal;font-variant-caps:normal;orphans:2;text-align:start;widows:2;-webkit-text-stroke-width:0px;text-decoration-style:initial;text-decoration-color:initial;word-spacing:0px;">
        <span style="font-style:inherit;font-weight:inherit;outline:0px;" id="%E6%96%BD%E8%80%90%E5%BE%B7PLC%E9%80%9A%E4%BF%A1%E5%8D%8F%E8%AE%AE"><span style="color:#1E1E1E;">施耐德<span lang="EN-US" style="font-family:&quot;color:#1E1E1E;">PLC<span style="color:#1E1E1E;">通信协议<span lang="EN-US" style="font-family:&quot;color:#1E1E1E;"></span></span></span></span></span>
</h2>
<p style="margin-top:0cm;margin-right:0cm;margin-bottom:15.0pt;margin-left:0cm;background:white;vertical-align:baseline;outline:0px;font-variant-ligatures:normal;font-variant-caps:normal;orphans:2;text-align:start;widows:2;-webkit-text-stroke-width:0px;text-decoration-style:initial;text-decoration-color:initial;word-spacing:0px;">
        <span style="color:#777777;font-size:10.5pt;">施耐德<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">Pentium 140 PLC<span style="color:#777777;font-size:10.5pt;">使用<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">ModBus/TCP<span style="color:#777777;font-size:10.5pt;">协议,通过<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">502<span style="color:#777777;font-size:10.5pt;">端口进行通信。施耐德<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">PLC<span style="color:#777777;font-size:10.5pt;">的通信数据包使用<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">ModBus<span style="color:#777777;font-size:10.5pt;">功能码<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">90<span style="color:#777777;font-size:10.5pt;">,后面的<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">data<span style="color:#777777;font-size:10.5pt;">部分为施耐德<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">PLC<span style="color:#777777;font-size:10.5pt;">私有协议。<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;"></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span>
</p>
<p style="margin-top:0cm;margin-right:0cm;margin-bottom:15.0pt;margin-left:0cm;background:white;vertical-align:baseline;outline:0px;font-variant-ligatures:normal;font-variant-caps:normal;orphans:2;text-align:start;widows:2;-webkit-text-stroke-width:0px;text-decoration-style:initial;text-decoration-color:initial;word-spacing:0px;">
        <span style="color:#777777;font-size:10.5pt;">在施耐德<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">PLC<span style="color:#777777;font-size:10.5pt;">的通信过程中,首先向施耐德<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">PLC<span style="color:#777777;font-size:10.5pt;">发送一个获取<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">Session<span style="color:#777777;font-size:10.5pt;">的数据包,当<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">PLC<span style="color:#777777;font-size:10.5pt;">收到该数据包后,会发送带有一个字节<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">Session Key<span style="color:#777777;font-size:10.5pt;">的响应数据包,如图<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">2<span style="color:#777777;font-size:10.5pt;">所示的<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">”0xdf”<span style="color:#777777;font-size:10.5pt;">。<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;"></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span>
</p>
<p style="margin-top:0cm;margin-right:0cm;margin-bottom:15.0pt;margin-left:0cm;background:white;vertical-align:baseline;outline:0px;font-variant-ligatures:normal;font-variant-caps:normal;orphans:2;text-align:start;widows:2;-webkit-text-stroke-width:0px;text-decoration-style:initial;text-decoration-color:initial;word-spacing:0px;">
        <span lang="EN-US" style="color:#777777;font-family:Lato,sans-serif;font-size:10.5pt;"><img width="456" height="201" src="https://www.2k8.org/content/uploadfile/202211/26/bba2bdd6.png" alt="" style="vertical-align:middle;" /><span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;"></span></span>
</p>
<p align="center" style="margin-top:0cm;margin-right:0cm;margin-bottom:15.0pt;margin-left:0cm;text-align:center;background:white;vertical-align:baseline;outline:0px;font-variant-ligatures:normal;font-variant-caps:normal;orphans:2;widows:2;-webkit-text-stroke-width:0px;text-decoration-style:initial;text-decoration-color:initial;word-spacing:0px;">
        <span style="color:#777777;font-size:10.5pt;">图<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">2<span style="color:#777777;font-size:10.5pt;">获取<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">Session Key<span style="color:#777777;font-size:10.5pt;">数据包<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;"></span></span></span></span></span></span>
</p>
<p style="margin-top:0cm;margin-right:0cm;margin-bottom:15.0pt;margin-left:0cm;background:white;vertical-align:baseline;outline:0px;font-variant-ligatures:normal;font-variant-caps:normal;orphans:2;text-align:start;widows:2;-webkit-text-stroke-width:0px;text-decoration-style:initial;text-decoration-color:initial;word-spacing:0px;">
        <span style="color:#777777;font-size:10.5pt;">启动<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">PLC<span style="color:#777777;font-size:10.5pt;">的数据包如图<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">3<span style="color:#777777;font-size:10.5pt;">所示,其中第一个字节为从<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">PLC<span style="color:#777777;font-size:10.5pt;">中获取到的<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">Session Key<span style="color:#777777;font-size:10.5pt;">,第二个字节<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">“0x40”<span style="color:#777777;font-size:10.5pt;">为启动<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">PLC<span style="color:#777777;font-size:10.5pt;">的功能码。<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;"></span></span></span></span></span></span></span></span></span></span></span></span></span></span>
</p>
<p style="margin-top:0cm;margin-right:0cm;margin-bottom:15.0pt;margin-left:0cm;background:white;vertical-align:baseline;outline:0px;font-variant-ligatures:normal;font-variant-caps:normal;orphans:2;text-align:start;widows:2;-webkit-text-stroke-width:0px;text-decoration-style:initial;text-decoration-color:initial;word-spacing:0px;">
