• XSS.stack #1 – первый литературный журнал от юзеров форума

Selling 0-day from ICS device.

В этой теме можно использовать автоматический гарант!

Статус
Закрыто для дальнейших ответов.

god osiris

HDD-drive
Пользователь
Регистрация
02.09.2023
Сообщения
40
Реакции
3
Selling a 0-day exploit, its about a model device from Accuenergy.
This 0-day can extract log details about voltage, kWh, energy by Consumption/Demand, etc.
Extraction over HTTP.
No password is required.
CVS Score: 10.

Price: USD1000 | USD1500 for final deal*. Just by BTC

*The final deal close future deals. 10 buyers can buy before you, but you buying the "final deal" you have the guarantee that after you the sell is closed. If you wanna exclusive deal, buy the "final deal" before everybody.

Edit 1.
OBS: ICS attack can cause a lot of problems, in this case, since the 0day is about data leak from device, it can be used by espionage.

Гарант-сервис xss.pro - https://xss.pro/help/escrow/
 
Последнее редактирование модератором:
Пожалуйста, обратите внимание, что пользователь заблокирован
voltage, kWh, energy by Consumption/Demand, etc.
Price: USD1000 | USD1500 for final deal*. Just by BTC
Why would someone pay 1K+ for such info? Or am I missing something?
 
Пожалуйста, обратите внимание, что пользователь заблокирован
Because its a 0day easy exploitable.
ICS attack can cause a lot of problems, in this case, since the 0day is about data leak from device, it can be used by espionage.
I'm sure the "0day" you are talking about is just some exposed service / poor configuration. Either way, I don't see how the data leak has any value - and even less why someone would pay 1K+ for that. There is difference between ICS attack and some data leak of completely worthless data.
 
I'm sure the "0day" you are talking about is just some exposed service / poor configuration. Either way, I don't see how the data leak has any value - and even less why someone would pay 1K+ for that. There is difference between ICS attack and some data leak of completely worthless data.
Make your offer.
 
Пожалуйста, обратите внимание, что пользователь заблокирован
Make your offer.
I don't see any value in the data, it's completely worthless, so I don't need it even for free. If I was you, I'd just post what the "0day" is (as I already said, most likely it's just some exposed service / poor configuration). But it's your choice.
 
I don't see any value in the data, it's completely worthless, so I don't need it even for free. If I was you, I'd just post what the "0day" is (as I already said, most likely it's just some exposed service / poor configuration). But it's your choice.
Just post what the 0day is? And about the value?
Besides, the 0day is not poor configuration, its web bug.
 
Статус
Закрыто для дальнейших ответов.
Верх