Interesting related story from July 2012: http://www.washingtonpost.com/investigations/tridiums-niagar... “We’re not going to say Niagara is secure” What I find most worrisome about this is that it can enable attackers to access internal video feeds. Seems like an excellent vector to grab someone's credentials. Also, ironically, one of the people mentioned in the WaPo article who discovered these vulnerabilities used…
Hacking Google's HVAC Systems
11–20 of 46 posts
Re: Hacking Google's HVAC Systems
#12Interesting related story from July 2012: http://www.washingtonpost.com/investigations/tridiums-niagar... “We’re not going to say Niagara is secure” What I find most worrisome about this is that it can enable attackers to access internal video feeds. Seems like an excellent vector to grab someone's credentials. Also, ironically, one of the people mentioned in the WaPo article who discovered these vulnerabilities used…
That same guy [Billy Rios] is the one who wrote the blog post.
Re: Hacking Google's HVAC Systems
#13You certainly see lots of examples of lawsuits over changing numbers in URLs, so you'd figure downloading configuration info from a machine and then reversing a password would definitely provide grounds for a suit.
Nice to see Google not overreact here.
Re: Hacking Google's HVAC Systems
#14Re: Hacking Google's HVAC Systems
#15Re: Hacking Google's HVAC Systems
#16Earlier quoted context omitted.
It's not in scope, because it's not a "Google operated web service." http://www.google.com/about/appsecurity/reward-program/ (I work for Google.)
And potentially shutting down the HVAC for the web servers has no relation?
Re: Hacking Google's HVAC Systems
#17Re: Hacking Google's HVAC Systems
#18Re: Hacking Google's HVAC Systems
#19Earlier quoted context omitted.
It's not in scope, because it's not a "Google operated web service." http://www.google.com/about/appsecurity/reward-program/ (I work for Google.)
And potentially shutting down the HVAC for the web servers has no relation?
Re: Hacking Google's HVAC Systems
#20I'm impressed that they had the balls to actively compromise the device before reporting it to Google... under normal circumstances, wouldn't most companies go after you in court for a CFAA violation or somesuch? You certainly see lots of examples of lawsuits over changing numbers in URLs, so you'd figure downloading configuration info from a machine and then reversing a password would definitely provide grounds for…
He worked there for almost 3 years: http://www.linkedin.com/pub/billy-rios/3/a7a/5b1
Before that, he was recognized for "ongoing and sustained contribution to the security of Google's applications": http://www.google.com/about/appsecurity/hall-of-fame/archive...