        <span lang="EN-US" style="color:#777777;font-family:Lato,sans-serif;font-size:10.5pt;"><img width="445" height="264" src="https://www.2k8.org/content/uploadfile/202211/26/6e2e1282.png" alt="" style="vertical-align:middle;" /><span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;"></span></span>
</p>
<p align="center" style="margin-top:0cm;margin-right:0cm;margin-bottom:15.0pt;margin-left:0cm;text-align:center;background:white;vertical-align:baseline;outline:0px;font-variant-ligatures:normal;font-variant-caps:normal;orphans:2;widows:2;-webkit-text-stroke-width:0px;text-decoration-style:initial;text-decoration-color:initial;word-spacing:0px;">
        <span style="color:#777777;font-size:10.5pt;">图<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">3 <span style="color:#777777;font-size:10.5pt;">启动<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">PLC<span style="color:#777777;font-size:10.5pt;">数据包<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;"></span></span></span></span></span></span>
</p>
<p style="margin-top:0cm;margin-right:0cm;margin-bottom:15.0pt;margin-left:0cm;background:white;vertical-align:baseline;outline:0px;font-variant-ligatures:normal;font-variant-caps:normal;orphans:2;text-align:start;widows:2;-webkit-text-stroke-width:0px;text-decoration-style:initial;text-decoration-color:initial;word-spacing:0px;">
        <span style="color:#777777;font-size:10.5pt;">停止<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">PLC<span style="color:#777777;font-size:10.5pt;">数据包如图<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">4<span style="color:#777777;font-size:10.5pt;">所示,其中第一个字节为从<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">PLC<span style="color:#777777;font-size:10.5pt;">中获取到的<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">Session Key<span style="color:#777777;font-size:10.5pt;">,第二个字节<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">“0x41”<span style="color:#777777;font-size:10.5pt;">为停止<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">PLC<span style="color:#777777;font-size:10.5pt;">的功能码。<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;"></span></span></span></span></span></span></span></span></span></span></span></span></span></span>
</p>
<p style="margin-top:0cm;margin-right:0cm;margin-bottom:15.0pt;margin-left:0cm;background:white;vertical-align:baseline;outline:0px;font-variant-ligatures:normal;font-variant-caps:normal;orphans:2;text-align:start;widows:2;-webkit-text-stroke-width:0px;text-decoration-style:initial;text-decoration-color:initial;word-spacing:0px;">
        <span lang="EN-US" style="color:#777777;font-family:Lato,sans-serif;font-size:10.5pt;"><img width="448" height="271" src="https://www.2k8.org/content/uploadfile/202211/26/bad004ff.png" alt="" style="vertical-align:middle;" /><span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;"></span></span>
</p>
<p align="center" style="margin-top:0cm;margin-right:0cm;margin-bottom:15.0pt;margin-left:0cm;text-align:center;background:white;vertical-align:baseline;outline:0px;font-variant-ligatures:normal;font-variant-caps:normal;orphans:2;widows:2;-webkit-text-stroke-width:0px;text-decoration-style:initial;text-decoration-color:initial;word-spacing:0px;">
        <span style="color:#777777;font-size:10.5pt;">图<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">4 <span style="color:#777777;font-size:10.5pt;">停止<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">PLC<span style="color:#777777;font-size:10.5pt;">数据包<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;"></span></span></span></span></span></span>
</p>
<p style="margin-top:0cm;margin-right:0cm;margin-bottom:15.0pt;margin-left:0cm;background:white;vertical-align:baseline;outline:0px;font-variant-ligatures:normal;font-variant-caps:normal;orphans:2;text-align:start;widows:2;-webkit-text-stroke-width:0px;text-decoration-style:initial;text-decoration-color:initial;word-spacing:0px;">
        <span style="color:#777777;font-size:10.5pt;">开关量写值数据包如图<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">5<span style="color:#777777;font-size:10.5pt;">所示,其中第一个字节为从<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">PLC<span style="color:#777777;font-size:10.5pt;">中获取到的<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">Session Key<span style="color:#777777;font-size:10.5pt;">,第二个字节<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">“0x50”<span style="color:#777777;font-size:10.5pt;">为开关量写值的功能码,第<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">22<span style="color:#777777;font-size:10.5pt;">个字节为该开关量点的地址,第<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">29<span style="color:#777777;font-size:10.5pt;">个字节为要写的值。<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;"></span></span></span></span></span></span></span></span></span></span></span></span></span></span>
</p>
<p style="margin-top:0cm;margin-right:0cm;margin-bottom:15.0pt;margin-left:0cm;background:white;vertical-align:baseline;outline:0px;font-variant-ligatures:normal;font-variant-caps:normal;orphans:2;text-align:start;widows:2;-webkit-text-stroke-width:0px;text-decoration-style:initial;text-decoration-color:initial;word-spacing:0px;">
        <span lang="EN-US" style="color:#777777;font-family:Lato,sans-serif;font-size:10.5pt;"><img width="475" height="219" src="https://www.2k8.org/content/uploadfile/202211/26/c66c9b14.png" alt="" style="vertical-align:middle;" /><span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;"></span></span>
</p>
<p align="center" style="margin-top:0cm;margin-right:0cm;margin-bottom:15.0pt;margin-left:0cm;text-align:center;background:white;vertical-align:baseline;outline:0px;font-variant-ligatures:normal;font-variant-caps:normal;orphans:2;widows:2;-webkit-text-stroke-width:0px;text-decoration-style:initial;text-decoration-color:initial;word-spacing:0px;">
        <span style="color:#777777;font-size:10.5pt;">图<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">5 <span style="color:#777777;font-size:10.5pt;">开关量输出点写值数据包<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;"></span></span></span></span>
