Skip to main content

Application Note: ProSave Security Backdoor? Access HMI Settings without Password?

You can read this post on LinkedIn as well.

Introduction:

ProSave is a powerful software tool developed by SIEMENS. It's designed to streamline data management tasks for Siemens S7-1200 and S7-1500 series PLCs. It also communicates with SIMATIC HMI devices. ProSave provides backup, restore, and data transfer operations so that we can use ProSave for project management and ensure system reliability.

Join me as we uncover the power of backups, explore the realm of password-protected projects, and uncover a surprising discovery that may leave you running to check your devices.

Section 1: Backups for Peace of Mind

In the vast landscape of ProSave, we encounter a crucial feature that stands tall—the ability to generate backups of PLC/HMI projects. These backups serve as a safety net, offering swift restoration in the face of PLC/HMI failures or during project migrations. Whether you seek to safeguard the entire project or specific components such as hardware configurations, user programs, or data blocks, ProSave's backup capabilities ensure peace of mind in the realm of automation.

Section 2: The Mighty Password Protection

Security and integrity of sensitive data are paramount concerns in the world of automation. Enter ProSave's support for password-protected projects—a formidable shield against unauthorized access. Picture this: when backing up a password-protected project, ProSave presents a challenge—a prompt demanding the correct password. Only with the key to unlocking the gates can one gain authorized access for backup purposes. A tantalizing dance of security and confidentiality unfolds, where a single incorrect password sends even an HMI like KTP400 Basic into silence, refusing to reveal if the path taken is right or wrong.

Section 3: A Crack in the Armor

Amidst the quest for robust security, a discovery awaits—a crack in the armor of protection. Imagine this scenario: a repaired KTP400 Basic HMI with a new touch panel and buttons. As the Ethernet cable establishes the connection between laptop and device, ProSave springs into action. But behold! A previously hidden door swings open—the Setting page reveals itself, extending a friendly greeting to the curious observer. Though modifications to the project file remain out of reach, a spare HMI can now be crafted without the intervention of vendors and their lofty price tags. A double-edged sword it may be, for while company coffers may rejoice, vendors find their revenue streams disrupted.

Section 4: Hammer the Cracking Armor

Here are two notes for you to break the shield.

  1. If you don't know the IP address, you can use TIA Portal to check it out. Simply open TIA Portal and click Accessible Devices. You can see the device type and its IP address even though it's not on the same network as your laptop. You can also use IP scanning software to see what other devices are on the network if your laptop's connection goes through a switch instead of directly to the RJ45 port on your target device.
  2. You can find a set of touch panel and buttons on eBay for a fraction of a new HMI's cost. And it's much cheaper to send it back to SIEMENS for repair. For example, a new KTP400 Basic HMI is around $450. For SIEMENS's repair service, it's $300+, and it'll be shipped to China for repair and then back to the United States. I wasn't surprised that SIEMENS recommend I buy a new device. However, a set of touch panel and buttons on eBay only cost around $40. Why not do it yourself though your manager may not appreciate it?

Even though I can't modify the project file, a spare HMI can now be made without involving a vendor and their overpriced quote! And as always, it's a two-sided sword. On the bright side, we can save money for our company when we build up our inventory. On the dark side, the vendor can't rely on selling spare parts for revenue.

Conclusion:

In the realm of ProSave, we have explored the power of backups, the fortress of password protection, and a surprising crack in the security armor. As we conclude this journey, let us remember that the tests conducted are but a limited glimpse into the vast landscape of HMI devices provided by SIEMENS. The author stands firm in the stance of upholding Intellectual Property Rights and does not endorse or encourage any actions that breach these rights.

May ProSave be your steadfast companion in project management, may your backups be reliable, and may your ethical compass guide you through the intricate dance of convenience and security.

Comments

Popular posts from this blog

[申辦綠卡] EB-2 NIW 國家利益豁免綠卡申請教學(一)找合作的律師事務所

Image by  David Peterson  from  Pixabay

[申辦綠卡] EB-2 NIW 國家利益豁免綠卡申請教學(零)名詞解釋 Petitioner vs Applicant

Image by  David Peterson  from  Pixabay

[申辦綠卡] EB-2 NIW 國家利益豁免綠卡申請教學(二)閱讀官方申請條件—1

Image by  David Peterson  from  Pixabay