SlideShare a Scribd company logo
1 of 52
Download to read offline
Hacking a Bird in the Sky
The Revenge of Angry Birds

Jim Geovedi, Raditya Iryandi, Raoul Chiesa
Satellite Communication
When terrestrial communication FAIL, we PREVAIL!




                                                   Arthur C. Clarke
                                                      1917-2008
Broadcast Video to
  Cable Headends

                                                                       Local ISPs



Direct Broadcast TV                                       Video
Last-mile Broadband                                     Contribution




Corporate Data Networks                 Teleport              PSTN
 (Interactive & Multicast)
                                                                               End Users


                             Teleport              Internet

                                                                   End Users
average distance to moon:
                                                                         384,400 km
 Medium Earth Orbit
 Altitude: 8,000-20,000 km




                              Low Earth Orbit
EARTH
                             Altitude: 500-2,000 km




                                                      Geostationary Orbit
                                                        Altitude: 35,786 km




                                                       Highly Elliptical Orbit
                                                          Altitude: >35,786 km
Propulsion System



                             Telemetry, Attitude Control,
         Solar Arrays        Commanding, Fuel, Batteries,           Solar Arrays
                             Power/Thermal Systems



              Transponder    Down-converter,     High Power,       Transponder
                  Receiver   Pre-amplifier,      Amplifier,        Transmitter
                   Section   Filter              Filter            Section
RX Antenna                                                                       TX Antenna
    Jakarta                                                                      Jayapura

                              Uplink                    Downlink




                         Earth Stations / Antennas
Telkom-1 Footprint / 108.0º East (C Band)




    C Band
  38   40   42
Frequency Band Designations
Example of Frequency and Polarisation Distribution
                                                                                            Transmit

                    3720          3760          3800          3840          3880          3920          3960          4000          4040          4080          4120          4160      4199
                      1             3            5             7             9             11            13            15            17            19            21            23       T/M
  Polarisation
   Horizontal




                 3701      3740          3780          3820          3860          3900          3940          3980          4020          4060          4100          4140          4180
                 T/M         2             4            6             8             10            12            14            16            18            20            22            24
  Polarisation
    Vertical




                                                                                          Frequency MHz
                 3700                                                                                                                                                                   4200




                                                                                            Receive

                    5945          5985          6025          6065          6105          6145          6185          6225          6265          6305          6345          6385      6424
                      1             3            5             7             9             11            13            15            17            19            21            23       CMD
  Polarisation
    Vertical




                           5965          6005          6045          6085          6125          6165          6205          6245          6285          6325          6365          6405
                             2             4            6             8             10            12            14            16            18            20            22            24
  Polarisation
   Horizontal




                                                                                          Frequency MHz
                 5925                                                                                                                                                                   6245

                             Channel spacing = 40 MHz — Usable bandwidth = 36 MHz
VSAT / Very Small Aperture Terminal


‣    Two-way satellite communication
‣    Use small dish antennas
     (diameter: 75cm-2,4m)
‣    Managed by the HUB
     (master earth station)
VSAT / Services



‣   One-way multicast
‣   One-way with terrestrial return
‣   Two-way satellite access
VSAT Network Topologies / Simplex Transmission




 Hub Equipment                Hub Equipment       Hub Equipment    Hub Equipment



  TV Station / HQ Network                     Affiliated TV Stations
VSAT Network Topologies / Point-to-Point Duplex Transmission




   Public Network                                 Public Network



   Private Network   CPE                 CPE     Private Network



   Customer Site                                  Customer Site
VSAT Network Topologies / Point-to-Multipoint Transmission




      CPE                           CPE                 CPE


 Network or Sites              Network or Sites    Network or Sites
VSAT Network Topologies / Mobile Antenna Service




                 Public Network



 Hub Equipment   Private Network



                  Customer Site
VSAT Network Topologies / Star Network




 Hub Equipment                Hub Equipment     Hub Equipment     Hub Equipment



  Public/Private Networks                     Networks or Sites
VSAT Network Topologies / Mesh Network




