Researcher shows how to hack (and crash) a passenger aircraft with an Android phone...

 

If you're nervous about flying, this won't allay your fears about hopping on a plane, so you might want to look away now. The Hack In The Box security conference taking place in Amsterdam this week has thrown up some interesting talks - but none so concerning as 'Aircraft Hacking: Practical Aero Series' by Hugo Teso.

Teso works as a security consultant at n.runs in Germany, and his Aircraft Hacking talk promised a practical demonstration of how to remotely attack and take full control of an aircraft. His talk was the product of three years of developing code and tinkering with second-hand flight system software and hardware. It comes a fortnight after the Federal Aviation Administration (FAA) have expressed hopes that they will be able to relax rules for reading devices during take-off and landing - and with this research, they may want to reconsider their position.

The results of Teso's hard work are terrifying. Firstly, the Automated Dependent Surveillance-Broadcast (ADS-B), which is a surveillance technology for tracking aircraft, has no security. The United States government will require all aircraft to be equipped with ADS-B by the year 2020 - however, the system has been proven to be unencrypted and unauthenticated. Teso's presentation stated that the attacks on this system "range from passive attacks (eavesdropping) to active attacks (message jamming, replaying, injection)".

Secondly, the Aircraft Communications Addressing and Reporting System (ACARS) - which is used for exchanging messages between aircraft and stations via radio or satellite - also has no security. Teso pointed out that anyone with a little knowledge can read and send ACARS messages - and it may be as simple as purchasing some hardware from eBay.

Using a lab of virtual planes based on real aircraft codes, Teso gave a practical demonstration of how to use ACARS to upload Flight Management System (FMS) data. Once in, he was able to manipulate the steering of a Boeing jet in 'autopilot' mode, and said he could make oxygen masks drop down, and even cause the plane to crash by setting it on a collision course with another plane.

Teso explained to Forbes: "ACARS has no security at all. The plane has no means to know if the messages it receives are valid or not. So they accept them, and you can use them to upload data to the plane that triggers these vulnerabilities. And then it's game over."

The hijack was all carried out using Teso's code, SIMON, and a specially-made Android app called PlaneSploit (fortunately, it's not available for the masses) which enable the user to: change the plane's course; crash the plane; set lights flashing in the cockpit; activate something when the plane is in a certain area.

As well as ACARS and ADS-B having serious security failings, Teso also pointed out that lots of aircraft computers run outdated software which don't meet modern safety requirements.

Teso told Forbes: "You can use this system to modify approximately everything related to the navigation of the plane. That includes a lot of nasty things."

Although this makes for uncomfortable reading for those of us who love to jet off on holidays, rest assured that the Federal Aviation Administration and the European Aviation Safety Administration have been informed and are working to patch up these security flaws.

PROMOTED VIDEO
Life and Style
ebookNow available in paperback
ebooks
ebookPart of The Independent’s new eBook series The Great Composers
Latest stories from i100
Have you tried new the Independent Digital Edition apps?
Independent Dating
and  

By clicking 'Search' you
are agreeing to our
Terms of Use.

ES Rentals

    iJobs Job Widget
    iJobs Gadgets & Tech

    Recruitment Genius: Web Design Apprentice

    £6240 per annum: Recruitment Genius: This company is a well established websit...

    Recruitment Genius: Senior .Net Application Developer

    £40000 - £60000 per annum: Recruitment Genius: This is a fantastic opportunity...

    Recruitment Genius: .Net / SQL Developer

    £25000 - £35000 per annum: Recruitment Genius: A skilled .NET developer with e...

    Recruitment Genius: IT Technical Support Engineer - PC/Mac

    £25000 - £30000 per annum: Recruitment Genius: This IT support company are cur...

    Day In a Page

    Isis hostage crisis: The prisoner swap has only one purpose for the militants - recognition its Islamic State exists and that foreign nations acknowledge its power

    Isis hostage crisis

    The prisoner swap has only one purpose for the militants - recognition its Islamic State exists and that foreign nations acknowledge its power, says Robert Fisk
    Missing salvage expert who found $50m of sunken treasure before disappearing, tracked down at last

    The runaway buccaneers and the ship full of gold

    Salvage expert Tommy Thompson found sunken treasure worth millions. Then he vanished... until now
    Homeless Veterans appeal: ‘If you’re hard on the world you are hard on yourself’

    Homeless Veterans appeal: ‘If you’re hard on the world you are hard on yourself’

    Maverick artist Grayson Perry backs our campaign
    Assisted Dying Bill: I want to be able to decide about my own death - I want to have control of my life

    Assisted Dying Bill: 'I want control of my life'

    This week the Assisted Dying Bill is debated in the Lords. Virginia Ironside, who has already made plans for her own self-deliverance, argues that it's time we allowed people a humane, compassionate death
    Move over, kale - cabbage is the new rising star

    Cabbage is king again

    Sophie Morris banishes thoughts of soggy school dinners and turns over a new leaf
    11 best winter skin treats

    Give your moisturiser a helping hand: 11 best winter skin treats

    Get an extra boost of nourishment from one of these hard-working products
    Paul Scholes column: The more Jose Mourinho attempts to influence match officials, the more they are likely to ignore him

    Paul Scholes column

    The more Jose Mourinho attempts to influence match officials, the more they are likely to ignore him
    Frank Warren column: No cigar, but pots of money: here come the Cubans

    Frank Warren's Ringside

    No cigar, but pots of money: here come the Cubans
    Isis hostage crisis: Militant group stands strong as its numerous enemies fail to find a common plan to defeat it

    Isis stands strong as its numerous enemies fail to find a common plan to defeat it

    The jihadis are being squeezed militarily and economically, but there is no sign of an implosion, says Patrick Cockburn
    Virtual reality thrusts viewers into the frontline of global events - and puts film-goers at the heart of the action

    Virtual reality: Seeing is believing

    Virtual reality thrusts viewers into the frontline of global events - and puts film-goers at the heart of the action
    Homeless Veterans appeal: MP says Coalition ‘not doing enough’

    Homeless Veterans appeal

    MP says Coalition ‘not doing enough’ to help
    Larry David, Steve Coogan and other comedians share stories of depression in new documentary

    Comedians share stories of depression

    The director of the new documentary, Kevin Pollak, tells Jessica Barrett how he got them to talk
    Has The Archers lost the plot with it's spicy storylines?

    Has The Archers lost the plot?

    A growing number of listeners are voicing their discontent over the rural soap's spicy storylines; so loudly that even the BBC's director-general seems worried, says Simon Kelner
    English Heritage adds 14 post-war office buildings to its protected lists

    14 office buildings added to protected lists

    Christopher Beanland explores the underrated appeal of these palaces of pen-pushing
    Human skull discovery in Israel proves humans lived side-by-side with Neanderthals

    Human skull discovery in Israel proves humans lived side-by-side with Neanderthals

    Scientists unearthed the cranial fragments from Manot Cave in West Galilee