I wish people wouldn't do shit like this on live systems like this one. Even the port scan could have had bad consequences (especially since this person did -A). By all means explore the interesting JSON object that was downloaded and yeah I'd worry about installing random stuff on my machine. I'm not talking about crashing the plane; I'm talking about crashing the IFE and me then having to sit through 10 hours of pe…
Boeing 787 In Flight Entertainment System Security fun
81–90 of 147 posts
Re: Boeing 787 In Flight Entertainment System Security fun
#82There's a lot of posts mentioning that a scan shouldn't cause any trouble, however there's no way of knowing how the services are configured on the other end, or how they are set up to respond to certain packet types, or how the server will respond to certain data within those packets if said data does not conform to expected lengths etc. A lot of assumptions are made that non-conforming data will be ignored in a clo…
Re: Boeing 787 In Flight Entertainment System Security fun
#83Earlier quoted context omitted.
> definitely shouldn't affect the avionics No, and the flaw you're busy exploiting also definitely shouldn't be there. (Yes, the IFE is probably airgapped. Probably.)
Since when are web servers DO-178 certified?
Re: Boeing 787 In Flight Entertainment System Security fun
#84Earlier quoted context omitted.
If anything were to happen, it definitely shouldn't affect the avionics, not even remotely, or the plane would not have had a chance of certification. Data to the less secure IFE had better flow through a unidirectional network ("data diode"), and/or use a separate set of sensors. Even if it brought down the server, it's still nothing that the flight attendants can't solve by "turning it off and back on". This kind o…
I agree that, in theory, at least the avionics shouldn't be accessible from the IFE. I am sure there is a rigorous protocol for making sure this is properly secured and certification for airworthiness. I think the parent comment was more making the point that we don't need a flight full of people scanning ports for fun and profit, and the consequences of doing so are unknown and could lead to things like no wifi or I…
Re: Boeing 787 In Flight Entertainment System Security fun
#85> I did a port scan on the System Control Unit Is that still white hat? Did they also check to see if the cockpit door is locked?
I think if you are not specifically asked to do it, it isn't white hat, and I think (but am not 100% sure) the law is like that. I don't know what hat it is, but white it isn't.
Re: Boeing 787 In Flight Entertainment System Security fun
#86Reading through the post it didn't seem like he found any security issues. Their map has javascript variables which isn't a security issue. It doesn't seem like SCU had many open ports. It was running a relatively new version of Linux.
Why is this blog post being upvoted?
Re: Boeing 787 In Flight Entertainment System Security fun
#87Beside a scan is good or bad, how would they go about finding the source? There wont be an IT officr at landing collecting logs/mac address from any wireless card. I've scanned those systems many times and nothing ever happened - i am just pointing out to the issue that catching a real attacker it is hard not just technically but in practice
Re: Boeing 787 In Flight Entertainment System Security fun
#88Earlier quoted context omitted.
Accidents happen. Commenter below referenced Swiss Air 111: https://en.m.wikipedia.org/wiki/Swissair_Flight_111 They cite inadequate safety standards and an overheating entertainment system. It's easy to assume that government or the airlines wouldn't allow a faulty system to fly, but just like software it's those extreme edge cases that cause problems. Somehow I doubt hacking the entertainment system is comprehensiv…
This keeps getting cited on this thread. The IFE didn't simply "overheat". It had faulty wiring . The coffee maker could just as easily have caused that accident.
Half the bugs I notice in Chrome, I notice because my laptop fan starts running.
Re: Boeing 787 In Flight Entertainment System Security fun
#89I wish people wouldn't do shit like this on live systems like this one. Even the port scan could have had bad consequences (especially since this person did -A). By all means explore the interesting JSON object that was downloaded and yeah I'd worry about installing random stuff on my machine. I'm not talking about crashing the plane; I'm talking about crashing the IFE and me then having to sit through 10 hours of pe…
Re: Boeing 787 In Flight Entertainment System Security fun
#90I wish people wouldn't do shit like this on live systems like this one. Even the port scan could have had bad consequences (especially since this person did -A). By all means explore the interesting JSON object that was downloaded and yeah I'd worry about installing random stuff on my machine. I'm not talking about crashing the plane; I'm talking about crashing the IFE and me then having to sit through 10 hours of pe…
Thank you for this comment. I for one would be pretty pissed if a "hacker" decided to crash my/or my kids entertainment on a long flight. There is definitely a need for this type of work, but doing so in a 50,000 lb brick floating a few miles above the ground isn't an atmosphere I am comfortable with, especially if I am present...