Re: [Full-disclosure] Florida Power Light Company (FPL) Fort Sumner Wind turbine Control SCADA was HACKED

2011-04-19 Thread satyam pujari
(FPL) Fort Sumner Wind turbine Control SCADA was HACKED To: full-disclosure@lists.grok.org.uk Date: Monday, April 18, 2011, 12:31 PM Anyone checked this ? http://reversemode.com/index.php?option=com_contenttask=viewid=74Itemid=1 Regards, Satyamhax http://esploit.blogspot.com/ On Mon

Re: [Full-disclosure] Florida Power Light Company (FPL) Fort Sumner Wind turbine Control SCADA was HACKED

2011-04-19 Thread Cal Leeming
wrote: From: satyam pujari satyam...@gmail.com Subject: Re: [Full-disclosure] Florida Power Light Company (FPL) Fort Sumner Wind turbine Control SCADA was HACKED To: full-disclosure@lists.grok.org.uk Date: Monday, April 18, 2011, 12:31 PM Anyone checked this ? http

Re: [Full-disclosure] Florida Power Light Company (FPL) Fort Sumner Wind turbine Control SCADA was HACKED

2011-04-19 Thread Paul Schmehl
the incident and make it fake. --- On Mon, 4/18/11, satyam pujari satyam...@gmail.com wrote: From: satyam pujari satyam...@gmail.com Subject: Re: [Full-disclosure] Florida Power Light Company (FPL) Fort Sumner Wind turbine Control SCADA was HACKED To: full-disclosure@lists.grok.org.uk Date

Re: [Full-disclosure] Florida Power Light Company (FPL) Fort Sumner Wind turbine Control SCADA was HACKED

2011-04-18 Thread Cal Leeming
On Sun, Apr 17, 2011 at 3:39 PM, valdis.kletni...@vt.edu wrote: On Sat, 16 Apr 2011 08:22:42 PDT, Bgr R said: http://img24.imageshack.us/i/58868342.png/ Wow, some of those wires look very MS-Paint-y. :) OrgName: Florida Power Light Company Configuration file from the central Cisco

Re: [Full-disclosure] Florida Power Light Company (FPL) Fort Sumner Wind turbine Control SCADA was HACKED

2011-04-18 Thread Patrick R
He is crazy. BTW I checked, the BUG in FLP is real. Check it out: try cisco:cisco on 1) 161.154.232.2 (external FLP IP) 2) 65.14.117.30 (ISP alias) interface Vlan1578  ip address 65.14.117.30 255.255.255.252  load-interval 30  no clns route-cache Seems to be that after it he targeted on SCADA

Re: [Full-disclosure] Florida Power Light Company (FPL) Fort Sumner Wind turbine Control SCADA was HACKED

2011-04-18 Thread satyam pujari
Anyone checked this ? http://reversemode.com/index.php?option=com_contenttask=viewid=74Itemid=1 Regards, Satyamhax http://esploit.blogspot.com/ On Mon, Apr 18, 2011 at 1:24 AM, Patrick R patrick...@yahoo.com wrote: He is crazy. BTW I checked, the BUG in FLP is real. Check it out: try

Re: [Full-disclosure] Florida Power Light Company (FPL) Fort Sumner Wind turbine Control SCADA was HACKED

2011-04-18 Thread Cal Leeming
On Sun, Apr 17, 2011 at 8:54 PM, Patrick R patrick...@yahoo.com wrote: He is crazy. BTW I checked, the BUG in FLP is real. Check it out: try cisco:cisco on Oh sht, the feds are getting reallly clever :L 1) 161.154.232.2 (external FLP IP) 2) 65.14.117.30 (ISP alias)

[Full-disclosure] Florida Power Light Company (FPL) Fort Sumner Wind turbine Control SCADA was HACKED

