This document discusses exploiting vulnerabilities in Siemens Simatic S7 programmable logic controllers (PLCs). It describes how PLCs have evolved to use open communication protocols like PROFINET over Ethernet without sufficient security. The document demonstrates how an attacker could perform reconnaissance against PLCs using Metasploit and custom modules to run replay attacks, memory dumps, and other exploits remotely. It stresses the need for vendors and researchers to work together to promote responsible vulnerability disclosure and mitigation.