Newsletters
News & Information for Technology Purchasers NewsFactor Sites:       NewsFactor.com     Enterprise Security Today     CRM Daily     Business Report     Sci-Tech Today  
   
This ad will display for the next 20 seconds. Please click for more information, or scroll down to pass the ad, or Close Ad.
Home Enterprise I.T. Cloud Computing Applications Hardware More Topics...
APC Free White Paper
Optimize your network investment &
Enter to win a Samsung Galaxy Note

www.apc.com
Hackers
24/7/365 Network Uptime!
Average Rating:
Rate this article:  
Can Planes Be Hijacked by Android Phone?
Can Planes Be Hijacked by Android Phone?

By Barry Levine
April 12, 2013 2:14PM

    Bookmark and Share
The Android phone hijack claim is not the first warning that cyber-terrorism could be launched remotely against aircraft. Last summer, two presentations at a Black Hat and Defcon security conference said a new system for tracking and control of aircraft in the U.S. and other countries has insufficient encryption to prevent a terrorist from creating false plane information.
 


It sounds like part of a Bruce Willis action movie: A hacker takes remote control of a commercial aircraft, using only an Android smartphone. A German security researcher said this week it can be done, but the Federal Aviation Administration is denying the claim.

The researcher, Hugo Teso, works for German IT company n.runs and is also a commercial pilot. At the Hack in the Box security conference this week in Amsterdam, he explained that transmissions to commercial aircraft can be hijacked, thus hijacking the aircraft.

The protocol of the transmissions is ACARS, or the Aircraft Communications Addressing and Reporting System. Teso said a hacker can take advantage of security vulnerabilities in ACARS, as well as vulnerabilities in flight management software from Honeywell and other aircraft technology companies. To take control, Teso created an Android app called PlaneSploit that exploits these vulnerabilities to talk to the aircraft's Flight Management Systems.

'Lot of Nasty Things'

Teso said his app can direct the plane to change direction, altitude, speed, and can change the data on pilots' screens. He told Forbes magazine that "you can use this system to modify approximately everything related to the navigation of the plane," including "a lot of nasty things."

This is not the first warning that cyber-terrorism could be launched remotely against aircraft. Last summer, two presentations at the Black Hat and Defcon security conference in Las Vegas said a new system for tracking and control of aircraft in the U.S. and other countries, which is being rolled out over the next few years, has insufficient encryption to prevent a terrorist from creating false plane information.

This could swamp air traffic controllers with fake status reports from fake aircraft, preventing them from guiding actual aircraft to safe landings because they wouldn't known which ones were real. One of the security researchers at the Black Hat conference, Andrei Costin, had reported that even "a medium-technical savvy person" could impersonate a plane that wasn't there.

Honeywell, FAA Dispute Findings

Some of the companies that developed the aircraft flight management software dispute Teso's claims.

Honeywell said that, although it will work with n.runs to assess the vulnerabilities, Teso's work does not necessarily prove there is risk because his experimentations over three years were on Flight Management Systems hardware he bought on eBay, and used FMS training simulation software that claims it has some of the same code as in actual commercial aircraft. A Honeywell spokesperson told Forbes the training simulation software "doesn't have the same protections against overwriting or corrupting as our certified flight software."

In reply, n.runs said the vulnerabilities were not in the FMS software that was being tested, but in actual aircraft functions, and that the hack would require only minimum adaptation to work on an actual plane.

Similarly, the FAA, the European Aviation Safety Administration, and aircraft technology company Rockwell Collins have released statements that current systems are secure and are not equivalent to Teso's lab environment.
 

Tell Us What You Think
Comment:

Name:

Kevin:

Posted: 2013-04-23 @ 10:27am PT
yep. I want to see some proofs, stop talking gibberish.

Robert:

Posted: 2013-04-16 @ 5:16pm PT
If there are vulnerabilities... let's see them in action... all of this is just talk.



Your Next Generation Data Center Is Here! Vblock™ Systems: the world's most advanced converged infrastructure are built on the Cisco Unified Computing System with Intel® Xeon® processors. Vblock™ Systems deliver extraordinary time to market, ROI and TCO, and flexibility to meet your continually changing demands with 5X faster deployment, 96% less downtime, and 1/2 the cost. Click here to learn more.


 Hackers
1.   Target Hackers May Be Tough To Find
2.   Teen Arrested for Heartbleed Hack
3.   iPad Hacker Conviction Overturned
4.   Is Heartbleed the Biggest Threat Ever?
5.   Heartbleed Bug Breaks Web Security


advertisement
Internet Devices Lure Hackers
Mundane devices end up in online crime.
Average Rating:
Target Hackers May Be Tough To Find
Difficult challenges for Secret Service.
Average Rating:
Teen Arrested for Heartbleed Hack
Data stolen from Canadian tax agency.
Average Rating:
Product Information and Resources for Technology You Can Use To Boost Your Business

Network Security Spotlight
What Verizon's Data Breach Report Can Teach Enterprises
It’s probably not a jaw-dropper, but cyberespionage is officially on the rise. And the use of stolen or misused credentials is still the leading way the bad guys gain access to corporate information.
 
Top Cyberthreats Exposed by Verizon Report
Beyond Heartbleed, there are cyberthreats vying to take down enterprise networks, corrupt smartphones, and wreak havoc on businesses. Verizon is exposing these threats in a new report.
 
Where Do Web Sites Stand, Post-Heartbleed?
A security firm says the vast majority of Web sites have patched themselves to protect against the Heartbleed bug, but now there are questions raised on the reliability of open-source programs.
 

Navigation
NewsFactor Network
Home/Top News | Enterprise I.T. | Cloud Computing | Applications | Hardware | Mobile Tech | Big Data | Communications
World Wide Web | Network Security | Data Storage | Small Business | Microsoft/Windows | Apple/Mac | Linux/Open Source | Personal Tech
Press Releases
NewsFactor Network Enterprise I.T. Sites
NewsFactor Technology News | Enterprise Security Today | CRM Daily

NewsFactor Business and Innovation Sites
Sci-Tech Today | NewsFactor Business Report

NewsFactor Services
FreeNewsFeed | Free Newsletters | XML/RSS Feed

About NewsFactor Network | How To Contact Us | Article Reprints | Careers @ NewsFactor | Services for PR Pros | Top Tech Wire | How To Advertise

Privacy Policy | Terms of Service
© Copyright 2000-2014 NewsFactor Network. All rights reserved. Article rating technology by Blogowogo. Member of Accuserve Ad Network.