2011-04-17 Thread Bgr R
Here comes my revenge for illegitimate firing from Florida Power Light Company (FPL)    ... ain't nothing you can do with it, since your electricity is turned off !!! Secure you SCADA better! Leaked files are attached ... 1) http://img838.imageshack.us/i/49986845.png/ 2)

Re: [Full-disclosure] Florida Power Light Company (FPL) Fort Sumner Wind turbine Control SCADA was HACKED

2011-04-17 Thread Benji
so how long do you give yourself before you're in prison? On Sat, Apr 16, 2011 at 4:22 PM, Bgr R bgr_24...@yahoo.com wrote: Here comes my revenge for illegitimate firing from Florida Power Light Company (FPL) ... ain't nothing you can do with it, since your electricity is turned off !!!

Re: [Full-disclosure] Florida Power Light Company (FPL) Fort Sumner Wind turbine Control SCADA was HACKED

2011-04-17 Thread Jeffrey Walton
so how long do you give yourself before you're in prison? lol To pay devil's advocate here: FPL placed those hosts on a public internet. In addition, FPL also configured the hosts to advertise services. If FPL did not want the services accessed, the company would have removed the hosts from

Re: [Full-disclosure] Florida Power Light Company (FPL) Fort Sumner Wind turbine Control SCADA was HACKED

2011-04-17 Thread Benji
so wait? Let me humor you.. SSH was running and publically accessible so it was actually legal for me to login to something,gov, as if they didnt want me to connect it wouldnt be a publically accessible service? On Sun, Apr 17, 2011 at 12:39 PM, Jeffrey Walton noloa...@gmail.com wrote: so

Re: [Full-disclosure] Florida Power Light Company (FPL) Fort Sumner Wind turbine Control SCADA was HACKED

2011-04-17 Thread Benji
Interesting, as @reversemode on twitter has pointed out 74.50.135.51 is the ip for the scada system as pointed out, and found by SHODAN http://www.shodanhq.com/?q=Ft.+Sumner+SCADA Not the 160.x.x.x IP as indicated in the original email. On Sun, Apr 17, 2011 at 12:41 PM, Benji m...@b3nji.com

Re: [Full-disclosure] Florida Power Light Company (FPL) Fort Sumner Wind turbine Control SCADA was HACKED

2011-04-17 Thread Benji
Before you blindly emailed, it may have helped to have looked. Hes found that the 'screenshots provided have merely just been lifted out of pdfs. On 4/17/11, andrew.wallace andrew.wall...@rocketmail.com wrote: Just phone up FPL and ask if they've been hacked, instead of pissing around on

Re: [Full-disclosure] Florida Power Light Company (FPL) Fort Sumner Wind turbine Control SCADA was HACKED

2011-04-17 Thread Valdis . Kletnieks
On Sat, 16 Apr 2011 08:22:42 PDT, Bgr R said: http://img24.imageshack.us/i/58868342.png/ Wow, some of those wires look very MS-Paint-y. :) OrgName: Florida Power Light Company Configuration file from the central Cisco Router and Security Device Manager: 161.154.232.2 (FPL - FFPL-1) No

Re: [Full-disclosure] Florida Power Light Company (FPL) Fort Sumner Wind turbine Control SCADA was HACKED

2011-04-17 Thread Valdis . Kletnieks
On Sun, 17 Apr 2011 07:39:58 EDT, Jeffrey Walton said: To pay devil's advocate here: FPL placed those hosts on a public internet. In addition, FPL also configured the hosts to advertise services. If FPL did not want the services accessed, the company would have removed the hosts from the

Re: [Full-disclosure] Florida Power Light Company (FPL) Fort Sumner Wind turbine Control SCADA was HACKED

2011-04-17 Thread kite...@kitetoa.com
depends on the country and how you got into the house : http://www.zdnet.fr/actualites/affaire-kitetoa-le-parquet-general-defend-une-jurisprudence-favorable-aux-internautes-2123657.htm Best regards, K. valdis.kletni...@vt.edu a écrit : You're welcome to go ahead and break into a house, and

