Should We Call Satellite Hackers Space Invaders?

Source: The Register Should We Call Satellite Hackers Space Invaders?

Stop Us If You’ve Heard This One Before

Today The Register published a reminder of just how vulnerable the roughly 12,000 satellites orbiting the Earth are to hacking attempts.  Yamcs is an open source application used by NASA and Airbus which has five known CVEs in the code that would allow an attacker to gain complete control over the software on satellites which use the software.  OpenC3 Cosmos, another open source app commonly used in ground station systems has seven CVEs, five of which can be leveraged for remote code execution and cross-site scripting attacks.

NASA’s Core Flight System software, Aquila, has four critical flaws one of which is a remote-code-execution vulnerability and CryptoLib which is used in large number of satellites contains seven serious flaws; NASA’s modified version still has four.  These include a flaw which can be exploited by an unauthenticated telephone which lets you crash the entire onboard software and when it reboots none of the previous security keys are recreated, leaving the satellite’s systems open for anyone to play with.

One could say that the gravity of these flaws can’t be overstated.

Four countries have now tested anti-satellite missiles (the US, China, Russia, and India), but it's much easier and cheaper just to hack them.

Video News

About The Author

Jeremy Hellstrom

Call it K7M.com, AMDMB.com, or PC Perspective, Jeremy has been hanging out and then working with the gang here for years. Apart from the front page you might find him on the BOINC Forums or possibly the Fraggin' Frogs if he has the time.

Leave a reply

Your email address will not be published. Required fields are marked *

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Latest Podcasts

Archive & Timeline

Previous 12 months
Explore: All The Years!