/?pid=10950

Updated:03:40 AM EDT Jun 20


this is ggmania.com subsite Hijacking airplanes with an Android phone - TechAmok

Hijacking airplanes with an Android phone - [security]
07:30 AM EDT - Apr,11 2013 - post a comment

An extremely well attended talk by Hugo Teso, a security consultant at n.runs AG in Germany, about the completely realistic scenario of plane hijacking via a simple Android app has galvanized the crowd attending the Hack In The Box Conference in Amsterdam today.
Teso, who has been working in IT for the last eleven years and has been a trained commercial pilot for a year longer than that, has combined his two interests in order to bring to light the sorry state of security of aviation computer systems and communication protocols.

By taking advantage of two new technologies for the discovery, information gathering and exploitation phases of the attack, and by creating an exploit framework (SIMON) and an Android app (PlaneSploit) that delivers attack messages to the airplanes' Flight Management Systems (computer unit + control display unit), he demonstrated the terrifying ability to take complete control of aircrafts by making virtual planes "dance to his tune."

One of the two technologies he abused is the Automatic Dependent Surveillance-Broadcast, which sends information about each aircraft (identification, current position, altitude, and so on) through an on-board transmitter to air traffic controllers, and allows aircrafts equipped with the technology to receive flight, traffic and weather information about other aircrafts currently in the air in their vicinity.

The other one is the Aircraft Communications Addressing and Reporting System, which is used to exchange messages between aircrafts and air traffic controllers via radio or satellite, as well as to automatically deliver information about each flight phase to the latter.

Both of these technologies are massively insecure and are susceptible to a number of passive and active attacks. Teso misused the ADS-B to select targets, and the ACARS to gather information about the onboard computer as well as to exploit its vulnerabilities by delivering spoofed malicious messages that affect the "behavior" of the plane.

Here are some of the functions Teso showed to the HITBSecConf Amsterdam audience:

Please go here: A way of interacting with the plane where the user can dynamically tap locations on the map and change the plane's course.
Define area: Set detailed filters related to the airplane, for example activate something when a plane is in the area of X kilometers or when it starts flying on a predefined altitude.
Visit ground: Crash the airplane.
Kiss off: Remove itself from the system.
Be punckish: A theatric way of alerting the pilots that something is seriously wro


Add your comment (free registrationrequired)

Short overview of recent news articles

Jun,20 2025 CPU SCAM: AMD Ryzen 9800X3D Counterfeits & Fraud
Jun,19 2025 28 Years Later Review
Jun,18 2025 HW News - NVIDIA "N1x" CPU Leak, ASUS Xbox ROG Ally, More Intel
Jun,17 2025 NVIDIA GeForce 576.80 WHQL Driver
Jun,16 2025 The Fantastic Four: First Steps - Official 'H.E.R.B.I.E.' Teaser
Jun,15 2025 Huawei Maextro S800 First Look - A True BMW & Mercedes Killer?
Jun,14 2025 Upgrade Windows 10 to Windows 10 LTSC Without Losing Data
Jun,14 2025 Squid Game: Season 3 - Final Games Trailer
Jun,11 2025 WWDC 2025: Everything Revealed in 9 Minutes
Jun,10 2025 Microsoft June 2025 Patch Tuesday fixes exploited zero-day, 66 flaws
Jun,10 2025 This Malware BREAKS WINDOWS!
Jun,10 2025 Reset Forgotten Password without Any Software, without USB drive in
Jun,08 2025 Microsoft Will Block Unsupported Hardware For Windows 11
Jun,08 2025 Memory Wars! Apple vs Ryzen - Is Unified Memory Faster than Shared
Jun,06 2025 Predator: Killer of Killers - Exclusive Clip (2025)
Jun,06 2025 Enable Deep Effect on Samsung One Ui 7
Jun,05 2025 Google Kills Off PayPal in Google Wallet
Jun,05 2025 Samsung's Next Flagship Foldable Will be Ultra
Jun,05 2025 Over 40 Malicious Chrome Extensions Mimic Popular Brands to Steal
Jun,03 2025 The Witcher IV - Unreal Engine 5 tech demo
Jun,02 2025 Nintendo Switch 2 Welcome Tour trailer
Jun,01 2025 Stranger Things 5 | Date Announcement | Netflix
May,31 2025 RTX 5060 Review... No wonder NVIDIA tried to stop us from talking
May,30 2025 Samsung Galaxy Watch 8 Classic Is Here - 7 New Updates
May,30 2025 Biggest Windows 11 24H2 May Update in the Main Release
May,29 2025 How Much Money Should You Spend on a Gaming PC?
May,29 2025 laud Note vs Note Pin - Which AI Voice Recorder To Choose
May,29 2025 Samsung One UI 8.0 vs One UI 7.0 - 25+ Changes
May,28 2025 SECRET CODE UPDATE for Samsung Galaxy Phone to Boost Performance &
May,27 2025 WhatsApp is finally available on iPad
May,27 2025 Simple Trick To Lower CPU Temperatures
May,26 2025 Alma & The Wolf - Official Trailer (2025) Ethan Embry, Li Jun Li,
May,25 2025 Change These Browser Security Settings NOW
May,24 2025 I NEED AMD to Seize This Moment - RX 9060XT
May,23 2025 Windows 98 with a G41 Core 2 Duo System
May,23 2025 Disable These Windows Settings for Better FPS!
May,20 2025 I Got the Golden GPU from Dubai
May,19 2025 Windows 10 emergency update KB5061768 fixes BitLocker boot loops -
May,19 2025 2025 AUDI S5 AVANT // 0-100 100-200 TOP SPEED POV & SOUND
May,18 2025 Jurassic World Rebirth - Official 'Alert' Teaser Trailer (2025)
>> News Archive <<

TechAmok - Privacy Policy        loading time:0.01secs