Welcome to DU! The truly grassroots left-of-center political community where regular people, not algorithms, drive the discussions and set the standards. Join the community: Create a free account Support DU (and get rid of ads!): Become a Star Member Latest Breaking News General Discussion The DU Lounge All Forums Issue Forums Culture Forums Alliance Forums Region Forums Support Forums Help & Search
 

HoneyBadger

(2,297 posts)
20. Definitely queen geek
Sat Dec 31, 2016, 11:29 AM
Dec 2016
http://blog.ptsecurity.com/2015/05/schneider-electric-thanks-winner-of.html

Schneider Electric Thanks the Winner of the Positive Hack Days Hacker Contest

Early April, Schneider Electric has released several updates and patches fixing vulnerabilities in the software used for creating SCADA and HMI systems at nuclear power plants, chemical plants and other critical units.

The vulnerabilities which even a novice attacker could exploit were found in InduSoft Web Studio 7.1.3.2, InTouch Machine Edition 2014 7.1.3.2 as well as previous versions of these products. Among bugs fixed — arbitrary code execution and non-encrypted storage/transfer of sensitive data. The vendor recommends downloading the new patches as soon as possible.

Ilya Karpov and Kirill Nesterov, Positive Technologies researchers, detected the vulnerabilities during an ICS security analysis. Meanwhile, many bugs in those products were independently revealed by the participants of the Critical Infrastructure Attack contest held in May 2014 at the international infosec conference Positive Hack Days IV.

Schneider Electric thanked the contest winner, Alisa Shevchenko (Esage Lab), for the vulnerabilities she identified.

The first PHDays contest in analyzing ICS security was held in 2013 when security experts at Positive Technologies laboratory developed a railway model, whose components (trains, railroad crossing gates, and cranes) were controlled by an ICS based on three real SCADA systems and three industrial controllers.

In 2014, the contest infrastructure was significantly changed to allow detection of zero-day vulnerabilities within a wider range of systems and industrial protocols including: transport, city lighting system, power plants and various robots.



In the competition scenario, SCADA systems and controllers are used at critical installations within various industries. If exploited in a real life situation, these vulnerabilities could have very serious consequences. According to the responsible disclosure policy, Critical Infrastructure Attack contestants must notify respective vendors about vulnerabilities they detected. Details about the vulnerabilities are available upon the fixes being disclosed by the vendor.

They're ignoring it because they either knew about or were on on it Chasstev365 Dec 2016 #1
Yes! They are guilty of something! Connected to the whole she-bang! Madam45for2923 Dec 2016 #22
The geeks disagree HoneyBadger Dec 2016 #2
hmmm, that's too bad Fast Walker 52 Dec 2016 #7
Yes-- it's always a matter of cui bono ailsagirl Dec 2016 #19
The geeks are either CT peddlers meow2u3 Dec 2016 #8
SOME geeks disagree unc70 Dec 2016 #10
thanks for that perspective... personally, I have no clue how to evaluate this stuff Fast Walker 52 Dec 2016 #23
+1 uponit7771 Dec 2016 #33
Internet geeks vs. the CIA and FBI. hadEnuf Dec 2016 #12
Even the banned geeks disagree HoneyBadger Dec 2016 #17
Definitely queen geek HoneyBadger Dec 2016 #20
link is here Fast Walker 52 Dec 2016 #25
This is when we need Lisbeth Salander. pangaia Dec 2016 #35
This is false on its face, .. that's like saying climate scientist disagree... SOME climate scientis uponit7771 Dec 2016 #32
'scientists' also say climate change is a hoax nini Jan 2017 #39
He should be slamming greenwald, tucker, and taibbi, too.. for enabling Cha Dec 2016 #3
Ugh! Tucker Carlson. So hate that guy. Backpfeifengesicht! smirkymonkey Dec 2016 #9
Tucker wearing a grown-up tie? Must be a photo-shop... Thor_MN Dec 2016 #13
Ugh, Greenwald is on my shit list permanently now Fast Walker 52 Dec 2016 #24
Sure as hell hope the intelligence agencies aren't shackled democratisphere Dec 2016 #4
But.. but.. but.. emails! Amimnoch Dec 2016 #5
IOKIYAR pbrower2a Dec 2016 #18
M$Greedia is calling it malaise Dec 2016 #6
I know, right! Equinox Moon Dec 2016 #14
Has Obama changed his position? Buckeye_Democrat Dec 2016 #11
"the same sort of evidence they send people to jail on." panader0 Dec 2016 #15
a herd of idiots come to Donnie's defense Angry Dragon Dec 2016 #16
"Deplorables" to the rescue! pbrower2a Dec 2016 #21
He basically followed Hitler's playbook! n/t RKP5637 Dec 2016 #26
A herd of millions. FFS, where do we live now. I expect Alex Jones to soon be the lead on Fox News, RKP5637 Dec 2016 #27
Deep breath and have Good start to the New Year Angry Dragon Dec 2016 #28
... RKP5637 Dec 2016 #29
Fucking CNN triron Dec 2016 #30
This link has nothing to do with this hack, but everything to do with the hackers HoneyBadger Dec 2016 #31
See Putin's yooooge party tonight to celebrate putting his lackey Trump in the WH. keithbvadu2 Dec 2016 #34
The Republicans Will Sweep this Under the Rug dlk Dec 2016 #36
Will it do any good to bucolic_frolic Dec 2016 #37
But Trump says it's a 400-pound guy lying in his bed. tclambert Jan 2017 #38
"It's forensics. It's computer DNA." AmericanActivist Jan 2017 #40
Latest Discussions»General Discussion»This is forensic! Its ind...»Reply #20