Showing posts with label Vulnerabilities. Show all posts
Showing posts with label Vulnerabilities. Show all posts

Thursday, November 14, 2019

Malign Machine Learning Models and bad DICOM

Zeronighs 2019 AISec releases: how to insert malware into TensorFlow and PyTorch models and hack NVIDIA Clara ML pipeline with DICOM image.


Thursday, October 10, 2019

DICOM to passwd. On security of ML pipelines

Machine Learning and Artificial Intelligence Pipelines are very useful tools. They help to concentrate on specific task without digging into implementation details. However, from design and security perspective these things are like Frankenstein.

Here is  an example


Wednesday, September 11, 2019

Silverpeak SD-WAN +7 CVE

Fixed (?) published. Kudos SD-WAN New Hop team: Sergey Gordeychick, Denis Kolegov, Maxim Gorbunov, Nikolay Tkachenko, Nikita Oleksov, Oleg Broslavsky, Antony Nikolaev

Saturday, December 29, 2018

35C3 talk and metasploit releases

Refreshing memories of Chaos Communication Congress SD-WAN New Hop talk.

35C3 talk video and exploits for SD-WAN.

Citrix Netscaler SD-WAN #metasploit module. Remote command execution -> root.

Wednesday, November 7, 2018

Citrix NetScaler SD-WAN vulnerabilities details

On CTX236992, mode details and exploitation vectors by Sergey Gordeychik, Denis Kolegov, Nikita Oleksov, Nikolay Tkachenko, Oleg Broslavsky

Unauthenticated Access to Munin Service
Incorrect Access Controls
Cross-Site Request Forgery
Use of CakePHP Component with Known Vulnerabilities
Cross-Site Scripting(s)
Path Traversal(s)
SQL Injection(s)
Slow HTTP DoS Attacks
Session ID Leakage
Sudo Misconfiguration
OS Command Injection(s)

Friday, August 17, 2018

Silver Peak EdgeConnect < 8.1.7.x. multiple vulnerabilities

On SD-WAN vulnerabilities discussed here.

Silver Peak SD-WAN solutions enable distributed enterprises to build a better WAN, securely connecting users to applications without compromising application performance.

https://www.silver-peak.com/sd-wan

Saturday, October 14, 2017

Hopeless: Relay Protection for Substation Automation

If you need more details on Practical analysis of the cybersecurity of European smart grids, we have a  small present for all Digital Substations, IEC 61850 and Remote Code Execution lovers by Kirill Nesterov @k_v_nesterov and Alexander Tlypov @_Rigmar_


Digital Substation is an essential part of every electrical network. It is also a base ground for modern Smart Grid technologies. More than 4000 of IEC 61850 compatible substations operated in Europe, 20 000+ worldwide, each of the comprising communication and flow of gigawatts of electrical current between large power plants (thermoelectrical, hydroelectrical or even nuclear) and their respective consumers. Such consumers include cities, industrial objects and power plants themselves.

Wednesday, September 20, 2017

Thursday, December 15, 2016

Sunday, December 27, 2015

SCADAPASS #32C3 Release

Special Chaos Communication Congress release.
List of default password for industrial control systems components.

Kudos to  Oxana Andreeva (oxana.andreeva@inbox.ru)

37 vendors.
PLC, RTU, HMI, gateways, switches, servers, wireless ap, etc

Tuesday, December 22, 2015

Now Declared Capabilities

Neat FAQ about hardcoded password in Siemens SIPROTEC 4 protective relay.

"SIPROTEC 4 and SIPROTEC Compact devices allow the display of extended internal statistics and test information... 

Thursday, August 6, 2015

SCADA with antenna

Sometimes you can meet a SCADA with antenna.
Sometimes it's a old and boring 802.11 Wi-Fi antenna.
Sometimes it's a cool bright new 3G/4G device.


Monday, May 18, 2015

Friends don't let friends put SCADA on the Internet

New analytic research on ICS components vulnerabilities.

146 137 are online, (at least) 15000 can be hacked by script-kiddie.

Pictures below


Tuesday, May 5, 2015

More news from nowhere

Fixes for Inductive Automation Ignition 7.7.2. Bugs by Evgeny Druzhinin, Alexey Osipov, Ilya Karpov, and Gleb Gritsai. Simple bugs, simple list.
CVE-2015-0976
CVE-2015-0991
CVE-2015-0992
CVE-2015-0993
CVE-2015-0994
CVE-2015-0995

Now or never. CIA vs Schneider Electric

Few bugs in InduSoft Web Studio and InTouch Machine Edition 2014 recently fixed by Schneider Electric were discovered during PHDays Critical Infrastructure Attack challenge. Kudos @alisaesage. For bless you.

Absolutely old-school-community-drive-responsible-disclosure in action. Many emotions left behind..

Enjoy