v

Debian Linux Security Advisory 830-1

Debian Security Advisory DSA 830-1 - Drew Parsons noticed that the post-installation script of ntlmaps, an NTLM authorization proxy server, changes the permissions of the configuration file to be world-readable. It contains the user name and password of the Windows NT system that ntlmaps connects to and, hence, leaks them to local users.




v

Cisco Security Advisory 20081022-asa

Cisco Security Advisory - Multiple vulnerabilities exist in the Cisco ASA 5500 Series Adaptive Security Appliances and Cisco PIX Security Appliances. These include Windows NT domain authentication bypass, IPv6 denial of service, and a Crypto Accelerator memory leak.




v

Microsoft Server Service NetpwPathCanonicalize Overflow

This Metasploit module exploits a stack overflow in the NetApi32 CanonicalizePathName() function using the NetpwPathCanonicalize RPC call in the Server Service. It is likely that other RPC calls could be used to exploit this service. This exploit will result in a denial of service on on Windows XP SP2 or Windows 2003 SP1. A failed exploit attempt will likely result in a complete reboot on Windows 2000 and the termination of all SMB-related services on Windows XP. The default target for this exploit should succeed on Windows NT 4.0, Windows 2000 SP0-SP4+, Windows XP SP0-SP1 and Windows 2003 SP0.




v

Microsoft RPC DCOM Interface Overflow

This Metasploit module exploits a stack overflow in the RPCSS service, this vulnerability was originally found by the Last Stage of Delirium research group and has bee widely exploited ever since. This Metasploit module can exploit the English versions of Windows NT 4.0 SP3-6a, Windows 2000, Windows XP, and Windows 2003 all in one request :)




v

Microsoft IIS 4.0 .HTR Path Overflow

This exploits a buffer overflow in the ISAPI ISM.DLL used to process HTR scripting in IIS 4.0. This Metasploit module works against Windows NT 4 Service Packs 3, 4, and 5. The server will continue to process requests until the payload being executed has exited. If you've set EXITFUNC to 'seh', the server will continue processing requests, but you will have trouble terminating a bind shell. If you set EXITFUNC to thread, the server will crash upon exit of the bind shell. The payload is alpha-numerically encoded without a NOP sled because otherwise the data gets mangled by the filters.




v

Terminal Server License Bypass

This registry code allows any terminal client access to a Terminal Server. It bypasses the Microsoft "Terminal Server License" and allows the client to create a session on the server without a CAL (Client Access License) or MS Open License. It works on WinNT, Win2000, Win2003 server and Win2008 server.




v

Windows NT/2K/XP/2K3/VISTA/2K8/7 NtVdmControl()-

Microsoft Windows NT/2K/XP/2K3/VISTA/2K8/7 NtVdmControl()->KiTrap0d local ring0 exploit. Google flags this as malware so only use this if you know what you are doing. The password to unarchive this zip is the word "infected".




v

Windows NT/2K/XP/2K3/VISTA/2K8/7/8 EPATHOBJ Local ring0

There is a pretty obvious bug in win32k!EPATHOBJ::pprFlattenRec where the PATHREC object returned by win32k!EPATHOBJ::newpathrec does not initialize the next list pointer. This is a local ring0 exploit for Microsoft Windows NT/2K/XP/2K3/VISTA/2K8/7/8.




v

Disk Pulse Enterprise 9.0.34 Login Buffer Overflow

This Metasploit module exploits a stack buffer overflow in Disk Pulse Enterprise 9.0.34. If a malicious user sends a malicious HTTP login request, it is possible to execute a payload that would run under the Windows NT AUTHORITYSYSTEM account. Due to size constraints, this module uses the Egghunter technique.




v

Disk Pulse Enterprise 9.9.16 GET Buffer Overflow

This Metasploit module exploits an SEH buffer overflow in Disk Pulse Enterprise version 9.9.16. If a malicious user sends a crafted HTTP GET request it is possible to execute a payload that would run under the Windows NT AUTHORITYSYSTEM account.




v

SyncBreeze 10.1.16 SEH GET Overflow

There exists an unauthenticated SEH based vulnerability in the HTTP server of Sync Breeze Enterprise version 10.1.16, when sending a GET request with an excessive length it is possible for a malicious user to overwrite the SEH record and execute a payload that would run under the Windows NT AUTHORITYSYSTEM account. The SEH record is overwritten with a "POP,POP,RET" pointer from the application library libspp.dll. This exploit has been successfully tested on Windows XP, 7 and 10 (x86->x64). It should work against all versions of Windows and service packs.




v

South Africa Seeks to Improve Process for Renewable Energy Deals

South African Energy Minister Tina Joemat-Pettersson said her department wants to address weaknesses in the process of commissioning renewable-power projects.




