Close Menu
5gantennas.org5gantennas.org
  • Home
  • 5G
    • 5G Technology
  • 6G
  • AI
  • Data
    • Global 5G
  • Internet
  • WIFI
  • 5G Antennas
  • Legacy

Subscribe to Updates

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

What's Hot

4 Best Wi-Fi Mesh Networking Systems in 2024

September 6, 2024

India is on the brink of a new revolution in telecommunications and can lead the world with 6G: Jyotiraditya Scindia

August 29, 2024

Speaker Pelosi slams California AI bill headed to Governor Newsom as ‘ignorant’

August 29, 2024
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram
5gantennas.org5gantennas.org
  • Home
  • 5G
    1. 5G Technology
    2. View All

    Deutsche Telekom to operate 12,500 5G antennas over 3.6 GHz band

    August 28, 2024

    URCA Releases Draft “Roadmap” for 5G Rollout in the Bahamas – Eye Witness News

    August 23, 2024

    Smart Launches Smart ZTE Blade A75 5G » YugaTech

    August 22, 2024

    5G Drone Integration Denmark – DRONELIFE

    August 21, 2024

    Hughes praises successful private 5G demo for U.S. Navy

    August 29, 2024

    GSA survey reveals 5G FWA has become “mainstream”

    August 29, 2024

    China Mobile expands 5G Advanced, Chunghwa Telecom enters Europe

    August 29, 2024

    Ateme and ORS Boost 5G Broadcast Capacity with “World’s First Trial of IP-Based Statmux over 5G Broadcast” | TV Tech

    August 29, 2024
  • 6G

    India is on the brink of a new revolution in telecommunications and can lead the world with 6G: Jyotiraditya Scindia

    August 29, 2024

    Vodafonewatch Weekly: Rural 4G, Industrial 5G, 6G Patents | Weekly Briefing

    August 29, 2024

    Southeast Asia steps up efforts to build 6G standards

    August 29, 2024

    Energy efficiency as an inherent attribute of 6G networks

    August 29, 2024

    Finnish working group launches push for 6G technology

    August 28, 2024
  • AI

    Speaker Pelosi slams California AI bill headed to Governor Newsom as ‘ignorant’

    August 29, 2024

    Why Honeywell is betting big on Gen AI

    August 29, 2024

    Ethically questionable or creative genius? How artists are engaging with AI in their work | Art and Design

    August 29, 2024

    “Elon Musk and Trump” arrested for burglary in disturbing AI video

    August 29, 2024

    Nvidia CFO says ‘enterprise AI wave’ has begun and Fortune 100 companies are leading the way

    August 29, 2024
  • Data
    1. Global 5G
    2. View All

    Global 5G Enterprise Market is expected to be valued at USD 34.4 Billion by 2032

    August 12, 2024

    Counterpoint predicts 5G will dominate the smartphone market in early 2024

    August 5, 2024

    Qualcomm’s new chipsets will power affordable 5G smartphones

    July 31, 2024

    Best Super Fast Download Companies — TradingView

    July 31, 2024

    Crypto Markets Rise on Strong US Economic Data

    August 29, 2024

    Microsoft approves construction of third section of Mount Pleasant data center campus

    August 29, 2024

    China has invested $6.1 billion in state-run data center projects over two years, with the “East Data, West Computing” initiative aimed at capitalizing on the country’s untapped land.

    August 29, 2024

    What is the size of the clinical data analysis solutions market?

    August 29, 2024
  • Internet

    NATO believes Russia poses a threat to Western internet and GPS services

    August 29, 2024

    Mpeppe grows fast, building traction among Internet computer owners

    August 29, 2024

    Internet Computer Whale Buys Mpeppe (MPEPE) at 340x ROI

    August 29, 2024

    Long-term internet computer investor adds PEPE rival to holdings

    August 29, 2024

    Biden-Harris Administration Approves Initial Internet for All Proposals in Mississippi and South Dakota

    August 29, 2024
  • WIFI

    4 Best Wi-Fi Mesh Networking Systems in 2024

    September 6, 2024

    Best WiFi deal: Save $200 on the Starlink Standard Kit AX

    August 29, 2024

    Sonos Roam 2 review | Good Housekeeping UK

    August 29, 2024

    Popular WiFi extender that eliminates dead zones in your home costs just $12

    August 29, 2024

    North American WiFi 6 Mesh Router Market Size, Share, Forecast, [2030] – அக்னி செய்திகள்

