SlideShare a Scribd company logo
Hacking the aerospace
industry – should we
worry?
Jakub Kaluzny
European Space Agency, Madrid, 2015
whoami
ESAC project in 2012, beer&tapas lover
Sr. IT Security Consultant at SecuRing
• Consulting all phases of development
• penetration tests
• high-risk applications and systems
Researcher
• Hadoop, FOREX, MFP printers, proprietary network protocols
• Aerospace industry?
Agenda – hacking space industry
Who is your enemy?
What can be hacked?
How to protect?
WHO?
Script-kiddies
More sophisticated script-kiddies
Whitehats
Bounty hunters
Professionals
WHAT?
What can be hacked?
Software
• Company website
Hardware
Process
People
Company website deface
Company website deface
What can be hacked?
Software
• Company website
• Web app controlling telescope
Hardware
Process
People
Web application controlling telescope
http://hdwyn.com/european_extremely_large_telescope_chili_hd-wallpaper-89939/
Web application controlling telescope
http://hdwyn.com/european_extremely_large_telescope_chili_hd-wallpaper-89939/ http://www.damncoolpictures.com/2014/11/these-photos-will-definitely-mess-with.html
What can be hacked?
Software
• Company website
• Web app controlling telescope
• Operations centre
Hardware
Process
People
Operations centre information
Goldeneye weapon of mass destruction
http://jamesbond.wikia.com/wiki/Satellites
What can be hacked?
Software
Hardware
• Take over a satellite
Process
People
Tamil Tigers hacked a satellite
http://pixgood.com/aryabhatta-satellite.html
GPS clocks
What can be hacked?
Software
Hardware
• Take over a satellite
• Jamming / tampering GPS signal
Process
People
Hacking drones by tampering GPS signal
Tomorrow never dies GPS signal jamming
What can be hacked?
Software
Hardware
• Take over a satellite
• Jamming / tampering GPS signal
• Communication with rockets / spacecrafts / space stations
Process
People
Amateur radio ham contacts ISS
What can be hacked?
Software
Hardware
Process
• Remote software update
People
Voyager 1
https://en.wikipedia.org/wiki/Voyager_1
Exported encryption is bad enough
What can be hacked?
Software
Hardware
Process
• Remotely updating software
• Deploying software on a telescope / spaceship / whatever
People
Malware infects developers
SCADA worm
What can be hacked?
Software
Hardware
Process
People
• ?
Phishing
Albanian virus
https://ifunny.co/tags/virus/1441876610
HOW TO PROTECT?
Who can possibly attack your solution?
How can he achieve it?
What can you do?
How to protect?
http://the-tech-guy.net/2012/10/30/an-ultimate-solution-that-stops-people-from-hacking-your-
passwords/
Should we worry?
Thank you
Now go and change your passwords
jakub.kaluzny@securing.pl
MORE THAN
SECURITY
TESTING
Free security consultancy service:
www.securing.pl/konsultacje @j_kaluzny

More Related Content

PDF
Deception in Cyber Security (League of Women in Cyber Security)
Phillip Maddux
 
PPTX
Nsc42 - is the cloud secure - is easy if you do it smart Cybersecurity&Cloud ...
NSC42 Ltd
 
PPTX
Nsc42 - is the cloud secure - is easy if you do it smart UNICOM
NSC42 Ltd
 
PDF
Application Security by Ethical Hackers
Entersoft
 
PPTX
Nsc42-CSA AGM is the cloud secure - is easy if you do it smart
NSC42 Ltd
 
PDF
How to scale mobile application security testing
NowSecure
 
PDF
5 Reasons to attend iqnite 2014 Conference
KJR
 
PDF
Compliance in the mobile enterprise: 5 tips to prepare for your next audit
NowSecure
 
Deception in Cyber Security (League of Women in Cyber Security)
Phillip Maddux
 
Nsc42 - is the cloud secure - is easy if you do it smart Cybersecurity&Cloud ...
NSC42 Ltd
 
Nsc42 - is the cloud secure - is easy if you do it smart UNICOM
NSC42 Ltd
 
Application Security by Ethical Hackers
Entersoft
 
Nsc42-CSA AGM is the cloud secure - is easy if you do it smart
NSC42 Ltd
 
How to scale mobile application security testing
NowSecure
 
5 Reasons to attend iqnite 2014 Conference
KJR
 
Compliance in the mobile enterprise: 5 tips to prepare for your next audit
NowSecure
 

More from Jakub Kałużny (8)

PDF
The Hacker's Guide to NOT Getting Hacked
Jakub Kałużny
 
PDF
Pentesting voice biometrics solutions - AusCERT 2017
Jakub Kałużny
 
PDF
Zeronights 2015 - Big problems with big data - Hadoop interfaces security
Jakub Kałużny
 
PDF
Script based malware detection in online banking
Jakub Kałużny
 
PPTX
BSides London 2015 - Proprietary network protocols - risky business on the wire.
Jakub Kałużny
 