     Hub Equipment       Hub Equipment       Hub Equipment



   Networks or Sites   Networks or Sites   Networks or Sites
Access Methods / FDMA (Frequency Division Multiple Access)




         f1    f2   f3


                                       Transponder

          f1             f2                      f3
Access Methods / TDMA (Time Division Multiple Access)




             f1


                                        Transponder

            f1

                       f1
                                   f1          f1
Access Methods / CDMA (Code Division Multiple Access)

        ++++++++++++++++++++++++++++++++++++++++++
        xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
        oooooooooooooooooooooooooooooooooooooooooo
        ------------------------------------------

                                        Transponder




          f1          f1           f1         f1
Satellite Vulnerabilities
Current systems are vulnerable to a variety of attacks, and
future systems promise little improvement.
Unless you have millions of dollars and a team
of engineers, you have no hope of taking over
commercial or governmental satellites.

If someone did put together the power to try
such a stunt, they would be more likely to
damage a satellite than take it over.

How to Break into Satellites: Not!
Carolyn Meinel’s GUIDE TO (mostly) HARMLESS HACKING



                   Gobbles!
hackers will eventually find a way to hack
employees
                            management


      vendors


                              customers


           spieS

                      government

network of trust
It is worth noting that the most likely cause of damage
to or loss of service from a satellite is the actual operator.
Dan Veeneman
Dan Veeneman
   Low Earth Orbit Satellites

             Dan Veeneman
             Future & Existing Satellite Systems

                       Warezzman
                       DVB Satellite Hacking

                                  Jim Geovedi, Raditya Iryandi,
                                  Hacking a Bird in the Sky: Hijacking VSAT Connection

                                            Jim Geovedi, Raditya Iryandi, Anthony Zboralski
                                            Hacking a Bird in the Sky: Exploiting Satellite Trust Relationship

                                                      Adam Laurie
                                                      $atellite Hacking for Fun & Pr0fit!

                                                      Leonardo Nve Egea, Christian Martorella
                                                      Playing in a Satellite Environment 1.2

                                                      Jim Geovedi, Raditya Iryandi
                                                      Hacking Satellite: A New Universe to Discover

                                                                 Jim Geovedi, Raditya Iryandi, Raoul Chiesa
                                                                 Hacking a Bird in the Sky: The Revenge of Angry Birds




1996    1998       2004         2006    2008       2009      2011
Veeneman’s Satellite Hypothetical Attacks

Denial of Service   Orbital Positioning   Takeover Spare Satellite



                    Raging Transponder
                         Spoofing



                                                  ?
   Jam Uplink
                    Direct Commanding
Overpower Uplink
                     Command Replay
 Jam Downlink
                         Insertion
Satellite TT&C Ground Networks




                                              Frequency
    Network Gateway   Receivers/Modems
                                              Conversion



                                                                  Ground
                                             Geolocation          Antenna
                        Digital/Analog
                                              Spectrum
                      Record and Replay
                                             Monitoring


         IP



    Network Gateway       COMSEC          Front-end Processor




                                                            Command and Control
Land Earth Station Attacks
Satellite-based Attacks Against
ATMs and Bank Networks
It's not a big truck. It's a series of tubes.
TRADE FINANCE                          TREASURY


DATA WAREHOUSING



                              ANTI MONEY LAUNDERING
    REMITTANCE




                     CORE
                                               CRM




                                       ATM SWITCH
 COLLECTION SYSTEM


                                   MOBILE BANKING
 INTERNET BANKING


   ISLAMIC (SHARIA) BANKING      CARD MANAGEMENT
VSAT / Automated Teller Machine Networks




                     ATM               ATM             ATM           ATM




                 Standard Network
 Hub Equipment                      Hub Equipment   Hub Equipment   Hub Equipment
                    Equipment



      Core Banking Networks                  Automated Teller Machines
VSAT / Automated Teller Machine Networks
Automated Teller Machine
Automated Teller Machine
OMFGWTFKTHXBYE
The Usual Culprits