    August 29, 2024
  • 5G Antennas

    Nokia and Claro bring 5G to Argentina

    August 27, 2024

    Nokia expands FWA portfolio with new 5G devices – SatNews

    July 25, 2024

    Deutsche Telekom to operate 12,150 5G antennas over 3.6 GHz band

    July 24, 2024

    Vodafone and Ericsson develop a compact 5G antenna in Germany

    July 12, 2024

    Vodafone and Ericsson unveil new small antennas to power Germany’s 5G network

    July 11, 2024
  • Legacy
5gantennas.org5gantennas.org
Home»Data»Researchers remotely exploit device used to manage safe takeoff and landing of aircraft • The Register
Data

Researchers remotely exploit device used to manage safe takeoff and landing of aircraft • The Register

5gantennas.orgBy 5gantennas.orgFebruary 3, 2024No Comments5 Mins Read
Facebook Twitter Pinterest LinkedIn Tumblr Email
Share
Facebook Twitter LinkedIn Pinterest WhatsApp Email


New research has found that data used by apps used to inform airline pilots about safe takeoff and landing procedures can be remotely tampered with by criminals.

In a scenario that evokes strong memories of that painful flight scene, die hard 2researchers investigating electronic flight bags (EFBs) have found that the app used by Airbus pilots is vulnerable to remote data manipulation under the right conditions.

In reality, that Die Hard scene was surprisingly riddled with plot holes – researchers proved it months ago – but it proves something similar can happen. It was always an exciting thing to do.

EFBs are typically tablets or tablet-like portable computers that run aviation-specific apps used for various flight deck and cabin tasks, such as calculations to improve aircraft performance.

The vulnerability was discovered in Flysmart+ Manager, one of many apps in the Flysmart+ suite that Airbus pilots use to sync data to other Flysmart+ apps. Flysmart+ Manager provides data to inform pilots of safe takeoffs and landings.

Flysmart+ Manager, developed by Airbus-owned NAVBLUE, was found to disable App Transport Security (ATS) by setting the NSAllowsArbitraryLoads property list key to ‘true’. ATS is an important security control that protects communication between your app and the app update server.

“ATS is a security mechanism that forces applications to use HTTPS and prevents unencrypted communication,” Antonio Cassidy, partner at Pen Test Partners, which conducted the research, said in a blog post. “An attacker could exploit this weakness to intercept and decrypt potentially sensitive information in transit.”

A viable attack must involve intercepting data flowing into the app and requires a number of very specific conditions to be met. Even Ken Munro, another partner at Pen Test Partners, concedes that the likelihood of exploitation is low in a real-world scenario.

That’s right, this is the hotel that airlines always use…

First, the attacker must be within Wi-Fi range of the EFB with Flysmart+ Manager loaded. It may seem unlikely, but Munro said airlines often use the same hotels to house pilots between flights, and pilots and the airlines they work for are often It is said to be easy to distinguish.

Second, and perhaps the biggest barrier to realistic exploitability, is the fact that an attacker would need to monitor device traffic when the EFB handler initiates an app update.

The update cycle is determined by the Aviation Information and Regulatory Control (AIRAC) database. The AIRAC database can be updated with important information, such as when a new runway is installed or temporarily out of service, or when significant changes are made to the runway environment, such as the installation of a crane.

Once the database is updated with new data, the app must download that data to provide pilots with accurate and timely information. This is usually done once a month.

The attack scenario devised by the researchers targets a pilot sitting in a hotel bar (i.e. within Wi-Fi range) and targets a specific endpoint that the attacker knows about and is aware of the target app. The idea was to perform directional Wi-Fi hunting. .

“Given that airlines typically use the same hotels for outbound and connecting pilots, attackers could potentially target hotel Wi-Fi networks with the intent of tampering with aircraft performance data. “Yes,” Cassidy said.

While developing a proof of concept for the exploit, researchers had access to data downloaded from update servers. Most of these come in the form of SQLite databases, including aircraft weight balance data and a minimum equipment list, which is information about which systems may become inoperable during flight. It was.

Cassidy said possible effects of a successful exploit could include rear-ending an aircraft or a missed takeoff, which could lead to a runway excursion.

