Luigi Auriemma

aluigi.org (ARCHIVE-ONLY FORUM!)
It is currently 19 Jul 2012 14:23

All times are UTC [ DST ]





Forum locked This topic is locked, you cannot edit posts or make further replies.  [ 2 posts ] 
Author Message
 Post subject: Shame on ICS-CERT, SCADA and their advertisements
PostPosted: 07 Apr 2011 17:34 

Joined: 13 Aug 2007 21:44
Posts: 4068
Location: http://aluigi.org
if you find a vulnerability in a SCADA software and release it in full-disclosure (full details and proof-of-concept) the ICS-CERT will NOT credit you.
I mean just no name and even no links to your informations, doesn't matter if your report contains important details.

this is one of their rules and it's confirmed also by the mail I received from them:
Quote:
If a researcher simply publishes a vulnerability without coordinating with
the vendor and/or a CERT, then ICS-CERT will not credit a researcher by
name. If a researcher does coordinates the vulnerability prior to a public
disclosure, then ICS-CERT will provide attribution to the original
researcher.
I think it's an idiocy because for a vendor a public vulnerability is a service he gets for free and is for sure better than leaving the vulnerabilities undisclosed/unpatched anyway if it's their rule I can say nothing, it's ok.

or at least it's ok till they release one of their so called advisories in which they make a complete free advertisement to a company that sells some small SCADA bugs:
http://www.us-cert.gov/control_systems/ ... 096-01.pdf
http://www.us-cert.gov/control_systems/ ... il2011.pdf

the "ironic" thing is that my full name is there because it's part of the announcement/advertisement of that company... shame.

basicly if you find vulnerabilities in the software that the same ICS-CERT defines as critical and important (personally for me SCADA is just like a game or a media player or a Microsoft server, nothing else) and you sell it in the so called "black market" to people usually with bad intentions then you will credited on their website.

at the same time the usual "idiot" who reveals the vulnerability for free and to anyone (vendor included) will be simply tagged as a nameless "independent researcher":
http://www.us-cert.gov/control_systems/ ... 91-01A.pdf
http://www.us-cert.gov/control_systems/ ... 091-01.pdf
http://www.us-cert.gov/control_systems/ ... 080-01.pdf
http://www.us-cert.gov/control_systems/ ... 080-02.pdf
http://www.us-cert.gov/control_systems/ ... 080-03.pdf
http://www.us-cert.gov/control_systems/ ... 080-04.pdf
http://www.us-cert.gov/control_systems/ ... 48-01A.pdf
http://www.us-cert.gov/control_systems/ ... versal.pdf
http://www.us-cert.gov/control_systems/ ... 355-01.pdf
http://www.us-cert.gov/control_systems/ ... 348-01.pdf
http://www.us-cert.gov/control_systems/ ... 313-01.pdf
http://www.us-cert.gov/control_systems/ ... 305-01.pdf

try to guess who is that "indipendent researcher" there :)
not that I care much but my intention is to highlight a behaviour that I find completely senseless and even unethical.

the only lucky thing about their advertisement is that the so called zero days that are sold from that company are only some Denial of Service bugs in some less known softwares so just nothing to care.


Top
 Profile  
 
 
 Post subject: Re: Shame on ICS-CERT, SCADA and their advertisements
PostPosted: 09 May 2011 03:12 

Joined: 27 Apr 2011 18:44
Posts: 47
Sometimes the COMMON sense is the less COMMON on the people.

It's a shame!


Top
 Profile  
 
Display posts from previous:  Sort by  
Forum locked This topic is locked, you cannot edit posts or make further replies.  [ 2 posts ] 

All times are UTC [ DST ]


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for: