[Home]  [Headlines]  [Latest Articles]  [Latest Comments]  [Post]  [Sign-in]  [Mail]  [Setup]  [Help] 

Status: Not Logged In; Sign In

When Philadelphia’s Foul-Mouthed Cop-Turned-Mayor Invented White Identity Politics

Trump Wanted to Pardon Assange and Snowden. Blocked by RINOs.

What The Pentagon Is Planning Against Trump Will Make Your Blood Run Cold Once Revealed

How Trump won the Amish vote in Pennsylvania

FEC Filings Show Kamala Harris Team Blew Funds On Hollywood Stars, Private Jets

Israel’s Third Lebanon War is underway: What you need to know

LEAK: First Behind-The-Scenes Photos Of Kamala After Getting DESTROYED By Trump | Guzzling Wine!🍷

Scott Ritter Says: Netanyahu's PAINFUL Stumble Pushes Tel Aviv Into Its WORST NIGHTMARE

These Are Trump's X-Men | Dr. Jordan B. Peterson

Houthis (Yemen) Breached THAAD. Israel Given a Dud Defense!!

Yuma County Arizona Doubles Its Outstanding Votes Overnight They're Stealing the Race from Kari Lake

Trump to withdraw U.S. troops from northern Syria

Trump and RFK created websites for the people to voice their opinion on people the government is hiring

Woke Georgia DA Deborah Gonzalez pummeled in re-election bid after refusing Laken Riley murder case

Trump has a choice: Obliterate Palestine or end the war

Rod Blagojevich: Kamala’s Corruption, & the Real Cause of the Democrat Party’s Spiral Into Insanity

Israel's Defense Shattered by Hezbollah's New Iranian Super Missiles | Prof. Mohammad Marandi

Trump Wins Arizona in Clean Sweep of Swing States in US Election

TikTok Harlots Pledge in Droves: No More Pussy For MAGA Fascists!

Colonel Douglas Macgregor:: Honoring Veteran's Day

Low-Wage Nations?

Trump to pull US out of Paris climate agreement NYT

Pixar And Disney Animator Bolhem Bouchiba Sentenced To 25 Years In Prison

Six C-17s, C-130s deploy US military assets to Northeastern Syria

SNL cast members unveil new "hot jacked" Trump character in MAGA-friendly cold open

Here's Why These Geopolitical And Financial Chokepoints Need Your Attention...

Former Army Chief Moshe Ya'alon Calls for Civil Disobedience to Protest Netanyahu Government

The Deep State against Trump

A Post Mortem Autopsy: From A Diddy Party to a Pity Party

Whoopie Goldberg Blames Inflation on Grocery Store Owners, Calls Them Pigs


Science/Tech
See other Science/Tech Articles

Title: Crashing passenger jet with Android phone?
Source: [None]
URL Source: http://rt.com/news/teso-plane-hijack-android-716/
Published: Apr 12, 2013
Author: Reuters / Luke MacGregor
Post Date: 2013-04-12 05:49:25 by Tatarewicz
Keywords: None
Views: 38

Reuters: There’s now another reason to be aerophobic after a German hacker demonstrated how to remotely hijack and bring down an airplane using an app for the Android phone.

The presentation called ‘Aircraft Hacking: Practical Aero Series' by Hugo Teso has become the highlight of the Hack In The Box security conference in Amsterdam on April 10-11, terrifying most of those, who attended it.

Teso, who currently works as a security consultant at the German n.runs IT-company, has used his experience of being a commercial pilot to create the software, which grants him full control of a passenger aircraft.

It took the researcher three years to come up with the PlaneSploit app for Android based on his SIMON code, which proved that – despite the tightened security in airports and on-board – air carriers are completely defenceless when it comes cyber-attacks.

Teso’s presentation revealed that the Automated Dependent Surveillance-Broadcast (ADS-B), which is a surveillance technology for tracking planes, is unencrypted and unauthenticated.

He said that the possible attacks on this system can “range from passive attacks (eavesdropping) to active attacks (message jamming, replaying, injection)”.

Meanwhile, the US government demands all aircrafts to be equipped with ADS-B by the 2020.

It turned out that the Aircraft Communications Addressing and Reporting System (ACARS), which is used for exchanging messages between aircraft and stations via radio or satellite, is also extremely vulnerable.

FMZ-2000 Flight Management System (Photo from honeywell.com)"ACARS has no security at all. The airplane has no means to know if the messages it receives are valid or not. So they accept them, and you can use them to upload data to the airplane that triggers these vulnerabilities. And then it's game over," Teso is cited as saying by The Independent.

The hacker added that just a little knowledge is required to read and send ACARS messages as it’s sometimes as easy as ordering goods from an online store.

Teso has demonstrated how to upload Flight Management System (FMS) data through ACARS, using a lab of virtual airplanes, which are based on real aircraft codes.

Once he got into the system, he was able to manipulate the steering of a Boeing jet in autopilot mode, saying he could also change the plane's course, crash it, make oxygen masks fall out and etc.

"You can use this system to modify approximately everything related to the navigation of the plane. That includes a lot of nasty things," the hacker told Forbes.

Another problem, which Teso pointed out during his presentation, is that lots of aircraft computers run outdated software, which doesn’t meet modern safety requirements.

The hacker said that during his research he only experimented with second-hand flight system software and hardware as hijacking a real plane during a flight was

“too dangerous and unethical.” Thankfully, the PlaneSploit is proof-of-concept software, which will not be making its way to the app stores.

Post Comment   Private Reply   Ignore Thread  



[Home]  [Headlines]  [Latest Articles]  [Latest Comments]  [Post]  [Sign-in]  [Mail]  [Setup]  [Help]