Wednesday, October 29, 2014

Different type of SCADA...

Slides and demo from Olga and Alex report on ATM hacking at Black Hat. MS08-067 strikes again. Now ATM.
There are a lot of different kinds of SCADA...


Monday, September 1, 2014

Few bugs in Wonderware Information Server

Vulnerabilities/fixes in Schneider Electric/Invensys Wonderware Information Server (WIS) to support tradition.

The following Schneider Electric WIS versions are affected:

  • Wonderware Information Server 4.0 SP1 Portal,
  • Wonderware Information Server 4.5 Portal,
  • Wonderware Information Server 5.0 Portal, and
  • Wonderware Information Server 5.5 Portal.


Not by SCADA alone: ATM hack @BH Europe

Alexey and Olga gonna speak @BlackHat 2014 EU on ATM security.

Wednesday, July 23, 2014

Siemens SIMATIC WinCC 7.3: Vulnerabilities/Fixes

New version of WinCC/new features/new advisories/new vulnerabilities. Kudos Gleb Gritsai, Dmitry Nagibin and Alexander Tlyapov .

CVE-2014-4682/HTTP/sensitive data (session) leakage
CVE-2014-4683/HTTP/remote privileges escalation (useful with CVE-2014-4682 and CVE-2013-3958)
CVE-2014-4685/Local/lot of funny stuff with Windows IPC objects
CVE-2014-4686/RPC/hardcoded key in authentication sequence/our new favorite slide

Details in SSA-214365.