</p>
<h2 style="margin:0cm;background:white;vertical-align:baseline;font-weight:inherit;outline:0px;transition:all 0.3s ease 0s;font-variant-ligatures:normal;font-variant-caps:normal;orphans:2;text-align:start;widows:2;-webkit-text-stroke-width:0px;text-decoration-style:initial;text-decoration-color:initial;word-spacing:0px;">
        <span style="font-style:inherit;font-weight:inherit;outline:0px;" id="%E7%BD%97%E5%85%8B%E9%9F%A6%E5%B0%94PLC%E9%80%9A%E4%BF%A1%E5%8D%8F%E8%AE%AE"><span style="color:#1E1E1E;">罗克韦尔<span lang="EN-US" style="font-family:&quot;color:#1E1E1E;">PLC<span style="color:#1E1E1E;">通信协议<span lang="EN-US" style="font-family:&quot;color:#1E1E1E;"></span></span></span></span></span>
</h2>
<p style="margin-top:0cm;margin-right:0cm;margin-bottom:15.0pt;margin-left:0cm;background:white;vertical-align:baseline;outline:0px;font-variant-ligatures:normal;font-variant-caps:normal;orphans:2;text-align:start;widows:2;-webkit-text-stroke-width:0px;text-decoration-style:initial;text-decoration-color:initial;word-spacing:0px;">
        <span style="color:#777777;font-size:10.5pt;">罗克韦尔<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">Micrologix 1400 PLC<span style="color:#777777;font-size:10.5pt;">使用<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">EtherNet/IP<span style="color:#777777;font-size:10.5pt;">以及<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">CIP<span style="color:#777777;font-size:10.5pt;">协议,通过<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">44818<span style="color:#777777;font-size:10.5pt;">端口进行通信。其中<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">CIP<span style="color:#777777;font-size:10.5pt;">协议中的<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">Command Specific Data<span style="color:#777777;font-size:10.5pt;">字段为罗克韦尔<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">PLC<span style="color:#777777;font-size:10.5pt;">通信的私有协议内容。<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;"></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span>
</p>
<p style="margin-top:0cm;margin-right:0cm;margin-bottom:15.0pt;margin-left:0cm;background:white;vertical-align:baseline;outline:0px;font-variant-ligatures:normal;font-variant-caps:normal;orphans:2;text-align:start;widows:2;-webkit-text-stroke-width:0px;text-decoration-style:initial;text-decoration-color:initial;word-spacing:0px;">
        <span style="color:#777777;font-size:10.5pt;">罗克韦尔<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">PLC<span style="color:#777777;font-size:10.5pt;">通信包括<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">EtherNet/IP<span style="color:#777777;font-size:10.5pt;">连接过程、<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">CIP<span style="color:#777777;font-size:10.5pt;">连接过程以及功能数据包(启动、停止<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">PLC<span style="color:#777777;font-size:10.5pt;">、读值、写值等)。<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;"></span></span></span></span></span></span></span></span></span></span>
</p>
<h3 style="margin:0cm;background:white;vertical-align:baseline;font-weight:inherit;outline:0px;transition:all 0.3s ease 0s;font-variant-ligatures:normal;font-variant-caps:normal;orphans:2;text-align:start;widows:2;-webkit-text-stroke-width:0px;text-decoration-style:initial;text-decoration-color:initial;word-spacing:0px;">
        <span style="font-style:inherit;font-weight:inherit;outline:0px;" id="1%E3%80%81EtherNet/IP%E8%BF%9E%E6%8E%A5%E8%BF%87%E7%A8%8B"><span lang="EN-US" style="font-size:15.0pt;font-family:&quot;color:#1E1E1E;">1<span style="color:#1E1E1E;font-size:15.0pt;">、<span lang="EN-US" style="font-size:15.0pt;font-family:&quot;color:#1E1E1E;">EtherNet/IP<span style="color:#1E1E1E;font-size:15.0pt;">连接过程<span lang="EN-US" style="font-size:15.0pt;font-family:&quot;color:#1E1E1E;"></span></span></span></span></span></span>
</h3>
<p style="margin-top:0cm;margin-right:0cm;margin-bottom:15.0pt;margin-left:0cm;background:white;vertical-align:baseline;outline:0px;font-variant-ligatures:normal;font-variant-caps:normal;orphans:2;text-align:start;widows:2;-webkit-text-stroke-width:0px;text-decoration-style:initial;text-decoration-color:initial;word-spacing:0px;">
        <span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">EtherNet/IP<span style="color:#777777;font-size:10.5pt;">的连接过程包括<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">4<span style="color:#777777;font-size:10.5pt;">个<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">ENIP<span style="color:#777777;font-size:10.5pt;">数据包,其<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">Command<span style="color:#777777;font-size:10.5pt;">字段分别为<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">”0x0001”,”0x0004”,”0x0064”,”0x0065”<span style="color:#777777;font-size:10.5pt;">。其中对于<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">Command<span style="color:#777777;font-size:10.5pt;">字段为<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">“0x0065”<span style="color:#777777;font-size:10.5pt;">的请求数据包,<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">PLC<span style="color:#777777;font-size:10.5pt;">会发送一个带有<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">Register Session ID<span style="color:#777777;font-size:10.5pt;">的响应数据包,如图<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">6<span style="color:#777777;font-size:10.5pt;">所示<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;"></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span>
</p>
<p style="margin-top:0cm;margin-right:0cm;margin-bottom:15.0pt;margin-left:0cm;background:white;vertical-align:baseline;outline:0px;font-variant-ligatures:normal;font-variant-caps:normal;orphans:2;text-align:start;widows:2;-webkit-text-stroke-width:0px;text-decoration-style:initial;text-decoration-color:initial;word-spacing:0px;">
        <span lang="EN-US" style="color:#777777;font-family:Lato,sans-serif;font-size:10.5pt;"><img width="554" height="133" src="https://www.2k8.org/content/uploadfile/202211/26/5bebd094.png" alt="" style="vertical-align:middle;" /><span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;"></span></span>