 People Problems         System Problems
      Weak Passwords          Outdated Systems
     Lack of Awareness     Insecure Configurations
       Lack of Skills         Insecure Protocols
MANAGEMENT PROBLEMS
Distributed Satellite Scanning
Framework
Identify potential problems at an early stage.
Framework Goals



‣   Dead or Alive status / checking if the bird is still alive
‣   Protocols / understand which protocols the target is running
‣   Service type / knowing which service we can (ab)use
‣   Distributed IP C&C / widening the coverage
Distributed IP C&C
Satellite Carrier Monitoring System



‣   Spectrum Analyser and Digital Spectrum Processor
    analysis
‣   Reference trace and measurement
‣   Automatic alerts for abnormal and missing carriers
Shared Data
What’s Next?
No, the journey doesn't end here.
http://www.dunnspace.com/leo_on_the_cheap.htm
Fin.
Jim Geovedi <jim@geovedi.com>, @geovedi
Raoul Chiesa <raoul.chiesa@mediaservice.net>

More Related Content

What's hot

Seismic Technology and Geophysical Flexibility
Seismic Technology and Geophysical FlexibilitySeismic Technology and Geophysical Flexibility
Seismic Technology and Geophysical FlexibilitySergey Starokadomsky
 
Doordarshan Presentation
Doordarshan Presentation  Doordarshan Presentation
Doordarshan Presentation Yash Verma
 
Bc2419681971
Bc2419681971Bc2419681971
Bc2419681971IJMER
 
Satellite Antenna Systems Brochure
Satellite Antenna Systems BrochureSatellite Antenna Systems Brochure
Satellite Antenna Systems BrochureSematron UK Ltd
 
Advanced Satellite Communications Systems Technical Training Course Sampler
Advanced Satellite Communications Systems Technical Training Course SamplerAdvanced Satellite Communications Systems Technical Training Course Sampler
Advanced Satellite Communications Systems Technical Training Course SamplerJim Jenkins
 
DOORDARSHAN KENDRA SUMMER TRAINING REPORT
DOORDARSHAN KENDRA SUMMER TRAINING REPORTDOORDARSHAN KENDRA SUMMER TRAINING REPORT
DOORDARSHAN KENDRA SUMMER TRAINING REPORTAnkur Gupta
 
Report on Doordarshan indore
Report on Doordarshan  indoreReport on Doordarshan  indore
Report on Doordarshan indoreAbhishek Roy
 
What is the main difference between single carrier and ofdm yahoo! answers
What is the main difference between single carrier and ofdm    yahoo! answersWhat is the main difference between single carrier and ofdm    yahoo! answers
What is the main difference between single carrier and ofdm yahoo! answersen_maruf78
 
Doordarshan industrial training report
Doordarshan industrial training reportDoordarshan industrial training report
Doordarshan industrial training reportSatyendra Gupta
 
Doordarshan Indore,Summer Training ppt
Doordarshan Indore,Summer Training pptDoordarshan Indore,Summer Training ppt
Doordarshan Indore,Summer Training pptAayush Shah
 
Ec2306 mini project report-matlab
Ec2306 mini project report-matlabEc2306 mini project report-matlab
Ec2306 mini project report-matlabunnimaya_k
 
Cambium networks pmp_450_access_point_specification
Cambium networks pmp_450_access_point_specificationCambium networks pmp_450_access_point_specification
Cambium networks pmp_450_access_point_specificationAdvantec Distribution
 
Satellite communication system
Satellite communication systemSatellite communication system
Satellite communication systemRoman M. Vitenberg
 

What's hot (20)

WDM Basics
WDM BasicsWDM Basics
WDM Basics
 
Seismic Technology and Geophysical Flexibility
Seismic Technology and Geophysical FlexibilitySeismic Technology and Geophysical Flexibility
Seismic Technology and Geophysical Flexibility
 
2G Topology
2G Topology2G Topology
2G Topology
 
Asr 9000-line-cards
Asr 9000-line-cardsAsr 9000-line-cards
Asr 9000-line-cards
 
Doordarshan Presentation
Doordarshan Presentation  Doordarshan Presentation
Doordarshan Presentation
 
