Live data from Hacker News

SATCOM terminals under attack in Europe: a plausible analysis

reversemode.com

61–70 of 79 posts

Re: SATCOM terminals under attack in Europe: a plausible analysis

#61

Seems entirely plausible to me that someone pushed a firmware update which corrupted the firmware (even maybe at the fpga/bootcode level) and effectively bricked the devices. Not horribly complicated to do and once you've done it it would require physical access to recover each device individually. Is there a plausible explanation for who would do this, besides Russia? Is Viasat/Eutelsat a particularly good target fo…

Viasat KA-SAT was used by Ukraine for some Military and Government communications. The US, perhaps acting on intelligence preceding the Viasat attack, provided Zelenskywith an Iridium 9575A. https://www.cnn.com/europe/live-news/ukraine-russia-putin-ne...

>"Initially it took a few days for the Ukrainians to get the satellite phones up and working because the instructions on how to use it were in English, not in Ukrainian."

Seriously?! Did the president hire my parents to set up his satellite phone? I refuse to believe that a nation state doesn't have at least a couple of techs on their payroll with decent command of English. If this is true then it's just embarrassing on so many levels and I'm really afraid of how Ukraine has a chance at winning this war.

Re: SATCOM terminals under attack in Europe: a plausible analysis

#62
post #5

I've investigated network equipment before, my findings were that you shouldn't trust any of it and use a standard Linux box whenever possible. The worst was consumer-grade modems/routers with low-hanging fruits such as backdoors, "forgotten" telnet servers left enabled, shell command injection in the web UI, etc but even enterprise stuff had its problems (thankfully, at least on enterprise stuff you can disable the…

From personal experience (I guess now that the statue of limitations has passed..) I was part of a large community of people in the not so distant past hacking into cable ISPs. Small ones were easy to bypass security mechanisms and spoof other customers devices or simply trick their servers into issuing valid configs, but obviously there was the one big one that I’m sure everyone has heard of. Anyway, before the community was shut down, in the quest to defeat the more stringent security mechanisms, a few folks figured out how to jump from modems to an internal VLAN, got access to privileged SNMP communities and eventually owned the entire network starting at the head ends and eventually made their way to the core routers (Of course, the provider used the same credentials for everything, in an industry that to this day doesn’t use 2FA). Eventually the community was shut down. However, said ISP never acknowledged the breach. If some hobbyists could figure it out, I guarantee that nation-states can do it.

Re: SATCOM terminals under attack in Europe: a plausible analysis

#63

Simultaneously, Russian ground forces have had a hell of a time using their encrypted radios, resulting in the logistical and tactical omnishambles observed by many, and fallback transmitting in the clear using civilian ham radios or cell phones. Some have attributed this to difficulty in distributing encryption keys to forward units or just general incompetence, but one fun theory I saw on twitter is that Russia use…

https://twitter.com/ralee85/status/1367614591698690056

>Interfax reports that the Deputy Chief of the General Staff and the most senior communications officer in the Russian military, Colonel General Khalil Arslanov, has been arrested for fraud in relation to the purchase of special equipment.

>The case involves Colonel Pavel Kutakhov, who was arrested last week for stealing an estimated 30 M RUB from an 800 M RUB contract for comm systems.

30M rubles, pocket change

>Kommersant reports that Colonel General Khalil Arslanov, head of Russia's Signal Troops and Deputy Chief of the General Staff, was charged in the theft of 2.2 B RUB and was hospitalized after suffering a hypertensive crisis during his interrogation

2B rubles, now we are starting to talk real money

>After expanding their investigation, investigators discovered that Russian troops had received equipment that was made in China even though it was supposed to be from Russia (they changed the labels).

>The investigation isn't limited to 2.2 B RUB worth of theft, but also to fraud related to contracts for the Azart comm system built by NPO Angstrem JSC and Yaroslavl Radio Plant. Of 18 B RUB spent on the radios, 6.5 B RUB might have been stolen due to artificially high prices

6B rubles, ouch

>Arslanov says that they saved so much on the purchase of R-187-P1 Azart radios, 6.7 B RUB of the contract's 18.5 B RUB was allegedly embezzled, because the radios were purchased from China in almost finished form with some components added in Russia

so corruption and potentially backdoored by China

and this is how you end up with https://twitter.com/radio_research/status/150084725994823680... Chechen soldiers wearing 3 non military radios (susceptible to basic radio finding/tracking), one being Motorola DRM and two analogs.

