Power plants everywhere...
Showing posts with label energy. Show all posts
Showing posts with label energy. Show all posts
Monday, December 30, 2019
Turbines, Simens, Vulnerabilities, Power
Power plants everywhere...
Thursday, February 15, 2018
GE D60 Line Distance Relay security fixes
Security hardening of network services with encrypted tunnel leads to buffer overflow and remote code execution in D60 Line Distance Relay as reported in security advisory ICSA-18-046-02.
Thursday, February 1, 2018
Saturday, October 14, 2017
Hopeless: Relay Protection for Substation Automation
If you need more details on Practical analysis of the cybersecurity of European smart grids, we have a small present for all Digital Substations, IEC 61850 and Remote Code Execution lovers by Kirill Nesterov @k_v_nesterov and Alexander Tlypov @_Rigmar_
Digital Substation is an essential part of every electrical network. It is also a base ground for modern Smart Grid technologies. More than 4000 of IEC 61850 compatible substations operated in Europe, 20 000+ worldwide, each of the comprising communication and flow of gigawatts of electrical current between large power plants (thermoelectrical, hydroelectrical or even nuclear) and their respective consumers. Such consumers include cities, industrial objects and power plants themselves.
Digital Substation is an essential part of every electrical network. It is also a base ground for modern Smart Grid technologies. More than 4000 of IEC 61850 compatible substations operated in Europe, 20 000+ worldwide, each of the comprising communication and flow of gigawatts of electrical current between large power plants (thermoelectrical, hydroelectrical or even nuclear) and their respective consumers. Such consumers include cities, industrial objects and power plants themselves.
Labels:
digital substation,
energy,
iec-61850,
Releases,
smartgrid,
Vulnerabilities
Location:
Brussels, Belgium
Sunday, February 28, 2016
SCADASOS annual report
SCADASOS, (in)Secure Open SmartGrids, is open initiative to raise awareness on insecurities of SmartGrid, Photovoltaic Power Stations and Wind Farms.
For last year, 80,000+ SmartGrid components reported by SCADASOS were disconnected from the internet.
For last year, 80,000+ SmartGrid components reported by SCADASOS were disconnected from the internet.
Labels:
digital substation,
energy,
Releases,
scadasos,
smartgrid
Location:
Munich, Germany
Sunday, December 27, 2015
SCADAPASS #32C3 Release
Labels:
CCC,
digital substation,
energy,
Releases,
scadapass,
smartgrid,
Vulnerabilities
Location:
Hamburg, Germany
Tuesday, December 22, 2015
Thursday, August 6, 2015
SCADA with antenna
Labels:
3g,
4G,
digital substation,
energy,
Releases,
smartgrid,
Vulnerabilities
Location:
Las Vegas, NV, USA
Tuesday, August 4, 2015
A Few Facts on IEC61850 in China
A Few Facts on IEC61850-based Substation Integration & Automation in China by Mr Jim Y Cai, Dr Gao Xiang and Dr. Jun Zha:
- In 2013, 10 000 substations from 35KV to 10000KV with 100% 61850 based IEDs are in operation
- By the end of 2013, there are 893 fully digital substations with process bus are in operation
See you there http://xcon.xfocus.org/
- In 2013, 10 000 substations from 35KV to 10000KV with 100% 61850 based IEDs are in operation
- By the end of 2013, there are 893 fully digital substations with process bus are in operation
See you there http://xcon.xfocus.org/
Labels:
digital substation,
energy,
iec-61850,
smartgrid,
talks
Location:
Beijing, Beijing, China
Tuesday, May 5, 2015
Now or never. CIA vs Schneider Electric
Few bugs in InduSoft Web Studio and InTouch Machine Edition 2014 recently fixed by Schneider Electric were discovered during PHDays Critical Infrastructure Attack challenge. Kudos @alisaesage. For bless you.
Absolutely old-school-community-drive-responsible-disclosure in action. Many emotions left behind..