</p>
<p align="center" style="margin-top:0cm;margin-right:0cm;margin-bottom:15.0pt;margin-left:0cm;text-align:center;background:white;vertical-align:baseline;outline:0px;font-variant-ligatures:normal;font-variant-caps:normal;orphans:2;widows:2;-webkit-text-stroke-width:0px;text-decoration-style:initial;text-decoration-color:initial;word-spacing:0px;">
        <span lang="EN-US" style="color:#777777;font-family:Lato,sans-serif;font-size:10.5pt;"><img width="426" height="247" src="https://www.2k8.org/content/uploadfile/202211/26/31dc1aa0.png" alt="" style="vertical-align:middle;" /><span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;"></span></span>
</p>
<p align="center" style="margin-top:0cm;margin-right:0cm;margin-bottom:15.0pt;margin-left:0cm;text-align:center;background:white;vertical-align:baseline;outline:0px;font-variant-ligatures:normal;font-variant-caps:normal;orphans:2;widows:2;-webkit-text-stroke-width:0px;text-decoration-style:initial;text-decoration-color:initial;word-spacing:0px;">
        <span style="color:#777777;font-size:10.5pt;">图<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">6 EtherNet/IP<span style="color:#777777;font-size:10.5pt;">连接过程<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;"></span></span></span></span>
</p>
<h3 style="margin:0cm;background:white;vertical-align:baseline;font-weight:inherit;outline:0px;transition:all 0.3s ease 0s;font-variant-ligatures:normal;font-variant-caps:normal;orphans:2;text-align:start;widows:2;-webkit-text-stroke-width:0px;text-decoration-style:initial;text-decoration-color:initial;word-spacing:0px;">
        <span style="font-style:inherit;font-weight:inherit;outline:0px;" id="2%E3%80%81CIP%E8%BF%9E%E6%8E%A5%E8%BF%87%E7%A8%8B"><span lang="EN-US" style="font-size:15.0pt;font-family:&quot;color:#1E1E1E;">2<span style="color:#1E1E1E;font-size:15.0pt;">、<span lang="EN-US" style="font-size:15.0pt;font-family:&quot;color:#1E1E1E;">CIP<span style="color:#1E1E1E;font-size:15.0pt;">连接过程<span lang="EN-US" style="font-size:15.0pt;font-family:&quot;color:#1E1E1E;"></span></span></span></span></span></span>
</h3>
<p style="margin-top:0cm;margin-right:0cm;margin-bottom:15.0pt;margin-left:0cm;background:white;vertical-align:baseline;outline:0px;font-variant-ligatures:normal;font-variant-caps:normal;orphans:2;text-align:start;widows:2;-webkit-text-stroke-width:0px;text-decoration-style:initial;text-decoration-color:initial;word-spacing:0px;">
        <span style="color:#777777;font-size:10.5pt;">当<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">EtherNet/IP<span style="color:#777777;font-size:10.5pt;">连接建立成功后,<span style="font-size:10.5pt;font-family:&quot;color:#777777;"> <span style="color:#777777;font-size:10.5pt;">一个<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">CIP Connection Manager<span style="color:#777777;font-size:10.5pt;">数据包将被发送给<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">PLC<span style="color:#777777;font-size:10.5pt;">设备,如图<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">7<span style="color:#777777;font-size:10.5pt;">所示<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;"></span></span></span></span></span></span></span></span></span></span></span></span>
</p>
<p style="margin-top:0cm;margin-right:0cm;margin-bottom:15.0pt;margin-left:0cm;background:white;vertical-align:baseline;outline:0px;font-variant-ligatures:normal;font-variant-caps:normal;orphans:2;text-align:start;widows:2;-webkit-text-stroke-width:0px;text-decoration-style:initial;text-decoration-color:initial;word-spacing:0px;">
        <span lang="EN-US" style="color:#777777;font-family:Lato,sans-serif;font-size:10.5pt;"><img width="554" height="34" src="https://www.2k8.org/content/uploadfile/202211/26/1a6f7faf.png" alt="" style="vertical-align:middle;" /><span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;"></span></span>
</p>
<p align="center" style="margin-top:0cm;margin-right:0cm;margin-bottom:15.0pt;margin-left:0cm;text-align:center;background:white;vertical-align:baseline;outline:0px;font-variant-ligatures:normal;font-variant-caps:normal;orphans:2;widows:2;-webkit-text-stroke-width:0px;text-decoration-style:initial;text-decoration-color:initial;word-spacing:0px;">
        <span style="color:#777777;font-size:10.5pt;">图<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">7 CIP CM<span style="color:#777777;font-size:10.5pt;">连接数据包<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;"></span></span></span></span>
</p>
<p style="margin-top:0cm;margin-right:0cm;margin-bottom:15.0pt;margin-left:0cm;background:white;vertical-align:baseline;outline:0px;font-variant-ligatures:normal;font-variant-caps:normal;orphans:2;text-align:start;widows:2;-webkit-text-stroke-width:0px;text-decoration-style:initial;text-decoration-color:initial;word-spacing:0px;">
        <span style="color:#777777;font-size:10.5pt;">如<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">PLC<span style="color:#777777;font-size:10.5pt;">响应成功,则会发送一个<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">CIP CM<span style="color:#777777;font-size:10.5pt;">的<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">Response<span style="color:#777777;font-size:10.5pt;">数据包,如图<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">8<span style="color:#777777;font-size:10.5pt;">所示<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;"></span></span></span></span></span></span></span></span></span></span>
</p>
<p style="margin-top:0cm;margin-right:0cm;margin-bottom:15.0pt;margin-left:0cm;background:white;vertical-align:baseline;outline:0px;font-variant-ligatures:normal;font-variant-caps:normal;orphans:2;text-align:start;widows:2;-webkit-text-stroke-width:0px;text-decoration-style:initial;text-decoration-color:initial;word-spacing:0px;">
        <span lang="EN-US" style="color:#777777;font-family:Lato,sans-serif;font-size:10.5pt;"><img width="515" height="410" src="https://www.2k8.org/content/uploadfile/202211/26/59b52de8.png" alt="" style="vertical-align:middle;" /><span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;"></span></span>
