
At the recently concluded HackInTheBox 2013 (HITB) conference German security consultant Hugo Teso has once again drawn into question the security of aero comms. In a presentation at the Amsterdam conference, Hugo highlighted the security vulnerabilities of the Automatic Dependent Surveillance-Broadcast (ADS-B) and Aeronautical Communications Addressing and Reporting System (ACARS) digital aero radio data systems. Net-Security reports, “By taking advantage of these two new technologies for the discovery, information gathering and exploitation phases of the attack, and by creating an exploit framework (SIMON) and an Android app (PlaneSploit) that delivers attack messages to the airplanes’ Flight Management Systems (computer unit + control display unit), he demonstrated the terrifying ability to take complete control of aircrafts by making virtual planes “dance to his tune.” ”
While the presentation video has not been posted yet, here’s a link to the slides. Hugo has also posted a link to his primer on the RF systems discussed in the presentation. (We promise to post the video as soon as it’s released.)
It should be noted that the United States FAA has denied the viability of this hack in an interview with the The Daily Caller.
