Tuesday, November 18, 2014
BootKit via SMS
Labels:
4G,
pacsec,
Releases,
Vulnerabilities
Location:
Tokyo, Japan
Wednesday, October 29, 2014
Different type of SCADA...
+Update http://blog.ptsecurity.com/2015/01/hacking-atm-with-raspberry-pi.html
Slides and demo from Olga and Alex report on ATM hacking at Black Hat. MS08-067 strikes again. Now ATM.
There are a lot of different kinds of SCADA...
Slides and demo from Olga and Alex report on ATM hacking at Black Hat. MS08-067 strikes again. Now ATM.
There are a lot of different kinds of SCADA...
Labels:
atm,
Releases,
speeches,
Vulnerabilities
Location:
Amsterdam, The Netherlands
Thursday, October 9, 2014
What is my encryption key?
Update for update for WinCC <7.3. Now for Siemens SIMATIC PCS 7 <8.1.
Details: https://ics-cert.us-cert.gov/advisories/ICSA-14-205-02A
Details: https://ics-cert.us-cert.gov/advisories/ICSA-14-205-02A
Monday, September 1, 2014
Few bugs in Wonderware Information Server
Vulnerabilities/fixes in Schneider Electric/Invensys Wonderware Information Server (WIS) to support tradition.
The following Schneider Electric WIS versions are affected:
The following Schneider Electric WIS versions are affected:
- Wonderware Information Server 4.0 SP1 Portal,
- Wonderware Information Server 4.5 Portal,
- Wonderware Information Server 5.0 Portal, and
- Wonderware Information Server 5.5 Portal.
Labels:
Invensys,
Releases,
Schneider Electric,
Vulnerabilities,
Wonderware
Location:
Stockholm, Sweden
Not by SCADA alone: ATM hack @BH Europe
Location:
Amsterdam, The Netherlands
Wednesday, July 23, 2014
Siemens SIMATIC WinCC 7.3: Vulnerabilities/Fixes
New version of WinCC/new features/new advisories/new vulnerabilities. Kudos Gleb Gritsai, Dmitry Nagibin and Alexander Tlyapov .
CVE-2014-4682/HTTP/sensitive data (session) leakage
CVE-2014-4683/HTTP/remote privileges escalation (useful with CVE-2014-4682 and CVE-2013-3958)
CVE-2014-4685/Local/lot of funny stuff with Windows IPC objects
CVE-2014-4686/RPC/hardcoded key in authentication sequence/our new favorite slide
Details in SSA-214365.
CVE-2014-4682/HTTP/sensitive data (session) leakage
CVE-2014-4683/HTTP/remote privileges escalation (useful with CVE-2014-4682 and CVE-2013-3958)
CVE-2014-4685/Local/lot of funny stuff with Windows IPC objects
CVE-2014-4686/RPC/hardcoded key in authentication sequence/our new favorite slide
Details in SSA-214365.
Labels:
Releases,
Siemens,
Vulnerabilities,
WinCC
Location:
Daejeon, South Korea
Tuesday, June 10, 2014
Confidence 2014 slides and releases
Nice update by @atimorin.
Slides and tools:
http://www.slideshare.net/AlexanderTimorin/scada-deep-inside-protocols-and-security-mechanisms
https://github.com/atimorin/scada-tools
Hint from Code Monkey Hate Bug also: https://twitter.com/jadamcrain/status/476098591816450048
Slides and tools:
http://www.slideshare.net/AlexanderTimorin/scada-deep-inside-protocols-and-security-mechanisms
https://github.com/atimorin/scada-tools
Hint from Code Monkey Hate Bug also: https://twitter.com/jadamcrain/status/476098591816450048
Subscribe to:
Posts (Atom)