v

Expect $1.6 Trillion in Clean Energy Investments Through 2020, Says IEA

Investments in new clean-energy capacity will total $1.61 trillion through 2020 even as the expansion of renewables is expected to slow, the International Energy Agency said.




v

Divesting from Fossil Fuels: Last One Out Loses

A new report written by Nathaniel Bullard at Bloomberg New Energy Finance (BNEF) highlights the difficulties large institutional investors would have divesting from fossil fuels. What it does not specifically discuss is that these difficulties could lead to large financial losses for investors who see the difficulty of divesting as a reason to delay.




v

Eco Wave to Raise $5 Million to Accelerate Ocean Energy Plans

Eco Wave Power, based in Israel, plans to raise $5 million by the end of the year to further develop its technology and projects that harness the power of the ocean to generate electricity.




v

Ten Clean Energy Stocks for 2014: September Update and Thoughts on the Finavera Deal

Clean energy stocks and the market in general rebounded strongly in August. My broad market benchmark of small cap stocks, IWM, rose 4.5 percent, returning to positive territory up 1.7 percent for the year. My clean energy benchmark PBW also jumped back into the black with an 11.1 percent gain for the month and 10.8 percent for the year to date.




v

RGGI Chair Says States Won’t Leave Emissions Trading Market for California, Quebec

California and Quebec, which together created the largest carbon market in North America this year, may come away empty-handed as they woo northeastern U.S. states to join their system.




v

Microgrid Economics: It Takes a Village, a University, and a Ship

As a businessman exploring investments, I need simple answers, however complicated the problem. I wish to know: Are microgrids economical? How much investment is needed and for what? What are the factors that principally affect profitability, within the system and in the environment? If microgrids are not profitable at the present, when will they be? I recognize that understanding microgrids as a system requires complicated mathematics and modeling. I’m sympathetic to and respect those who do that.




v

Electrifying Keyna: How One African Country is Approaching Renewable Energy Development

Kenya’s renewable energy ambitions have attracted growing attention in recent months. There has been a strong uptick in interest in the country’s wind energy potential in particular. Last year, Kenya’s Ministry of Energy and Petroleum said in an investment prospectus for 2013-2016 that it plans to boost wind power generation by 630 MW as part of its target to increase electricity levels by 5,000 MW by 2016. In March, the Kenyan government also signed a financing document for the largest private investment in Kenya.




v

UK Green Bank Set to Draw Offshore Wind Investors to $1.6 Billion Fund

The U.K. Green Investment Bank is set to tie up the first investments in a $1.6 billion fund by the end of March, part of Britain’s push to cement its dominance in offshore wind power.




v

New Poll: New Yorkers Overwhelmingly Support Fracking Moratorium — And Clean Energy

Last month, NRDC engaged a nationally recognized opinion research firm to conduct polling in New York State to evaluate public attitudes about fracking and clean energy. Importantly, this is the first statewide poll in at least two years — and perhaps ever — to directly ask residents their views of the now six-year-old de facto moratorium on fracking.




v

The Next Revolution: Discarding Dangerous Fossil Fuel Accounting Practices

The green revolution and, in particular, renewable energy products such as solar power, wind turbines, geothermal and algae-based fuels are not waiting for viable technology — it already exists in many forms. What they are waiting for is a massive sea change in our antiquated financial accounting systems.





v

Are Environmental Regulations Causing US Utility Bills to Surge?

U.S. electricity markets face years of higher prices as clean-air regulations shut more coal-fired power plants than earlier forecast, cutting supply and forcing producers to rely more on natural gas.




v

UN Sees Irreversible Damage to Climate Caused by Fossil Fuels

Humans are causing irreversible damage to the planet from burning fossil fuels, the biggest ever study of the available science concluded in a report designed to spur the fight against climate change.




v

Fossil Fuels Reap $550 Billion in Subsidies, Hindering Renewables Investment

Fossil fuels are reaping $550 billion a year in subsidies and holding back investment in cleaner forms of energy, the International Energy Agency said.





v

Marine Energy Making Waves on Both Sides of the Pond

In recent months, a number of initiatives aimed at speeding up the development of the wave energy sector have been launched in the U.S. and Europe. As part of the ongoing work to establish a viable United States wave energy industry, the National Renewable Energy Laboratory (NREL) and Sandia National Laboratories (SANDIA) are working on the creation of a sophisticated open-source modeling tool known as WEC-Sim — and the U.S. Department of Energy is also enlisting the coding community to help in its development. Meanwhile, the European WavePOD project is an industry-wide initiative that aims to solve the problem of converting captured wave energy into electricity by creating a "standardised self-contained offshore electricity generator for the wave industry."




v

Wind Energy Provides More Than Two-Thirds of New US Generating Capacity in October