</p>
<p align="center" style="margin-top:0cm;margin-right:0cm;margin-bottom:15.0pt;margin-left:0cm;text-align:center;background:white;vertical-align:baseline;outline:0px;font-variant-ligatures:normal;font-variant-caps:normal;orphans:2;widows:2;-webkit-text-stroke-width:0px;text-decoration-style:initial;text-decoration-color:initial;word-spacing:0px;">
        <span style="color:#777777;font-size:10.5pt;">图<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">8 CIP CM<span style="color:#777777;font-size:10.5pt;">响应数据包<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;"></span></span></span></span>
</p>
<p style="margin-top:0cm;margin-right:0cm;margin-bottom:15.0pt;margin-left:0cm;background:white;vertical-align:baseline;outline:0px;font-variant-ligatures:normal;font-variant-caps:normal;orphans:2;text-align:start;widows:2;-webkit-text-stroke-width:0px;text-decoration-style:initial;text-decoration-color:initial;word-spacing:0px;">
        <span style="color:#777777;font-size:10.5pt;">其中<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">CIP<span style="color:#777777;font-size:10.5pt;">字段中的<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">Command Specific Data<span style="color:#777777;font-size:10.5pt;">字段中的<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;"> O-&gt;T Network Connection ID<span style="color:#777777;font-size:10.5pt;">以及<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">Originator Serial Number<span style="color:#777777;font-size:10.5pt;">作为<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">CIP<span style="color:#777777;font-size:10.5pt;">数据包的<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">Session ID<span style="color:#777777;font-size:10.5pt;">在后续<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">CIP<span style="color:#777777;font-size:10.5pt;">功能数据包中会使用被验证。<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;"></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span>
</p>
<p style="margin-top:0cm;margin-right:0cm;margin-bottom:15.0pt;margin-left:0cm;background:white;vertical-align:baseline;outline:0px;font-variant-ligatures:normal;font-variant-caps:normal;orphans:2;text-align:start;widows:2;-webkit-text-stroke-width:0px;text-decoration-style:initial;text-decoration-color:initial;word-spacing:0px;">
        <span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">CIP Connection Manager<span style="color:#777777;font-size:10.5pt;">连接建立完成后,开始建立<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">CIP<span style="color:#777777;font-size:10.5pt;">连接,共<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">6<span style="color:#777777;font-size:10.5pt;">个<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">CIP<span style="color:#777777;font-size:10.5pt;">连接数据包,如图<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">9<span style="color:#777777;font-size:10.5pt;">所示<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;"></span></span></span></span></span></span></span></span></span></span></span>
</p>
<p style="margin-top:0cm;margin-right:0cm;margin-bottom:15.0pt;margin-left:0cm;background:white;vertical-align:baseline;outline:0px;font-variant-ligatures:normal;font-variant-caps:normal;orphans:2;text-align:start;widows:2;-webkit-text-stroke-width:0px;text-decoration-style:initial;text-decoration-color:initial;word-spacing:0px;">
        <span lang="EN-US" style="color:#777777;font-family:Lato,sans-serif;font-size:10.5pt;"><img width="427" height="147" src="https://www.2k8.org/content/uploadfile/202211/26/39658087.png" alt="" style="vertical-align:middle;" /><span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;"></span></span>
</p>
<p align="center" style="margin-top:0cm;margin-right:0cm;margin-bottom:15.0pt;margin-left:0cm;text-align:center;background:white;vertical-align:baseline;outline:0px;font-variant-ligatures:normal;font-variant-caps:normal;orphans:2;widows:2;-webkit-text-stroke-width:0px;text-decoration-style:initial;text-decoration-color:initial;word-spacing:0px;">
        <span style="color:#777777;font-size:10.5pt;">图<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">9 CIP<span style="color:#777777;font-size:10.5pt;">连接数据包<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;"></span></span></span></span>
</p>
<p style="margin-top:0cm;margin-right:0cm;margin-bottom:15.0pt;margin-left:0cm;background:white;vertical-align:baseline;outline:0px;font-variant-ligatures:normal;font-variant-caps:normal;orphans:2;text-align:start;widows:2;-webkit-text-stroke-width:0px;text-decoration-style:initial;text-decoration-color:initial;word-spacing:0px;">
        <span style="color:#777777;font-size:10.5pt;">其中每个连接数据包都会用到<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">CIP Connection Manager Response<span style="color:#777777;font-size:10.5pt;">数据包中的<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">O-&gt;T Network Connection ID<span style="color:#777777;font-size:10.5pt;">以及<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">Originator Serial Number</span></span></span></span></span></span>
</p>
<h3 style="margin:0cm;background:white;vertical-align:baseline;font-weight:inherit;outline:0px;transition:all 0.3s ease 0s;font-variant-ligatures:normal;font-variant-caps:normal;orphans:2;text-align:start;widows:2;-webkit-text-stroke-width:0px;text-decoration-style:initial;text-decoration-color:initial;word-spacing:0px;">
        <span style="font-style:inherit;font-weight:inherit;outline:0px;" id="3%E3%80%81%E5%8A%9F%E8%83%BD%E6%95%B0%E6%8D%AE%E5%8C%85"><span lang="EN-US" style="font-size:15.0pt;font-family:&quot;color:#1E1E1E;">3<span style="color:#1E1E1E;font-size:15.0pt;">、功能数据包<span lang="EN-US" style="font-size:15.0pt;font-family:&quot;color:#1E1E1E;"></span></span></span></span>
</h3>
<p style="margin-top:0cm;margin-right:0cm;margin-bottom:15.0pt;margin-left:0cm;background:white;vertical-align:baseline;outline:0px;font-variant-ligatures:normal;font-variant-caps:normal;orphans:2;text-align:start;widows:2;-webkit-text-stroke-width:0px;text-decoration-style:initial;text-decoration-color:initial;word-spacing:0px;">