Bc2419681971
Bc2419681971Bc2419681971
Bc2419681971
 
Paso neo a
Paso neo aPaso neo a
Paso neo a
 
Satellite Antenna Systems Brochure
Satellite Antenna Systems BrochureSatellite Antenna Systems Brochure
Satellite Antenna Systems Brochure
 
Advanced Satellite Communications Systems Technical Training Course Sampler
Advanced Satellite Communications Systems Technical Training Course SamplerAdvanced Satellite Communications Systems Technical Training Course Sampler
Advanced Satellite Communications Systems Technical Training Course Sampler
 
DOORDARSHAN KENDRA SUMMER TRAINING REPORT
DOORDARSHAN KENDRA SUMMER TRAINING REPORTDOORDARSHAN KENDRA SUMMER TRAINING REPORT
DOORDARSHAN KENDRA SUMMER TRAINING REPORT
 
TT&M Brochure
TT&M BrochureTT&M Brochure
TT&M Brochure
 
Report on Doordarshan indore
Report on Doordarshan  indoreReport on Doordarshan  indore
Report on Doordarshan indore
 
What is the main difference between single carrier and ofdm yahoo! answers
What is the main difference between single carrier and ofdm    yahoo! answersWhat is the main difference between single carrier and ofdm    yahoo! answers
What is the main difference between single carrier and ofdm yahoo! answers
 
Doordarshan industrial training report
Doordarshan industrial training reportDoordarshan industrial training report
Doordarshan industrial training report
 
Doordarshan Indore,Summer Training ppt
Doordarshan Indore,Summer Training pptDoordarshan Indore,Summer Training ppt
Doordarshan Indore,Summer Training ppt
 
Ec2306 mini project report-matlab
Ec2306 mini project report-matlabEc2306 mini project report-matlab
Ec2306 mini project report-matlab
 
Cambium networks cmm4_specification
Cambium networks cmm4_specificationCambium networks cmm4_specification
Cambium networks cmm4_specification
 
Cambium networks pmp_450_access_point_specification
Cambium networks pmp_450_access_point_specificationCambium networks pmp_450_access_point_specification
Cambium networks pmp_450_access_point_specification
 
Satellite communication system
Satellite communication systemSatellite communication system
Satellite communication system
 
MIMO in 4G Wireless
MIMO in 4G WirelessMIMO in 4G Wireless
MIMO in 4G Wireless
 

Similar to Hacking a Bird in the Sky: The Revenge of Angry Birds

Tranzeo TR-5a Series (quantumwimax.com)
Tranzeo TR-5a Series (quantumwimax.com)Tranzeo TR-5a Series (quantumwimax.com)
Tranzeo TR-5a Series (quantumwimax.com)Ari Zoldan
 
Fundamentals of Intelligent Compaction
Fundamentals of Intelligent CompactionFundamentals of Intelligent Compaction
Fundamentals of Intelligent Compactiongkchang
 
Tranzeo TR – CPQ Series (quantumwimax.com)
Tranzeo TR – CPQ Series (quantumwimax.com)Tranzeo TR – CPQ Series (quantumwimax.com)
Tranzeo TR – CPQ Series (quantumwimax.com)Ari Zoldan
 
2 Basic Principal Of Utp Installation
2 Basic Principal Of Utp Installation2 Basic Principal Of Utp Installation
2 Basic Principal Of Utp InstallationMrirfan
 
Overview of Photonics Research at Calit2: Scaling from Nanometers to the Earth
Overview of Photonics Research at Calit2: Scaling from Nanometers to the EarthOverview of Photonics Research at Calit2: Scaling from Nanometers to the Earth
Overview of Photonics Research at Calit2: Scaling from Nanometers to the EarthLarry Smarr
 
Tranzeo TR – 6000 Series (quantumwimax.com)
Tranzeo TR – 6000 Series (quantumwimax.com)Tranzeo TR – 6000 Series (quantumwimax.com)
Tranzeo TR – 6000 Series (quantumwimax.com)Ari Zoldan
 
