finds.dev← search

// the find

filipepestana/SCADA-ettercap-MITM

★ 3 · C · GPL-3.0 · updated Jan 2019

Ettercap plugins for DNP3 and IEC 60870-5-104

Two Ettercap plugins for performing man-in-the-middle attacks on IEC 60870-5-104 and DNP3 industrial control protocols. Targeted at security researchers and pentesters working in OT/SCADA environments who want to inspect or tamper with SCADA traffic in a lab.

Covers two of the most widely deployed SCADA protocols, which are rarely touched by mainstream security tooling. Ettercap plugin architecture means you get ARP spoofing and packet interception for free — no need to implement your own capture layer. Useful as a starting point for understanding how these protocols look on the wire before building more sophisticated tooling.

Three stars and no commits since 2019 — this is effectively abandoned. No build instructions, no CMakeLists.txt, no documentation beyond a one-line README. The code appears to be adapted from an existing plugin with minimal modification, so there is no guarantee it handles edge cases in either protocol correctly. DNP3 and IEC 104 have evolved and this will likely not work against modern implementations without patching.

View on GitHub →

// want more like this?

We dig through GitHub every week and send a few repos picked for what you actually care about — each with an honest take like this one.

Get finds in your inbox → Search again →