Re: [Full-disclosure] Florida Power Light Company (FPL) Fort Sumner Wind turbine Control SCADA was HACKED

2011-04-17 Thread Cal Leeming
So hold on.. the person who did this, was an ex-employee who already had access to their systems? On Sun, Apr 17, 2011 at 2:28 PM, Benji m...@b3nji.com wrote: Interesting, as @reversemode on twitter has pointed out 74.50.135.51 is the ip for the scada system as pointed out, and found by

Re: [Full-disclosure] Florida Power Light Company (FPL) Fort Sumner Wind turbine Control SCADA was HACKED

2011-04-17 Thread Thor (Hammer of God)
Oh, and many of the statutes *do not* include intent in them.  So whether you're a black hat doing something evil, or a white hat investigating so you can tell them they have a problem, you're still in trouble. Intent has nothing to do with using public services (I'm not sure how to

Re: [Full-disclosure] Florida Power Light Company (FPL) Fort Sumner Wind turbine Control SCADA was HACKED

2011-04-17 Thread Valdis . Kletnieks
On Sun, 17 Apr 2011 12:36:42 EDT, Jeffrey Walton said: I was thinking more along the lines of an Office Depot, Sports Authority, Verizon Wireless, etc - public businesses which automatically open the sliding glass doors for you. I don't expect these businesses to claim a 'comparison shopper'

Re: [Full-disclosure] Florida Power Light Company (FPL) Fort Sumner Wind turbine Control SCADA was HACKED

2011-04-17 Thread Rob Nelson
Why the hell are we arguing statutes? Look at the big picture: He leaked config files to a system that has access to something in a /nuclear power plant/.  He's going to jail, it's just a matter of time. On Sun, Apr 17, 2011 at 11:55 AM, valdis.kletni...@vt.edu wrote: On Sun, 17 Apr 2011

Re: [Full-disclosure] Florida Power Light Company (FPL) Fort Sumner Wind turbine Control SCADA was HACKED

2011-04-17 Thread Thor (Hammer of God)
Company (FPL) Fort Sumner Wind turbine Control SCADA was HACKED Why the hell are we arguing statutes? Look at the big picture: He leaked config files to a system that has access to something in a /nuclear power plant/.  He's going to jail, it's just a matter of time

Re: [Full-disclosure] Florida Power Light Company (FPL) Fort Sumner Wind turbine Control SCADA was HACKED

2011-04-17 Thread Thor (Hammer of God)
-Original Message- From: full-disclosure-boun...@lists.grok.org.uk [mailto:full-disclosure- boun...@lists.grok.org.uk] On Behalf Of Rob Nelson Sent: Sunday, April 17, 2011 12:05 PM To: full-disclosure@lists.grok.org.uk Subject: Re: [Full-disclosure] Florida Power Light Company (FPL

Re: [Full-disclosure] Florida Power Light Company (FPL) Fort Sumner Wind turbine Control SCADA was HACKED

2011-04-17 Thread Thor (Hammer of God)
; Jeffrey Walton; valdis.kletni...@vt.edu; kite...@kitetoa.com; Thor (Hammer of God); Rob Nelson Subject: Re: [Full-disclosure] Florida Power Light Company (FPL) Fort Sumner Wind turbine Control SCADA was HACKED On Sun, Apr 17, 2011 at 2:35 PM, Cal Leeming c...@foxwhisper.co.ukmailto:c

Re: [Full-disclosure] Florida Power Light Company (FPL) Fort Sumner Wind turbine Control SCADA was HACKED

2011-04-17 Thread Christian Sciberras
(FPL) Fort Sumner Wind turbine Control SCADA was HACKED On Sun, Apr 17, 2011 at 2:35 PM, Cal Leeming c...@foxwhisper.co.uk wrote: So hold on.. the person who did this, was an ex-employee who already had access to their systems? Nothing illegal has happened then, the dude is just