Master thesis presentation
Master thesis presentationMaster thesis presentation
Master thesis presentationMayur Sarode
 
Final tssa design and realization of passive phase shifters
Final tssa design and realization of passive phase shiftersFinal tssa design and realization of passive phase shifters
Final tssa design and realization of passive phase shiftersDr.Joko Suryana
 
SKT Business Strategy of WCDMA
SKT Business Strategy of WCDMASKT Business Strategy of WCDMA
SKT Business Strategy of WCDMAPeter Kim
 
Tsl Capabilities Short Form Rev
Tsl Capabilities   Short Form RevTsl Capabilities   Short Form Rev
Tsl Capabilities Short Form RevEd Arcemont
 
Towards Terabit per Second Optical Networking
Towards Terabit per Second Optical NetworkingTowards Terabit per Second Optical Networking
Towards Terabit per Second Optical NetworkingCPqD
 
Constellations Demystified.ppt
Constellations Demystified.pptConstellations Demystified.ppt
Constellations Demystified.pptStefan Oprea
 
Transmission Line Basics
Transmission Line BasicsTransmission Line Basics
Transmission Line BasicsJohn Williams
 
SPICE MODEL of 2SK3938 (Standard+BDS Model) in SPICE PARK
SPICE MODEL of 2SK3938 (Standard+BDS Model) in SPICE PARKSPICE MODEL of 2SK3938 (Standard+BDS Model) in SPICE PARK
SPICE MODEL of 2SK3938 (Standard+BDS Model) in SPICE PARKTsuyoshi Horigome
 
Rdb45350 access point_specifications
Rdb45350 access point_specificationsRdb45350 access point_specifications
Rdb45350 access point_specificationsAdvantec Distribution
 

Similar to Hacking a Bird in the Sky: The Revenge of Angry Birds (20)

Tr5 Plus
Tr5 PlusTr5 Plus
Tr5 Plus
 
Tranzeo TR-5a Series (quantumwimax.com)
Tranzeo TR-5a Series (quantumwimax.com)Tranzeo TR-5a Series (quantumwimax.com)
Tranzeo TR-5a Series (quantumwimax.com)
 
Fundamentals of Intelligent Compaction
Fundamentals of Intelligent CompactionFundamentals of Intelligent Compaction
Fundamentals of Intelligent Compaction
 
Tranzeo TR – CPQ Series (quantumwimax.com)
Tranzeo TR – CPQ Series (quantumwimax.com)Tranzeo TR – CPQ Series (quantumwimax.com)
Tranzeo TR – CPQ Series (quantumwimax.com)
 
2 Basic Principal Of Utp Installation
2 Basic Principal Of Utp Installation2 Basic Principal Of Utp Installation
2 Basic Principal Of Utp Installation
 
Overview of Photonics Research at Calit2: Scaling from Nanometers to the Earth
Overview of Photonics Research at Calit2: Scaling from Nanometers to the EarthOverview of Photonics Research at Calit2: Scaling from Nanometers to the Earth
Overview of Photonics Research at Calit2: Scaling from Nanometers to the Earth
 
Photonics @ IITM
Photonics @ IITMPhotonics @ IITM
Photonics @ IITM
 
Tranzeo TR – 6000 Series (quantumwimax.com)
Tranzeo TR – 6000 Series (quantumwimax.com)Tranzeo TR – 6000 Series (quantumwimax.com)
Tranzeo TR – 6000 Series (quantumwimax.com)
 
Master thesis presentation
Master thesis presentationMaster thesis presentation
Master thesis presentation
 
Final tssa design and realization of passive phase shifters
Final tssa design and realization of passive phase shiftersFinal tssa design and realization of passive phase shifters
Final tssa design and realization of passive phase shifters
 
Tr5 Amp
Tr5 AmpTr5 Amp
Tr5 Amp
 
Lcd samsung sp20 so la20s51b
Lcd samsung sp20 so la20s51bLcd samsung sp20 so la20s51b
Lcd samsung sp20 so la20s51b
 