        <span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">1<span style="color:#777777;font-size:10.5pt;">)<span style="font-size:10.5pt;font-family:&quot;color:#777777;"> <span style="color:#777777;font-size:10.5pt;">启动<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">PLC</span></span></span></span></span>
</p>
<p style="margin-top:0cm;margin-right:0cm;margin-bottom:15.0pt;margin-left:0cm;background:white;vertical-align:baseline;outline:0px;font-variant-ligatures:normal;font-variant-caps:normal;orphans:2;text-align:start;widows:2;-webkit-text-stroke-width:0px;text-decoration-style:initial;text-decoration-color:initial;word-spacing:0px;">
        <span style="color:#777777;font-size:10.5pt;">启动<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">PLC<span style="color:#777777;font-size:10.5pt;">数据包如图<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">10<span style="color:#777777;font-size:10.5pt;">所示,其中红框和蓝框分别为<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">CIP Connection Manager Response<span style="color:#777777;font-size:10.5pt;">数据包中的<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">O-&gt;T Network Connection ID<span style="color:#777777;font-size:10.5pt;">以及<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">Originator Serial Number<span style="color:#777777;font-size:10.5pt;">,绿框为<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">Sequence Count<span style="color:#777777;font-size:10.5pt;">。黄色字段<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">0x55<span style="color:#777777;font-size:10.5pt;">,<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">0x01<span style="color:#777777;font-size:10.5pt;">为启动<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">PLC<span style="color:#777777;font-size:10.5pt;">的功能码。<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;"></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span>
</p>
<p style="margin-top:0cm;margin-right:0cm;margin-bottom:15.0pt;margin-left:0cm;background:white;vertical-align:baseline;outline:0px;font-variant-ligatures:normal;font-variant-caps:normal;orphans:2;text-align:start;widows:2;-webkit-text-stroke-width:0px;text-decoration-style:initial;text-decoration-color:initial;word-spacing:0px;">
        <span lang="EN-US" style="color:#777777;font-family:Lato,sans-serif;font-size:10.5pt;"><img width="392" height="353" src="https://www.2k8.org/content/uploadfile/202211/26/0e2f6d15.png" alt="" style="vertical-align:middle;" /><span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;"></span></span>
</p>
<p align="center" style="margin-top:0cm;margin-right:0cm;margin-bottom:15.0pt;margin-left:0cm;text-align:center;background:white;vertical-align:baseline;outline:0px;font-variant-ligatures:normal;font-variant-caps:normal;orphans:2;widows:2;-webkit-text-stroke-width:0px;text-decoration-style:initial;text-decoration-color:initial;word-spacing:0px;">
        <span style="color:#777777;font-size:10.5pt;">图<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">10 <span style="color:#777777;font-size:10.5pt;">启动罗克韦尔<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">PLC<span style="color:#777777;font-size:10.5pt;">数据包<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;"></span></span></span></span></span></span>
</p>
<p style="margin-top:0cm;margin-right:0cm;margin-bottom:15.0pt;margin-left:0cm;background:white;vertical-align:baseline;outline:0px;font-variant-ligatures:normal;font-variant-caps:normal;orphans:2;text-align:start;widows:2;-webkit-text-stroke-width:0px;text-decoration-style:initial;text-decoration-color:initial;word-spacing:0px;">
        <span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">2<span style="color:#777777;font-size:10.5pt;">)<span style="font-size:10.5pt;font-family:&quot;color:#777777;"> <span style="color:#777777;font-size:10.5pt;">停止<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">PLC</span></span></span></span></span>
</p>
<p style="margin-top:0cm;margin-right:0cm;margin-bottom:15.0pt;margin-left:0cm;background:white;vertical-align:baseline;outline:0px;font-variant-ligatures:normal;font-variant-caps:normal;orphans:2;text-align:start;widows:2;-webkit-text-stroke-width:0px;text-decoration-style:initial;text-decoration-color:initial;word-spacing:0px;">
        <span style="color:#777777;font-size:10.5pt;">停止<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">PLC<span style="color:#777777;font-size:10.5pt;">数据包如图<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">11<span style="color:#777777;font-size:10.5pt;">所示,其中红框和蓝框分别为<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">CIP Connection Manager Response<span style="color:#777777;font-size:10.5pt;">数据包中的<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">O-&gt;T Network Connection ID<span style="color:#777777;font-size:10.5pt;">以及<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">Originator Serial Number<span style="color:#777777;font-size:10.5pt;">,绿框为<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">Sequence Count<span style="color:#777777;font-size:10.5pt;">。黄色字段<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">0xF1<span style="color:#777777;font-size:10.5pt;">,<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">0x01<span style="color:#777777;font-size:10.5pt;">为停止<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">PLC<span style="color:#777777;font-size:10.5pt;">的功能码。<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;"></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span>
</p>
<p style="margin-top:0cm;margin-right:0cm;margin-bottom:15.0pt;margin-left:0cm;background:white;vertical-align:baseline;outline:0px;font-variant-ligatures:normal;font-variant-caps:normal;orphans:2;text-align:start;widows:2;-webkit-text-stroke-width:0px;text-decoration-style:initial;text-decoration-color:initial;word-spacing:0px;">