“Do you think that’s a possibility? No, absolutely not,” Munro said. “But the important thing is there is a vulnerability. There is a problem with the flight system, but the good news is we found it and the manufacturer is fixing it.”

Airbus was praised by researchers for resolving the problem within 19 months, which they said was within the expected range for aviation technology.

While 19 months is completely unacceptable for regular IT patching, in the airline industry, such updates typically take about 12 months and not a million miles. The certification process with the airline industry is said to take even longer.

Munro said, “Could it have been done a little faster? Yes, I think it could have been done a little faster, but they fixed it, and that’s the important thing. It was done in a reasonable amount of time for aviation software.” I did.”

An active commercial pilot said: register The findings were particularly “concerning” regarding takeoff performance speeds, as Airbus’ performance programs are known to generate different speeds and flap settings to optimize takeoffs. They said that because of this frequent change, if a manipulated dataset appears in the EFB app, pilots likely won’t be able to spot it, which could lead to unsafe takeoff procedures.

Some airlines have significant error checks that examine the relationship between calculated speed and actual aircraft speed based on aircraft weight and balance data. This type was accessed by the researcher while examining his Flysmart + Manager.

“I assumed [these checks] We will find a hack…but we cannot say for sure,” the pilot said.

In response to the investigation, an Airbus spokesperson said, “We have identified a potential vulnerability in certain versions of the NAVBLUE FlySmart+ EFB product in 2022.”

“Our analysis, confirmed by EASA, showed that there were no safety issues thanks to the security procedures put in place to verify flight-related data. This potential vulnerability has been resolved in version “.”®



Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email
Previous ArticlePoonam Pandey is ‘not dead’ says the internet
Next Article Intel is building a multibillion-dollar AI accelerator business
5gantennas.org
  • Website

Related Posts

Crypto Markets Rise on Strong US Economic Data

August 29, 2024

Microsoft approves construction of third section of Mount Pleasant data center campus

August 29, 2024

China has invested $6.1 billion in state-run data center projects over two years, with the “East Data, West Computing” initiative aimed at capitalizing on the country’s untapped land.

August 29, 2024
Leave A Reply Cancel Reply

You must be logged in to post a comment.

Latest Posts

4 Best Wi-Fi Mesh Networking Systems in 2024

September 6, 2024

India is on the brink of a new revolution in telecommunications and can lead the world with 6G: Jyotiraditya Scindia

August 29, 2024

Speaker Pelosi slams California AI bill headed to Governor Newsom as ‘ignorant’

August 29, 2024

Crypto Markets Rise on Strong US Economic Data

August 29, 2024
Don't Miss

6G: Will it spark a manufacturing revolution?

By 5gantennas.orgJanuary 8, 2024

Roger Kauffman, Senior Director of Product Management and Marketing, Molex The next evolution in mobile…

Where 6G creates solid business impact

November 17, 2023

Introducing the researchers who supported the development of the 6G Framework Recommendation Draft – Samsung Global Newsroom

July 25, 2023

Subscribe to Updates

Subscribe to our newsletter and never miss our latest news

Subscribe my Newsletter for New Posts & tips Let's stay updated!

About Us
About Us

Welcome to 5GAntennas.org, your reliable source for comprehensive information on 5G technology, artificial intelligence (AI), and data-related advancements. We are passionate about staying at the forefront of these cutting-edge fields and bringing you the latest insights, trends, and developments.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks

4 Best Wi-Fi Mesh Networking Systems in 2024

September 6, 2024

India is on the brink of a new revolution in telecommunications and can lead the world with 6G: Jyotiraditya Scindia

August 29, 2024

Speaker Pelosi slams California AI bill headed to Governor Newsom as ‘ignorant’

August 29, 2024
Most Popular

Global 5G market expands to 1.6 billion users

January 23, 2024

Verizon Business expands private 5G in Port of Virginia with NIT’s new network | News Release

November 16, 2023

Verizon Business Provides Private 5G Network to Rocklahoma Music Festival | News Release

August 30, 2023
© 2025 5gantennas. Designed by 5gantennas.
  • Home
  • About us
  • Contact us
  • DMCA
  • Privacy Policy
  • About Creator

Type above and press Enter to search. Press Esc to cancel.