New User, Welcome!     Login

governmental agencies

C4 Security Advisory - GE Fanuc Cimplicity 6.1 Heap Overflow

 
Additional Information
-------------------------------
For additional information please contact us at info@c4-security.com. Note
that we will respond only to verified utility personnel and governmental
agencies.
The CVE identifier assigned to this vulnerability by CERT is CVE-2008-0176
 
Credit
--------
This vulnerability was discovered and exploited by Gilad Bakas and Eyal

=?us-ascii?Q?C4_SCADA_Security_Advisory_-_AREVA_e-terrahabitat_/_e-terrap?= =?us-ascii?Q?latform_Multiple_Vulnerabilities?=

Additional Information
-------------------------------
For additional information please contact us at info_at_c4-security.com.
Note that we will respond only to verified utility personnel and
governmental agencies. 
Details of this vulnerability will be disclosed only to legitimate parties
such as asset owners (utilities), after receiving the approval of the local
CERT or any other local official entity.

The CVE identifiers assigned to these vulnerabilities by CERT are: 

C4 Security Advisory - GE Fanuc Proficy Information Portal 2.6 Authentication Vulnerability

 
Additional Information
-------------------------------
For additional information please contact us at info@c4-security.com. Note
that we will respond only to verified utility personnel and governmental
agencies.
The CVE identifier assigned to this vulnerability by CERT is CVE-2008-0174
 
Credit
---------
This vulnerability was discovered by Eyal Udassin of C4.

C4 Security Advisory - GE Fanuc Proficy Information Portal 2.6 Arbitrary File Upload and Execution

 
Additional Information
-------------------------------
For additional information please contact us at info@c4-security.com. Note
that we will respond only to verified utility personnel and governmental
agencies.
The CVE identifier assigned to this vulnerability by CERT is CVE-2008-0175
 
Credit
--------
This vulnerability was discovered and exploited by Eyal Udassin of C4.

Re: Cryptome: NSA has real-time access to Hushmail servers

> On Sat, 22 Dec 2007 14:02:18 +0200, Juha-Matti Laurio said:
>> Guardster Team has posted its response on 21st Dec to Cryptome:
>
>> "We can assure you that we do not cooperate with the NSA or any other
>> government agency anywhere in the world. We invite whomever is  
>> making this
>> statement to provide proof, rather than making a baseless accusation.
>
> Note that if they had been served with an NSL (National Security  
> Letter),

=?us-ascii?Q?C4_SCADA_Security_Advisory_-_Rockwell_Automation_=28Allen_Br?= =?us-ascii?Q?adley=29_Multiple_Vulnerabilities_in_Micrologix_1100_&_1400_?= =?us-ascii?Q?Series_Controllers?=

Additional Information
-------------------------------
For additional information please contact us at info_at_c4-security.com.
Note that we will respond only to verified utility personnel and
governmental agencies. Details of this vulnerability will be disclosed only
to legitimate parties such as asset owners (utilities), after receiving the
approval of the local CERT or any other local official entity.

The CVE identifier assigned to this vulnerability by CERT is CVE-2009-3739


=?us-ascii?Q?C4_SCADA_Security_Advisory_-_OSISoft_PI_Server_Authenticatio?= =?us-ascii?Q?n_Weakness?=

Additional Information
-------------------------------
For additional information please contact us at info_at_c4-security.com.
Note that we will respond only to verified utility personnel and
governmental agencies. 
Details of this vulnerability will be disclosed only to legitimate parties
such as asset owners (utilities), after receiving the approval of the local
CERT or any other local official entity.

The CVE identifier assigned to this vulnerability by CERT is CVE-2009-209.

RE: Cryptome: NSA has real-time access to Hushmail servers

On Dec 26, 2007 1:33 PM,  <Valdis.Kletnieks@vt.edu> wrote:
> On Sat, 22 Dec 2007 14:02:18 +0200, Juha-Matti Laurio said:
> > Guardster Team has posted its response on 21st Dec to Cryptome:
>
> > "We can assure you that we do not cooperate with the NSA or any other
> > government agency anywhere in the world. We invite whomever is making this
> > statement to provide proof, rather than making a baseless accusation.
>
> Note that if they had been served with an NSL (National Security Letter),
> they may be legally *required* to lie about it while cooperating.  Actually
> truthfully saying "Yeah, an NSL showed up and we complied" could land them

Re: Cryptome: NSA has real-time access to Hushmail servers

On Sat, 22 Dec 2007 14:02:18 +0200, Juha-Matti Laurio said:
> Guardster Team has posted its response on 21st Dec to Cryptome:

> "We can assure you that we do not cooperate with the NSA or any other
> government agency anywhere in the world. We invite whomever is making this
> statement to provide proof, rather than making a baseless accusation.

Note that if they had been served with an NSL (National Security Letter),
they may be legally *required* to lie about it while cooperating.  Actually
truthfully saying "Yeah, an NSL showed up and we complied" could land them

Re: Cryptome: NSA has real-time access to Hushmail servers

On Dec 26, 2007 1:33 PM,  <Valdis.Kletnieks@vt.edu> wrote:
> On Sat, 22 Dec 2007 14:02:18 +0200, Juha-Matti Laurio said:
> > Guardster Team has posted its response on 21st Dec to Cryptome:
>
> > "We can assure you that we do not cooperate with the NSA or any other
> > government agency anywhere in the world. We invite whomever is making this
> > statement to provide proof, rather than making a baseless accusation.
>
> Note that if they had been served with an NSL (National Security Letter),
> they may be legally *required* to lie about it while cooperating.  Actually
> truthfully saying "Yeah, an NSL showed up and we complied" could land them

RE: Cryptome: NSA has real-time access to Hushmail servers

Guardster Team has posted its response on 21st Dec to Cryptome:

"We can assure you that we do not cooperate with the NSA or any other government agency anywhere in the world. We invite whomever is making this statement to provide proof, rather than making a baseless accusation.
…."

Link:
http://cryptome.org/nsa-ssl-email.htm

My SecuriTeam Blogs post has been updated to include this information too.


C4 Security Advisory - ABB PCU400 4.4-4.6 Remote Buffer Overflow

 
Additional Information
-------------------------------
For additional information please contact us at info_at_c4-security.com. 
Note that we will respond only to verified utility personnel and governmental agencies.
The CVE identifier assigned to this vulnerability by CERT is CVE-2008-2474

 
Credit
--------

RE: Cryptome: NSA has real-time access to Hushmail servers

Hushmail Team has posted its response on 29th Dec to Cryptome:

"Hush Communications Corporation, the company that provides the Hushmail.com email service, is not owned, wholly or in part, by any government agency."

Response from Safe-mail.net Team is the following:

"1. We never had any contacts, direct or indirect, with the NSA or any other
government agency anywhere in the world.
2. All software we use is in-house development.
3. We have never shared our technology with any other party."



Copyright © 1995-2012 LinuxRocket.net. All rights reserved.

Nearly all of LinuxRocket's features are free. Be kind and donate to the cause!