SKT Business Strategy of WCDMA
SKT Business Strategy of WCDMASKT Business Strategy of WCDMA
SKT Business Strategy of WCDMA
 
Tsl Capabilities Short Form Rev
Tsl Capabilities   Short Form RevTsl Capabilities   Short Form Rev
Tsl Capabilities Short Form Rev
 
Towards Terabit per Second Optical Networking
Towards Terabit per Second Optical NetworkingTowards Terabit per Second Optical Networking
Towards Terabit per Second Optical Networking
 
Constellations Demystified.ppt
Constellations Demystified.pptConstellations Demystified.ppt
Constellations Demystified.ppt
 
Transmission Line Basics
Transmission Line BasicsTransmission Line Basics
Transmission Line Basics
 
Avnet, TE Antenna Selector Guide
Avnet, TE Antenna Selector GuideAvnet, TE Antenna Selector Guide
Avnet, TE Antenna Selector Guide
 
SPICE MODEL of 2SK3938 (Standard+BDS Model) in SPICE PARK
SPICE MODEL of 2SK3938 (Standard+BDS Model) in SPICE PARKSPICE MODEL of 2SK3938 (Standard+BDS Model) in SPICE PARK
SPICE MODEL of 2SK3938 (Standard+BDS Model) in SPICE PARK
 
Rdb45350 access point_specifications
Rdb45350 access point_specificationsRdb45350 access point_specifications
Rdb45350 access point_specifications
 

More from Jim Geovedi

Waluku: Answering Astronomy Questions through Social Media
Waluku: Answering Astronomy Questions through Social MediaWaluku: Answering Astronomy Questions through Social Media
Waluku: Answering Astronomy Questions through Social MediaJim Geovedi
 
Perbandingan distribusi frekuensi kata bahasa Indonesia di Kompas, Wikipedia,...
Perbandingan distribusi frekuensi kata bahasa Indonesia di Kompas, Wikipedia,...Perbandingan distribusi frekuensi kata bahasa Indonesia di Kompas, Wikipedia,...
Perbandingan distribusi frekuensi kata bahasa Indonesia di Kompas, Wikipedia,...Jim Geovedi
 
Satellite Hacking — Intro by Indianz (2012)
Satellite Hacking — Intro by Indianz (2012)Satellite Hacking — Intro by Indianz (2012)
Satellite Hacking — Intro by Indianz (2012)Jim Geovedi
 
HITB Labs: Practical Attacks Against 3G/4G Telecommunication Networks
HITB Labs: Practical Attacks Against 3G/4G Telecommunication NetworksHITB Labs: Practical Attacks Against 3G/4G Telecommunication Networks
HITB Labs: Practical Attacks Against 3G/4G Telecommunication NetworksJim Geovedi
 
Cheating the 10,000 hour rule
Cheating the 10,000 hour ruleCheating the 10,000 hour rule
Cheating the 10,000 hour ruleJim Geovedi
 
Professional Hackers
Professional HackersProfessional Hackers
Professional HackersJim Geovedi
 
AI & NLP pada @begobet
AI & NLP pada @begobetAI & NLP pada @begobet
AI & NLP pada @begobetJim Geovedi
 
IDS & Log Management
IDS & Log ManagementIDS & Log Management
IDS & Log ManagementJim Geovedi
 
Warezzman - DVB-Satellite Hacking
Warezzman - DVB-Satellite HackingWarezzman - DVB-Satellite Hacking
Warezzman - DVB-Satellite HackingJim Geovedi
 
Adam Laurie - $atellite Hacking for Fun & Pr0fit!
Adam Laurie - $atellite Hacking for Fun & Pr0fit!Adam Laurie - $atellite Hacking for Fun & Pr0fit!
Adam Laurie - $atellite Hacking for Fun & Pr0fit!Jim Geovedi
 
Leonardo Nve Egea - Playing in a Satellite Environment 1.2
Leonardo Nve Egea - Playing in a Satellite Environment 1.2Leonardo Nve Egea - Playing in a Satellite Environment 1.2
Leonardo Nve Egea - Playing in a Satellite Environment 1.2Jim Geovedi
 
