Hacker claims he can remotely hijack airplanes using an Android app

Hacker claims he can remotely hijack airplanes using an Android app

Hugo Teso, a security consultant who also happens to be a trained commercial pilot, says he's developed an Android app that can make an airliner "dance to his tune" by attacking its flight management systems. The hack was demoed at this year's Hack In The Box conference in Amsterdam, where Teso showed how the app -- called PlaneSploit -- can seek out targets from the ground by infiltrating radio broadcasts between aircraft and air traffic control, and then use a second communication system to send malicious messages to that could "take full control of the plane" or indirectly affect the pilot's behavior. PlaneSploit is proof-of-concept software, designed to work in a closed virtual environment, so it's not like we're going to see it pop up on Google Play any time soon, but just the fact it exists will hopefully help to keep the puppet masters out of real-world planes. And no, there's no Windows Phone version.

Filed under: , ,

Comments

Via: Net Security, Computerworld

Source: Aircraft Hacking: Practical Aero Series (PDF)

Google patches SVG and IPC exploits in Chrome, discoverer banks $60,000 in the process

Google Chrome logoGoogle revels in hacking contests as ways of testing Chrome's worth. Even if the browser is compromised, the failure provides a shot at fixing an exploit under much safer circumstances than an in-the-wild attack. No better example exists than the results of Google's Pwnium 2 challenge in Malaysia: the company has already patched vulnerabilities found in the contest that surround SVG images and IPC (inter-process communication) before they become real problems. Staying one step ahead of truly malicious hackers carries a price, however. Pwnium 2 winner Pinkie Pie -- yes, Pinkie Pie -- is being paid $60,000 in prize money for catching the exploits. That may be a small price to pay if it reassures a few more Internet Explorer users looking to hop the fence.

Filed under: ,

Google patches SVG and IPC exploits in Chrome, discoverer banks $60,000 in the process originally appeared on Engadget on Thu, 11 Oct 2012 09:31:00 EDT. Please see our terms for use of feeds.

Permalink   |  sourceGoogle Chrome Releases  | Email this | Comments

Google teases hackers with $2 million in prizes, announces Pwnium 2 exploit competition

Google teases hackers with $2 million in prizes, announces Pwnium 2 exploit competitionThe folks in Mountain View are starting to make a habit of getting hacked -- intentionally, that is. Earlier this year, Google hosted an event at the CanSecWest security conference called Pwnium, a competition that challenged aspiring hackers to poke holes in its Chrome browser. El Goog apparently learned so much from the event that it's doing it again -- hosting Pwnium 2 at the Hack in the Box 10th anniversary conference in Malaysia and offering up to $2 million in rewards. Bugging out the browser by exploiting its own code wins the largest award, a cool $60,000. Enlisting the help of a WebKit or Windows kernel bug makes you eligible for a $50,000 reward, and non-Chrome exploits that rely on a bug in Flash or a driver are worth $40,000. Not confident you can break Chrome? Don't let that stop you -- Google plans to reward incomplete exploits as well, noting that it has plenty to learn from unreliable or incomplete attacks. Check out the Chromium Blog at the source link below for the full details.

Filed under: ,

Google teases hackers with $2 million in prizes, announces Pwnium 2 exploit competition originally appeared on Engadget on Thu, 16 Aug 2012 11:12:00 EDT. Please see our terms for use of feeds.

Permalink   |  sourceGoogle  | Email this | Comments