
Speaking Siemens S7comm: Protocol Mechanics and Security Boundaries
This story was originally published on HackerNoon at: https://hackernoon.com/speaking-siemens-s7comm-protocol-mechanics-and-security-boundaries. A packet-level S7comm security investigation tracing COTP session setup, PDU negotiation, PLC memory access, SZL diagnostics, and state-machine anomalies. Check more stories related to cybersecurity at: https://hackernoon.com/c/cybersecurity. You can also check exclusive content about #cybersecurity, #industrial-control-systems, #ics-security, #ot-security, #plc, #siemens, #network-security, #protocol-security, and more. This story was written by: @404saint. Learn more about this writer by checking @404saint's about page, and for more stories, please visit hackernoon.com. This research takes S7comm from the protocol stack all the way to the wire. Using a custom Python client and a local Snap7 server, I manually constructed and analyzed the communication sequence across TCP/102, TPKT, COTP, and S7comm. The investigation covered COTP session establishment, TSAP handling, S7 PDU negotiation, ReadVar memory enumeration, WriteVar operations, SZL diagnostic queries, CPU control request construction, and deliberate state-machine violations. The lab produced several interesting implementation-level observations. Snap7 accepted an unauthenticated WriteVar operation against the configured DB3 memory area, correctly rejected an out-of-range write, exposed module identification through SZL `0x0011`, and processed a ReadVar request before Setup Communication had occurred. A corresponding pre-Setup WriteVar did not successfully modify memory. The tested CPU control request was also unsupported by the Snap7 implementation, while a controlled 50-session resource-handling experiment left the server available after the connections were released. The research then contrasts these classic S7comm behaviors with the security model found in newer Siemens platforms, including configurable access protection and secure communication mechanisms associated with S7CommPlus-era systems. The important distinction throughout the investigation is between what the protocol permits conceptually, what the Snap7 implementation actually does, and what has been demonstrated on physical Siemens hardware. The experiments establish the first two within the laboratory. They do not automatically generalize to every Siemens PLC or firmware generation. The result is a packet-level view of S7comm as more than TCP/102: a layered communication model where transport establishment, session negotiation, memory services, diagnostics, and state enforcement each expose a different part of the PLC's security boundary.


