PPTX
Bypassing malware detection mechanisms in online banking
Jakub Kałużny
 
PPTX
Shameful Secrets of Proprietary Network Protocols - OWASP AppSec EU 2014
Jakub Kałużny
 
PPTX
In The Middle of Printers - The (In)Security of Pull Printing solutions - Hac...
Jakub Kałużny
 
The Hacker's Guide to NOT Getting Hacked
Jakub Kałużny
 
Pentesting voice biometrics solutions - AusCERT 2017
Jakub Kałużny
 
Zeronights 2015 - Big problems with big data - Hadoop interfaces security
Jakub Kałużny
 
Script based malware detection in online banking
Jakub Kałużny
 
BSides London 2015 - Proprietary network protocols - risky business on the wire.
Jakub Kałużny
 
Bypassing malware detection mechanisms in online banking
Jakub Kałużny
 
Shameful Secrets of Proprietary Network Protocols - OWASP AppSec EU 2014
Jakub Kałużny
 
In The Middle of Printers - The (In)Security of Pull Printing solutions - Hac...
Jakub Kałużny
 

Recently uploaded (20)

PDF
OFFOFFBOX™ – A New Era for African Film | Startup Presentation
ambaicciwalkerbrian
 
PDF
Google I/O Extended 2025 Baku - all ppts
HusseinMalikMammadli
 
PPTX
cloud computing vai.pptx for the project
vaibhavdobariyal79
 
PDF
Unlocking the Future- AI Agents Meet Oracle Database 23ai - AIOUG Yatra 2025.pdf
Sandesh Rao
 
PDF
Software Development Methodologies in 2025
KodekX
 
PDF
Research-Fundamentals-and-Topic-Development.pdf
ayesha butalia
 
PDF
Automating ArcGIS Content Discovery with FME: A Real World Use Case
Safe Software
 
PDF
Tea4chat - another LLM Project by Kerem Atam
a0m0rajab1
 
PDF
A Strategic Analysis of the MVNO Wave in Emerging Markets.pdf
IPLOOK Networks
 
PPTX
AI in Daily Life: How Artificial Intelligence Helps Us Every Day
vanshrpatil7
 
PPTX
New ThousandEyes Product Innovations: Cisco Live June 2025
ThousandEyes
 
PDF
Structs to JSON: How Go Powers REST APIs
Emily Achieng
 
PPTX
What-is-the-World-Wide-Web -- Introduction
tonifi9488
 
PPTX
AI and Robotics for Human Well-being.pptx
JAYMIN SUTHAR
 
PDF
Get More from Fiori Automation - What’s New, What Works, and What’s Next.pdf
Precisely
 
PDF
MASTERDECK GRAPHSUMMIT SYDNEY (Public).pdf
Neo4j
 
PDF
REPORT: Heating appliances market in Poland 2024
SPIUG
 
PPTX
IT Runs Better with ThousandEyes AI-driven Assurance
ThousandEyes
 
PPTX
Dev Dives: Automate, test, and deploy in one place—with Unified Developer Exp...
AndreeaTom
 
PPTX
Applied-Statistics-Mastering-Data-Driven-Decisions.pptx
parmaryashparmaryash
 
OFFOFFBOX™ – A New Era for African Film | Startup Presentation
ambaicciwalkerbrian
 
Google I/O Extended 2025 Baku - all ppts
HusseinMalikMammadli
 
cloud computing vai.pptx for the project
vaibhavdobariyal79
 
Unlocking the Future- AI Agents Meet Oracle Database 23ai - AIOUG Yatra 2025.pdf
Sandesh Rao
 
Software Development Methodologies in 2025
KodekX
 
Research-Fundamentals-and-Topic-Development.pdf
ayesha butalia
 
Automating ArcGIS Content Discovery with FME: A Real World Use Case
Safe Software
 
Tea4chat - another LLM Project by Kerem Atam
a0m0rajab1
 
A Strategic Analysis of the MVNO Wave in Emerging Markets.pdf
IPLOOK Networks
 
AI in Daily Life: How Artificial Intelligence Helps Us Every Day
vanshrpatil7
 
New ThousandEyes Product Innovations: Cisco Live June 2025
ThousandEyes
 
Structs to JSON: How Go Powers REST APIs
Emily Achieng
 
What-is-the-World-Wide-Web -- Introduction
tonifi9488
 
AI and Robotics for Human Well-being.pptx
JAYMIN SUTHAR
 
Get More from Fiori Automation - What’s New, What Works, and What’s Next.pdf
Precisely
 
MASTERDECK GRAPHSUMMIT SYDNEY (Public).pdf
Neo4j
 
REPORT: Heating appliances market in Poland 2024
SPIUG
 
IT Runs Better with ThousandEyes AI-driven Assurance
ThousandEyes
 
Dev Dives: Automate, test, and deploy in one place—with Unified Developer Exp...
AndreeaTom
 
Applied-Statistics-Mastering-Data-Driven-Decisions.pptx
parmaryashparmaryash
 

ESA - Hacking the aerospace industry - should we worry ?