        <span lang="EN-US" style="color:#777777;font-family:Lato,sans-serif;font-size:10.5pt;"><img width="401" height="328" src="https://www.2k8.org/content/uploadfile/202211/26/f5843b03.png" alt="" style="vertical-align:middle;" /><span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;"></span></span>
</p>
<p align="center" style="margin-top:0cm;margin-right:0cm;margin-bottom:15.0pt;margin-left:0cm;text-align:center;background:white;vertical-align:baseline;outline:0px;font-variant-ligatures:normal;font-variant-caps:normal;orphans:2;widows:2;-webkit-text-stroke-width:0px;text-decoration-style:initial;text-decoration-color:initial;word-spacing:0px;">
        <span style="color:#777777;font-size:10.5pt;">图<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">11 <span style="color:#777777;font-size:10.5pt;">停止罗克韦尔<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">PLC<span style="color:#777777;font-size:10.5pt;">数据包<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;"></span></span></span></span></span></span>
</p>
<p style="margin-top:0cm;margin-right:0cm;margin-bottom:15.0pt;margin-left:0cm;background:white;vertical-align:baseline;outline:0px;font-variant-ligatures:normal;font-variant-caps:normal;orphans:2;text-align:start;widows:2;-webkit-text-stroke-width:0px;text-decoration-style:initial;text-decoration-color:initial;word-spacing:0px;">
        <span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">3<span style="color:#777777;font-size:10.5pt;">)<span style="font-size:10.5pt;font-family:&quot;color:#777777;"> <span style="color:#777777;font-size:10.5pt;">开关量写值<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;"></span></span></span></span></span>
</p>
<p style="margin-top:0cm;margin-right:0cm;margin-bottom:15.0pt;margin-left:0cm;background:white;vertical-align:baseline;outline:0px;font-variant-ligatures:normal;font-variant-caps:normal;orphans:2;text-align:start;widows:2;-webkit-text-stroke-width:0px;text-decoration-style:initial;text-decoration-color:initial;word-spacing:0px;">
        <span style="color:#777777;font-size:10.5pt;">开关量写值数据包如上图所示,其中红框和蓝框分别为<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">CIP Connection Manager Response<span style="color:#777777;font-size:10.5pt;">数据包中的<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">O-&gt;T Network Connection ID<span style="color:#777777;font-size:10.5pt;">以及<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">Originator Serial Number<span style="color:#777777;font-size:10.5pt;">,绿框为<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">Sequence Count<span style="color:#777777;font-size:10.5pt;">。黄色字段<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">0xab<span style="color:#777777;font-size:10.5pt;">,<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">0x02<span style="color:#777777;font-size:10.5pt;">为写开关量点的功能码。紫红色框为点地址,橙色框为所写的值。<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;"></span></span></span></span></span></span></span></span></span></span></span></span></span></span>
</p>
<p style="margin-top:0cm;margin-right:0cm;margin-bottom:15.0pt;margin-left:0cm;background:white;vertical-align:baseline;outline:0px;font-variant-ligatures:normal;font-variant-caps:normal;orphans:2;text-align:start;widows:2;-webkit-text-stroke-width:0px;text-decoration-style:initial;text-decoration-color:initial;word-spacing:0px;">
        <span lang="EN-US" style="color:#777777;font-family:Lato,sans-serif;font-size:10.5pt;"><img width="345" height="252" src="https://www.2k8.org/content/uploadfile/202211/26/147148c7.png" alt="" style="vertical-align:middle;" /><span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;"></span></span>
</p>
<p align="center" style="margin-top:0cm;margin-right:0cm;margin-bottom:15.0pt;margin-left:0cm;text-align:center;background:white;vertical-align:baseline;outline:0px;font-variant-ligatures:normal;font-variant-caps:normal;orphans:2;widows:2;-webkit-text-stroke-width:0px;text-decoration-style:initial;text-decoration-color:initial;word-spacing:0px;">
        <span style="color:#777777;font-size:10.5pt;">图<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">12 <span style="color:#777777;font-size:10.5pt;">罗克韦尔<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">PLC<span style="color:#777777;font-size:10.5pt;">开关量写值数据包<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;"></span></span></span></span></span></span>
</p>
<h2 style="margin:0cm;background:white;vertical-align:baseline;font-weight:inherit;outline:0px;transition:all 0.3s ease 0s;font-variant-ligatures:normal;font-variant-caps:normal;orphans:2;text-align:start;widows:2;-webkit-text-stroke-width:0px;text-decoration-style:initial;text-decoration-color:initial;word-spacing:0px;">
        <span style="font-style:inherit;font-weight:inherit;outline:0px;" id="%E6%94%BB%E5%87%BBPLC"><span style="color:#1E1E1E;">攻击<span lang="EN-US" style="font-family:&quot;color:#1E1E1E;">PLC</span></span></span>
</h2>
<p style="margin-top:0cm;margin-right:0cm;margin-bottom:15.0pt;margin-left:0cm;background:white;vertical-align:baseline;outline:0px;font-variant-ligatures:normal;font-variant-caps:normal;orphans:2;text-align:start;widows:2;-webkit-text-stroke-width:0px;text-decoration-style:initial;text-decoration-color:initial;word-spacing:0px;">
        <span style="color:#777777;font-size:10.5pt;">当掌握了西门子<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">PLC<span style="color:#777777;font-size:10.5pt;">、施耐德<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">PLC<span style="color:#777777;font-size:10.5pt;">、罗克韦尔<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">PLC<span style="color:#777777;font-size:10.5pt;">的通信协议后,即可通过协议进行<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">PLC<span style="color:#777777;font-size:10.5pt;">的攻击。<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;"></span></span></span></span></span></span></span></span></span></span>
</p>
<p style="margin-top:0cm;margin-right:0cm;margin-bottom:15.0pt;margin-left:0cm;background:white;vertical-align:baseline;outline:0px;font-variant-ligatures:normal;font-variant-caps:normal;orphans:2;text-align:start;widows:2;-webkit-text-stroke-width:0px;text-decoration-style:initial;text-decoration-color:initial;word-spacing:0px;">