Re: SATCOM terminals under attack in Europe: a plausible analysis

#64
post #5

I've investigated network equipment before, my findings were that you shouldn't trust any of it and use a standard Linux box whenever possible. The worst was consumer-grade modems/routers with low-hanging fruits such as backdoors, "forgotten" telnet servers left enabled, shell command injection in the web UI, etc but even enterprise stuff had its problems (thankfully, at least on enterprise stuff you can disable the…

From personal experience (I guess now that the statue of limitations has passed..) I was part of a large community of people in the not so distant past hacking into cable ISPs. Small ones were easy to bypass security mechanisms and spoof other customers devices or simply trick their servers into issuing valid configs, but obviously there was the one big one that I’m sure everyone has heard of. Anyway, before the comm…

rip www.sbhacker.net

Re: SATCOM terminals under attack in Europe: a plausible analysis

#65
post #5

I've investigated network equipment before, my findings were that you shouldn't trust any of it and use a standard Linux box whenever possible. The worst was consumer-grade modems/routers with low-hanging fruits such as backdoors, "forgotten" telnet servers left enabled, shell command injection in the web UI, etc but even enterprise stuff had its problems (thankfully, at least on enterprise stuff you can disable the…

> What I think happened is that they breached the control infrastructure which gives them access to an "internal" VLAN that the satellite terminals use to communicate with the mothership for ...

> ... whatever is the TR-069 equivalent for BGAN terminals ...

These VSAT terminals support TR-069 [0] and my first thought when I heard about this was a compromised ACS. It wouldn't be the first time.

---

[0]: https://en.m.wikipedia.org/wiki/TR-069

Re: SATCOM terminals under attack in Europe: a plausible analysis

#66

Simultaneously, Russian ground forces have had a hell of a time using their encrypted radios, resulting in the logistical and tactical omnishambles observed by many, and fallback transmitting in the clear using civilian ham radios or cell phones. Some have attributed this to difficulty in distributing encryption keys to forward units or just general incompetence, but one fun theory I saw on twitter is that Russia use…

To be fair, ten years ago in Afghanistan I observed a lot of difficulty with encrypted radios on the US side too. The SATCOM radios on our very expensive aircraft seemed to work only a bit more than half the time. Actual military radios are cumbersome and limited, and the keys change constantly, and the keys are a pain to load. Civilian cellphones and cheap walkie-talkies were used for a lot of communications that probably should have been encrypted.

Re: SATCOM terminals under attack in Europe: a plausible analysis

#67
It's not clear how any of the suggested attacks constitute 'permanent' damage: disabling the transmitter, corrupting the antenna pointing logic, demod, power params can all be solved by reflashing the firmware and FPGAs. Not always simple but possible at least by the manufacturer.

One way to really destroy a transmitter is to transmit at full power without an antenna attached. Another is to burn the receiver front end by directing the full transmitter output to the receiver input. If the RF path is configured with software controlled RF switches a hack could burn out the front end circuitry for good. All depends on how permanent we're talking.

Re: SATCOM terminals under attack in Europe: a plausible analysis

#68
post #20

Earlier quoted context omitted.

It's easy to buy an end-user terminal and tear it apart on your workbench to develop an understanding of how it works. I don't know about you, but I haven't seen any satellites on eBay recently. Also, most satellites are intentionally as dumb as possible, just a "bent pipe" transponder, putting all the complexity on the ground stations which are easier to service if something goes wrong. There might not be much to do…

With the right commands, you could flip the satellite by 180 degrees, move it from Europe to the pacific ocean, or crash it into one of its neighbors. All geostationary satellites need to be capable of at least some station-keeping to correct for drift, move them to other service areas, or move them to a graveyard orbit at their end of life. (Unlike LEO, GEO satellites don't carry enough fuel for de-orbiting, and fri…

that is a completely separate layer run by and built by a different company using technology from 20 years ago

Re: SATCOM terminals under attack in Europe: a plausible analysis

#69

Seems entirely plausible to me that someone pushed a firmware update which corrupted the firmware (even maybe at the fpga/bootcode level) and effectively bricked the devices. Not horribly complicated to do and once you've done it it would require physical access to recover each device individually. Is there a plausible explanation for who would do this, besides Russia? Is Viasat/Eutelsat a particularly good target fo…

> Is there a plausible explanation for who would do this, besides Russia? Any engineer could accidentally do it... I can totally imagine the release engineer accidentally pushing the dev version, only to realise later that the dev version doesn't have quite the right config to connect for example. Blaming it on a cyber attack is a lot less bad than saying "whoops, we bricked everyone's modems".

Release engineer would own up to it. There would be a trail, with no attempt to hide it.

Re: SATCOM terminals under attack in Europe: a plausible analysis

#70

Elon Musk mentioned this attack in one of his tweets a few days ago: https://twitter.com/elonmusk/status/1499585449450344451

Replying to @elonmusk Is there anything to stop it on starlink?

Musk replies "game on".

The russians have recently demonstrated their ability to physically take out satelites, and willingness to use it. If Putin did that, creating a lot of debris, US would loose the space advantage and we would push human advancement in to space back by perhaps 1000 years while we wait for the skys to clear.

US MUST stop provoking Russia.

"game on" is hard to interpret as anything but a flippant challenge to a dangerous man with military resources in space.

Is diplomacy that hard to grok?

Post reply on HN