Is Cyber-offence the New Cyber-defence?
Is Cyber-offence the New Cyber-defence?Is Cyber-offence the New Cyber-defence?
Is Cyber-offence the New Cyber-defence?Jim Geovedi
 
The 21st Century Bank Job
The 21st Century Bank JobThe 21st Century Bank Job
The 21st Century Bank JobJim Geovedi
 
Cloud Security - Security Aspects of Cloud Computing
Cloud Security - Security Aspects of Cloud ComputingCloud Security - Security Aspects of Cloud Computing
Cloud Security - Security Aspects of Cloud ComputingJim Geovedi
 
Hacking Satellite: A New Universe to Discover
Hacking Satellite: A New Universe to DiscoverHacking Satellite: A New Universe to Discover
Hacking Satellite: A New Universe to DiscoverJim Geovedi
 
Hacking a Bird in the Sky: Exploiting Satellite Trust Relationship
Hacking a Bird in the Sky: Exploiting Satellite Trust RelationshipHacking a Bird in the Sky: Exploiting Satellite Trust Relationship
Hacking a Bird in the Sky: Exploiting Satellite Trust RelationshipJim Geovedi
 
Hacking a Bird in the Sky: Hijacking VSAT Connection
Hacking a Bird in the Sky: Hijacking VSAT ConnectionHacking a Bird in the Sky: Hijacking VSAT Connection
Hacking a Bird in the Sky: Hijacking VSAT ConnectionJim Geovedi
 
Hacking Cracking 2008
Hacking Cracking 2008Hacking Cracking 2008
Hacking Cracking 2008Jim Geovedi
 
Wireless Hotspot Security
Wireless Hotspot SecurityWireless Hotspot Security
Wireless Hotspot SecurityJim Geovedi
 

More from Jim Geovedi (20)

Waluku: Answering Astronomy Questions through Social Media
Waluku: Answering Astronomy Questions through Social MediaWaluku: Answering Astronomy Questions through Social Media
Waluku: Answering Astronomy Questions through Social Media
 
Perbandingan distribusi frekuensi kata bahasa Indonesia di Kompas, Wikipedia,...
Perbandingan distribusi frekuensi kata bahasa Indonesia di Kompas, Wikipedia,...Perbandingan distribusi frekuensi kata bahasa Indonesia di Kompas, Wikipedia,...
Perbandingan distribusi frekuensi kata bahasa Indonesia di Kompas, Wikipedia,...
 
Satellite Hacking — Intro by Indianz (2012)
Satellite Hacking — Intro by Indianz (2012)Satellite Hacking — Intro by Indianz (2012)
Satellite Hacking — Intro by Indianz (2012)
 
Internet Worms
Internet WormsInternet Worms
Internet Worms
 
HITB Labs: Practical Attacks Against 3G/4G Telecommunication Networks
HITB Labs: Practical Attacks Against 3G/4G Telecommunication NetworksHITB Labs: Practical Attacks Against 3G/4G Telecommunication Networks
HITB Labs: Practical Attacks Against 3G/4G Telecommunication Networks
 
Cheating the 10,000 hour rule
Cheating the 10,000 hour ruleCheating the 10,000 hour rule
Cheating the 10,000 hour rule
 
Professional Hackers
Professional HackersProfessional Hackers
Professional Hackers
 
AI & NLP pada @begobet
AI & NLP pada @begobetAI & NLP pada @begobet
AI & NLP pada @begobet
 
IDS & Log Management
IDS & Log ManagementIDS & Log Management
IDS & Log Management
 
Warezzman - DVB-Satellite Hacking
Warezzman - DVB-Satellite HackingWarezzman - DVB-Satellite Hacking
Warezzman - DVB-Satellite Hacking
 
Adam Laurie - $atellite Hacking for Fun & Pr0fit!
Adam Laurie - $atellite Hacking for Fun & Pr0fit!Adam Laurie - $atellite Hacking for Fun & Pr0fit!
Adam Laurie - $atellite Hacking for Fun & Pr0fit!
 