        <span style="color:#777777;font-size:10.5pt;">西门子<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">PLC<span style="color:#777777;font-size:10.5pt;">中的<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">TCON<span style="color:#777777;font-size:10.5pt;">功能块可以与基于<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">TCP/IP<span style="color:#777777;font-size:10.5pt;">通信协议的<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">PLC<span style="color:#777777;font-size:10.5pt;">建立连接,当连接建立成功后,通过<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">TSEND<span style="color:#777777;font-size:10.5pt;">功能块向已经建立成功的<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">PLC<span style="color:#777777;font-size:10.5pt;">发送存储于<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">DB<span style="color:#777777;font-size:10.5pt;">块的协议报文。此时相当于通过一个西门子的<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">PLC<span style="color:#777777;font-size:10.5pt;">向其他<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">PLC<span style="color:#777777;font-size:10.5pt;">发送如启动<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">PLC<span style="color:#777777;font-size:10.5pt;">、停止<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">PLC<span style="color:#777777;font-size:10.5pt;">、<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">DO<span style="color:#777777;font-size:10.5pt;">点写值的操作。当施耐德<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">PLC<span style="color:#777777;font-size:10.5pt;">或罗克韦尔<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">PLC<span style="color:#777777;font-size:10.5pt;">收到该数据包后,不会判断数据包的来源,而是直接执行,从而达到了通过一个<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">PLC<span style="color:#777777;font-size:10.5pt;">攻击其他<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">PLC<span style="color:#777777;font-size:10.5pt;">的效果。图<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">13<span style="color:#777777;font-size:10.5pt;">所示为在西门子<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">PLC<span style="color:#777777;font-size:10.5pt;">中编写的攻击其他<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">PLC<span style="color:#777777;font-size:10.5pt;">的程序。<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;"></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span></span>
</p>
<p style="margin-top:0cm;margin-right:0cm;margin-bottom:15.0pt;margin-left:0cm;background:white;vertical-align:baseline;outline:0px;font-variant-ligatures:normal;font-variant-caps:normal;orphans:2;text-align:start;widows:2;-webkit-text-stroke-width:0px;text-decoration-style:initial;text-decoration-color:initial;word-spacing:0px;">
        <span lang="EN-US" style="color:#777777;font-family:Lato,sans-serif;font-size:10.5pt;"><img width="268" height="222" src="https://www.2k8.org/content/uploadfile/202211/26/1e899458.png" alt="" style="vertical-align:middle;" /><img width="264" height="217" src="https://www.2k8.org/content/uploadfile/202211/26/54ce3a68.png" alt="" style="vertical-align:middle;" /><span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;"></span></span>
</p>
<p align="center" style="margin-top:0cm;margin-right:0cm;margin-bottom:15.0pt;margin-left:0cm;text-align:center;background:white;vertical-align:baseline;outline:0px;font-variant-ligatures:normal;font-variant-caps:normal;orphans:2;widows:2;-webkit-text-stroke-width:0px;text-decoration-style:initial;text-decoration-color:initial;word-spacing:0px;">
        <span style="color:#777777;font-size:10.5pt;">图<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">13 <span style="color:#777777;font-size:10.5pt;">在西门子<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">PLC<span style="color:#777777;font-size:10.5pt;">中编写攻击其他<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;">PLC<span style="color:#777777;font-size:10.5pt;">的程序<span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;"></span></span></span></span></span></span></span></span>
</p>
<h2 style="margin:0cm;background:white;vertical-align:baseline;font-weight:inherit;outline:0px;transition:all 0.3s ease 0s;font-variant-ligatures:normal;font-variant-caps:normal;orphans:2;text-align:start;widows:2;-webkit-text-stroke-width:0px;text-decoration-style:initial;text-decoration-color:initial;word-spacing:0px;">
        <span style="font-style:inherit;font-weight:inherit;outline:0px;" id="%E6%BC%94%E7%A4%BA"><span style="color:#1E1E1E;">演示<span lang="EN-US" style="font-family:&quot;color:#1E1E1E;"></span></span></span>
</h2>
<p style="margin:0cm;background:white;vertical-align:baseline;outline:0px;font-variant-ligatures:normal;font-variant-caps:normal;orphans:2;text-align:start;widows:2;-webkit-text-stroke-width:0px;text-decoration-style:initial;text-decoration-color:initial;word-spacing:0px;">
        <span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;"><a href="https://v.youku.com/v_show/id_XMzQzNDkzOTE0OA==.html?spm=a2h0k.8191407.0.0&amp;from=s1.8-1-1.2" style="font-style:inherit;font-weight:inherit;outline:none 0px;cursor:pointer;transition:all 0.3s ease 0s;"><span style="border:none windowtext 1.0pt;color:#1EAAF1;font-family:inherit,serif;padding:0cm;text-decoration:none;text-underline:none;">https://v.youku.com/v_show/id_XMzQzNDkzOTE0OA==.html?spm=a2h0k.8191407.0.0&amp;from=s1.8-1-1.2</span></a></span>
</p>
<p style="margin:0cm;background:white;vertical-align:baseline;outline:0px;font-variant-ligatures:normal;font-variant-caps:normal;orphans:2;text-align:start;widows:2;-webkit-text-stroke-width:0px;text-decoration-style:initial;text-decoration-color:initial;word-spacing:0px;">
        <strong style="font-style:inherit;outline:0px;"><span lang="EN-US" style="border:none windowtext 1.0pt;color:#777777;font-family:inherit,serif;font-size:10.5pt;padding:0cm;">&nbsp;</span></strong><span lang="EN-US" style="font-size:10.5pt;font-family:&quot;color:#777777;"></span>
</p>
<p style="font-family:等线;font-size:10.5pt;margin:0cm;text-align:justify;text-justify:inter-ideograph;">
        <span lang="EN-US">&nbsp;</span>
</p>
页: [1]
查看完整版本: 转载ATTACKING PLCS BY PLC IN DEEP