How 2 Web Flaws Can Compromise Satellite Mission Control
Big thanks to DeleteMe for sponsoring this video. Protect your business with DeleteMe by using the following Link: https://joindeleteme.com/bombal-biz You’ll also get a free year of social media protection for every seat you purchase.
How do you hack a satellite? The attack can start on the ground. Watch a mission control demo showing how web vulnerabilities can change a simulated spacecraft’s orbit.
At DEF CON, I meet Milenko and Andrzej, the authors of The Spacecraft Hackers Handbook, to explore spacecraft cybersecurity. They explain the infrastructure behind satellite operations, what the Viasat attack actually targeted, and why protecting spacecraft requires both security and space engineering knowledge. Then Andrzej demonstrates previously patched vulnerabilities in an older version of mission control software. Using Burp Suite, he shows how path traversal exposes configuration files and how cross-site scripting can trigger a spacecraft command through an operator’s browser.
We cover:
• Why satellite security extends to systems on the ground
• How path traversal and XSS affect mission control software
• Telemetry, telecommands, CCSDS and the SDLS security layer
• How GPS supports timing as well as navigation
• Python examples, a prepared lab VM and learning resources
• The authors’ nine satellite cybersecurity challenges on Hack The Box
• Skills and career opportunities in spacecraft cybersecurity
The demonstration uses a spacecraft simulator. The vulnerabilities shown were disclosed to the vendor and patched.
// Link to No Starch Website for Milenko and Andrzej’s Book//
The Spacecraft Hacker’s Handbook: https://nostarch.com/spacecraft-hackers-handbook
Use Coupon Code SPACE25 for 25% off The Spacecraft Hacker’s Handbook.
// Milenko Starcik’s SOCIALS //
Website: https://visionspace.com/team/milenko-starcik/
Website 2: https://starcik.space/
// Andrzej Olchawa’s SOCIALS //
Website: https://visionspace.com/author/a-olchawa/
// Online Resources //
https://spacesecurity.club
https://github.com/orgs/spacecrafthacking
// Blog Post REFERENCE //
https://www.hackthebox.com/blog/hack-the-orbit-satellite-exploitation-track
// David's SOCIAL //
Discord: https://discord.com/invite/usKSyzb
X: https://www.twitter.com/davidbombal
Instagram: https://www.instagram.com/davidbombal
LinkedIn: https://www.linkedin.com/in/davidbombal
Facebook: https://www.facebook.com/davidbombal.co
TikTok: http://tiktok.com/@davidbombal
YouTube: https://www.youtube.com/@davidbombal
Spotify: https://open.spotify.com/show/3f6k6gERfuriI96efWWLQQ
SoundCloud: https://soundcloud.com/davidbombal
Apple Podcast: https://podcasts.apple.com/us/podcast/david-bombal/id1466865532
// MY STUFF //
https://www.amazon.com/shop/davidbombal
// SPONSORS //
Interested in sponsoring my videos? Reach out to my team here: sponsors@davidbombal.com
// MENU //
0:00 - Intro
0:52 - How Russia hacked satellites
02:12 - The Spacecraft Hacker's Handbook
03:23 - VisionSpace
04:04 - DeleteMe sponsor segment
05:29 - Growth in satellites launched
06:28 - What would losing satellites mean
07:12 - Protocols explained
08:00 - Misconceptions of satellite hacking
09:28 - Threat level of satellite hacking
10:39 - Upcoming demo explained
12:20 - Who is the book for?
16:46 - A gap
17:48 - Other recommendations
19:49 - Hacking satellite demo overview
20:34 - Hacking satellite demo walkthrough
33:54 - Demo next steps
34:29 - Demo walkthrough continued
38:51 - Conclusion
Please note that links listed may be affiliate links and provide me with a small percentage/kickback should you use them to purchase any of the items listed or recommended. Thank you for supporting me and this channel!
Disclaimer: This video is for educational purposes only.
#sattelitehacking #spacecraftcybersecurity #defcon
David Bombal
Want to learn about IT? Want to get ahead in your career? Well, this is the right place! On this channel, I discuss Linux, Python, Ethical Hacking, Networking, CCNA, Virtualization and other IT related topics. This YouTube channel has new videos upload...