According to the latest "Energy Infrastructure Update" report from the Federal Energy Regulatory Commission's (FERC) Office of Energy Projects, wind power provided over two-thirds (68.41 percent) of new U.S. electrical generating capacity in October 2014. Specifically, five wind farms in Colorado, Kansas, Michigan, Nebraska, and Texas came on line last month, accounting for 574 MW of new capacity.




v

Investing in Innovative Ideas for a Clean Energy Future

The clean energy revolution is now, and the U.S. Energy Department is stepping up its commitment to help innovators commercialize their best ideas. At the recent Industry Growth Forum (IGF) in Denver, Colorado, Assistant Secretary for Energy Efficiency and Renewable Energy David Danielson announced the new Lab-Corps program to accelerate the transfer of clean energy technologies from the national laboratories to the marketplace, so that game-changing innovations don't languish for lack of money and equipment.




v

EPA's Plan to Curb Carbon Pollution Can Save Billions

The news about the Environmental Protection Agency’s plan to limit carbon pollution from existing power plants just got even better: the proposed Clean Power Plan (CPP) can save the power industry and its customers — us — as much as $2 to $4 billion in 2020 and $6 to 9 billion in 2030, while cleaning our air and modernizing the electricity sector.




v

Energy Efficiency and Renewables Are Lowest Risk/Cost Investments for Utilities

A new report by utility and finance experts contains positive news for the environment, our air and our (and our utilities’) pocketbooks — the economics of electric power resources have made zero-emissions energy efficiency and renewable energy technologies the most financially attractive options to meet the nation’s future energy demands.





v

Sage Advice is the Highlight of the Women in Power Luncheon

The advice that Pennwell’s 2014 Woman of the Year, Mary Powell, gave to women in the power industry during Tuesday’s Women in Power Luncheon might come as a surprise to some. It was this: Stop undercutting each other. Powell said the most difficult obstacles she has encountered in her various leadership roles have not come from men, but rather from other women. Small comments like “I don’t know how you do it [being a mom and holding a high-level job]”, serve to bring doubt and uncertainty to high achieving women in any industry, and ultimately can lead to women exiting their careers in order to fit what they perceive is the societal norm.




v

Renewable Energy Is Driving the Energy Transformation: REWNA Recap Video

Renewable energy stakeholders are well aware that clean energy is slowly but steadily transforming the energy landscape and that message couldn’t have been more clear at the recently concluded Power-Gen International, the largest show for the traditional power generation industry. Since all forms of power generation are represented at the show through the four co-located conferences, PennWell calls the second week in December "Power Generation Week."




v

Japan Toughens Rules for Renewable Energy Incentive Payments

Japan’s trade ministry is setting stricter rules for production and sales of renewable energy in what it says is a drive to speed up development of projects and ensure stable power supply.







v

Renewable Energy Review: Finance Mechanisms

Developers, manufacturers, investors and other renewable energy industry stakeholders need updates on the latest and greatest finance mechanisms available today. Since 2003, global consultancy Ernst & Young has released its Country Attractiveness Indices, which ranks global renewable energy markets by analyzing investment strategies and resource availability.





v

Serbia Seeks to Boost Renewable Energy Investment With New Law

Serbia seeks to unblock investment in renewable energy after adopting legislation that opens gas and power markets in line with European Union guidelines.




v

Renewable Energy Review: Australia

Developers, manufacturers, investors and other renewable energy industry stakeholders need to know where the next big market is going to be so that they can adjust their business decisions accordingly.





v

California Governor Seeks to Increase Renewable Energy Mandate to 50 Percent

California Governor Jerry Brown proposed spending $59 billion to fix crumbling roads and raising the state’s renewable energy mandate to 50 percent.




v

Dynamic Tidal Power Technology Advances

As an industrial powerhouse and the world’s largest energy consumer, China is fortunate to have abundant coal and hydropower resources. However, to meet demand in the east and south of the country, planners continue to seek new ways to generate local energy. In addition, plans call for development that reduces the use of fossil fuels as a way to also reduce air pollution.




v

Obama's State of the Union Speech Highlights US Renewable Achievements, Climate Change Goals

President Obama has been under intense scrutiny for what he would do about climate change ever since he was elected in 2008. Part of that scrutiny takes place during his State of the Union Speech, when renewable energy proponents search for key words about solar and wind energy and count how often he mentions "climate change."




v

India Clean Energy Investments Rose 13 Percent to $7.9 Billion in 2014

Clean energy investments in India increased to $7.9 billion last year and are expected to surpass $10 billion in 2015.




v

Demand Response: A Valuable Tool that Can Help California Realize its Clean Energy Potential

A tool only has value if it’s used. For example, you could be the sort of person who’s set a goal of wanting to exercise more. If someone gives you a nifty little Fitbit to help you do that, and you never open the box, how useful, then, is this little device? The same is true about smart energy management solutions: good tools exist, but whether it’s calories or energy use that you want to cut, at some point those helpful devices need to be unpacked.