Enjoy
Absolutely old-school-community-drive-responsible-disclosure in action. Many emotions left behind..
Enjoy
Monday, February 16, 2015
Tuesday, December 30, 2014
31C3: Too Smart Grid in da Cloud ++
This year we want to discuss Green Energy. Our hackers' vision of Green Energy, SmartGrids and Cloud IoT technology. Our latest research was devoted to the analysis of the architecture and implementation of the most wide spread platforms for wind and solar energy generation which produce many gigawatts of it. It may seem (not) surprising but the systems which manage huge turbine towers and household PhotoVoltaic plants are not only connected to the internet but also prone to many well known vulnerabilities and low-hanging 0-days. Even if these systems cannot be found via Shodan, fancy cloud technologies leave no chances for security.
Location:
Kaprun, Austria
Sunday, December 28, 2014
SOS! Secure Open SmartGrids!
Dear all,
After our 31C3 Too SmartGrid in da Cloud talk we get many questions about Solar and Wind plants vulnerabilities, Internet
connected SmartGrid devices. Guys, sorry, but we don’t know yet.
There are dozens of platforms, hundreds of vendors,
thousands of SmartGrid devices… Millions of them connected to Internet without
any protection. But you can change the situation.
Join our SCADASOS project to make the world safer!
Labels:
digital substation,
energy,
scadasos,
smartgrid
Location:
Hamburg, Germany
Tuesday, December 16, 2014
Well, Honeywell
New knowledge about Honeywell Experion Process Knowledge System. Yes, you must patch it.
Yes, it's all about grep +1 SSRF.
Thanks to Alexander Tlyapov, Gleb Gritsai, Kirill Nesterov, Artem Chaykin and Ilya Karpov
Honeywell advisory/patch:
https://www.honeywellprocess.com/library/support/Public/Documents/ExperionPKS.R311.Server.Patch282.PAR1-2VNCSKZ_SCN.pdf
Sorry for the delay. It can wait.
Yes, it's all about grep +1 SSRF.
Thanks to Alexander Tlyapov, Gleb Gritsai, Kirill Nesterov, Artem Chaykin and Ilya Karpov
Honeywell advisory/patch:
https://www.honeywellprocess.com/library/support/Public/Documents/ExperionPKS.R311.Server.Patch282.PAR1-2VNCSKZ_SCN.pdf
Sorry for the delay. It can wait.
Labels:
digital substation,
energy,
EPK,
honewell,
smartgrid,
Vulnerabilities
Location:
İstanbul, Turkey
Monday, May 26, 2014
Emerson DeltaV Vulnerabilities/Fixes
DeltaV Versions 10.3.1, 11.3, 11.3.1, and 12.3
Can be related to Emerson AMS Device Management version, Emerson AMS Wireless SNAP-ON also.
CVE-2014-2349 - World writable system folder
CVE-2014-2350 - Hardcoded credentials
Please find fixes in KBA NK-1400-0031.
Kudos: Kirill Nesterov, Alexander Tlyapov, Dmitry Nagibin, Alexey Osipov and Timur Yunusov
Emerson has assigned CVSS v2 base score of 2.4; the CVSS vector string is (AV:L/AC:H/Au:S/C:N/I:P/A:P).
Hmmm, 2.4? BTW
Details
Enjoy
Can be related to Emerson AMS Device Management version, Emerson AMS Wireless SNAP-ON also.
CVE-2014-2349 - World writable system folder
CVE-2014-2350 - Hardcoded credentials
Please find fixes in KBA NK-1400-0031.
Kudos: Kirill Nesterov, Alexander Tlyapov, Dmitry Nagibin, Alexey Osipov and Timur Yunusov
Emerson has assigned CVSS v2 base score of 2.4; the CVSS vector string is (AV:L/AC:H/Au:S/C:N/I:P/A:P).
Hmmm, 2.4? BTW
Details
Enjoy
Subscribe to:
Posts (Atom)










.gif)


