Re: [Full-Disclosure] east coast powergrid / SCADA [OT?]

From: Bernie, CTA (cta_at_hcsin.net)
Date: 08/16/03

  • Next message: Jon Hart: "Re: [Full-Disclosure] Execution Flow Control (EFC)"
    To: full-disclosure@lists.netsys.com
    Date: Sat, 16 Aug 2003 16:45:53 -0400
    
    

    The theory that the Blackout event started by power generation
    loss (downed transmission lines) at a Cleveland plant is a
    little better then the lightning bolt Canada theory, but still
    inconsistent with the technical aspects of the Grids automated
    fault protection and power load balancing systems. Unless, of
    course, several other Power Plants and Sub Stations automated
    fault protection and power load balancing systems were taken
    offline, or their power cords cut.

    1. If the components of the protection system were taken offline
    at near the same time, was it in response to the threat of the
    MSBlaster or RPC vulnerability in the OS that runs these
    components? If not, then why did these systems fail to operate?
    Was it human interdiction or error? On the other hand, was it a
    statistically improvable event where these systems all failed
    simultaneously? What were the system security and protection
    engineering team doing since 9/11?

    2. If their cords were cut at the same time, would it then be
    logical to consider the Blackout was a terrorist related planned
    incident? If so, where was the system security and protection
    engineering team since 9/11?

    3. Or, this entire Blackout was do to coincidental and
    simultaneous stresses in the Grids' infrastructure, and
    completely unexpected as the transmission lines and protection
    systems were to old to properly respond. That notion would be
    oxymoronic, lame, and not acceptable especially considering the
    sophistication of these facilities and the recent upgrades made
    to accommodate power line hosted Internet / communications.

    As for the time span 14:06 - 15:21, well that just supports the
    theory that the safeguards did not properly function, option 1,
    or 2. If the time period was say a few seconds then maybe we can
    put some weight into the old and over-stressed technology
    theory.

    On 16 Aug 2003 at 12:08, Geoff Shively wrote:

    > NERC (nerc.com) North American Electric Reliability Council has a
    > hidden report that states at "14:06 Chamberlain - Harding 345 Kv
    > line tripped -- cause not reported". This was the first sign of
    > failure. NE US and Canada did not report significant outages
    > prior to 15:11.
    >
    > Another point to look at is at "15:17 - 15:21 Numerous lines in
    > Michigan tripped"
    >
    > Cheers,
    >
    > Geoff Shively, CHO
    > PivX Solutions, LLC
    >
    > http://www.pivx.com
    >
    > ----- Original Message -----
    > From: "Richard M. Smith" <rms@computerbytesman.com>
    > To: <full-disclosure@lists.netsys.com>
    > Sent: Saturday, August 16, 2003 11:25 AM
    > Subject: RE: [Full-Disclosure] east coast powergrid / SCADA [OT?]
    >
    >
    > > Ground zero for the blackout seems to be Parma, OH according to
    > > local papers and ABC News:
    > >
    > > http://abcnews.go.com/wire/US/ap20030816_755.html
    > >
    > > http://junior.apk.net/~jnoga/F16CAUSE.html
    > >
    > > http://www.toledoblade.com/apps/pbcs.dll/article?AID=/20030816/
    > > NEWS08/10 8160106
    > >
    > > Richard
    > >
    > > -----Original Message-----
    > > From: full-disclosure-admin@lists.netsys.com
    > > [mailto:full-disclosure-admin@lists.netsys.com] On Behalf Of
    > > Bernie, CTA Sent: Saturday, August 16, 2003 1:25 PM To:
    > > full-disclosure@lists.netsys.com Subject: Re: [Full-Disclosure]
    > > east coast powergrid / SCADA [OT?]
    > >
    > > I still feel that there was human intervention to disrupt or
    > > otherwise circumvent the automatic safeguards, in response to
    > > an anomaly (i.e. MSBlaster).
    > >
    > > ....
    > >
    > > _______________________________________________
    > > Full-Disclosure - We believe in it.
    > > Charter: http://lists.netsys.com/full-disclosure-charter.html
    > >
    >
    > _______________________________________________
    > Full-Disclosure - We believe in it.
    > Charter: http://lists.netsys.com/full-disclosure-charter.html
    >

    -
    ****************************************************
    Bernie
    Chief Technology Architect
    Chief Security Officer
    cta@hcsin.net
    Euclidean Systems, Inc.
    *******************************************************
    // "There is no expedient to which a man will not go
    // to avoid the pure labor of honest thinking."
    // Honest thought, the real business capital.
    // Observe> Think> Plan> Think> Do> Think>
    *******************************************************

    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html


  • Next message: Jon Hart: "Re: [Full-Disclosure] Execution Flow Control (EFC)"

    Relevant Pages

    • Animal farm in Mugabeland
      ... HARARE has been recovering this week from a devastating blackout that saw ... It was probably the worst power outage since the Second World War. ... President Mugabe is reelected there will be no balance-of-payments support ... able to comment on the MDC and Gordon Brown? ...
      (soc.culture.zimbabwe)
    • Re: [Full-Disclosure] Al Qaida claims responsibility for blackout
      ... If they are taking responsibility for the power outage then the plant would of definitely exploded. ... > blackout last week in the Northeast and Midwest United States. ... that lightning hit and destroyed the two plants. ...
      (Full-Disclosure)
    • RE: [Full-Disclosure] Al Qaida claims responsibility for blackout
      ... 'Al Qaeda Claims Responsibility For Power Blackout In U.S.!' ... "A communiqué by the Abu Hafs Brigades was published at ... Al-Qa'ida's Abu Hafs Brigades has claimed responsibility for "Operation ... power blackout that happened in the U.S. last Thursday, ...
      (Full-Disclosure)
    • New Zealand storm gives new meaning to all black
      ... Peter Williams in Christchurch ... The city council said more power cuts were possible, ... The blackout in Auckland left business people fuming at the estimated loss ... snow overnight. ...
      (soc.culture.israel)
    • Re: How to PostMortem?
      ... > well they perform for each type of surge. ... "American Power Conversion's Equipment Protection Policy: ... one uses a #12 guage wire less than 5 ...
      (comp.os.linux.setup)