Leonardo Nve Egea - Playing in a Satellite Environment 1.2
Leonardo Nve Egea - Playing in a Satellite Environment 1.2Leonardo Nve Egea - Playing in a Satellite Environment 1.2
Leonardo Nve Egea - Playing in a Satellite Environment 1.2
 
Is Cyber-offence the New Cyber-defence?
Is Cyber-offence the New Cyber-defence?Is Cyber-offence the New Cyber-defence?
Is Cyber-offence the New Cyber-defence?
 
The 21st Century Bank Job
The 21st Century Bank JobThe 21st Century Bank Job
The 21st Century Bank Job
 
Cloud Security - Security Aspects of Cloud Computing
Cloud Security - Security Aspects of Cloud ComputingCloud Security - Security Aspects of Cloud Computing
Cloud Security - Security Aspects of Cloud Computing
 
Hacking Satellite: A New Universe to Discover
Hacking Satellite: A New Universe to DiscoverHacking Satellite: A New Universe to Discover
Hacking Satellite: A New Universe to Discover
 
Hacking a Bird in the Sky: Exploiting Satellite Trust Relationship
Hacking a Bird in the Sky: Exploiting Satellite Trust RelationshipHacking a Bird in the Sky: Exploiting Satellite Trust Relationship
Hacking a Bird in the Sky: Exploiting Satellite Trust Relationship
 
Hacking a Bird in the Sky: Hijacking VSAT Connection
Hacking a Bird in the Sky: Hijacking VSAT ConnectionHacking a Bird in the Sky: Hijacking VSAT Connection
Hacking a Bird in the Sky: Hijacking VSAT Connection
 
Hacking Cracking 2008
Hacking Cracking 2008Hacking Cracking 2008
Hacking Cracking 2008
 
Wireless Hotspot Security
Wireless Hotspot SecurityWireless Hotspot Security
Wireless Hotspot Security
 

Recently uploaded

How AI, OpenAI, and ChatGPT impact business and software.
How AI, OpenAI, and ChatGPT impact business and software.How AI, OpenAI, and ChatGPT impact business and software.
How AI, OpenAI, and ChatGPT impact business and software.Curtis Poe
 
Time Series Foundation Models - current state and future directions
Time Series Foundation Models - current state and future directionsTime Series Foundation Models - current state and future directions
Time Series Foundation Models - current state and future directionsNathaniel Shimoni
 
Glenn Lazarus- Why Your Observability Strategy Needs Security Observability
Glenn Lazarus- Why Your Observability Strategy Needs Security ObservabilityGlenn Lazarus- Why Your Observability Strategy Needs Security Observability
Glenn Lazarus- Why Your Observability Strategy Needs Security Observabilityitnewsafrica
 
The Role of FIDO in a Cyber Secure Netherlands: FIDO Paris Seminar.pptx
The Role of FIDO in a Cyber Secure Netherlands: FIDO Paris Seminar.pptxThe Role of FIDO in a Cyber Secure Netherlands: FIDO Paris Seminar.pptx
The Role of FIDO in a Cyber Secure Netherlands: FIDO Paris Seminar.pptxLoriGlavin3
 
How to write a Business Continuity Plan
How to write a Business Continuity PlanHow to write a Business Continuity Plan
How to write a Business Continuity PlanDatabarracks
 
The Future Roadmap for the Composable Data Stack - Wes McKinney - Data Counci...
The Future Roadmap for the Composable Data Stack - Wes McKinney - Data Counci...The Future Roadmap for the Composable Data Stack - Wes McKinney - Data Counci...
The Future Roadmap for the Composable Data Stack - Wes McKinney - Data Counci...Wes McKinney
 
Unleashing Real-time Insights with ClickHouse_ Navigating the Landscape in 20...
Unleashing Real-time Insights with ClickHouse_ Navigating the Landscape in 20...Unleashing Real-time Insights with ClickHouse_ Navigating the Landscape in 20...
Unleashing Real-time Insights with ClickHouse_ Navigating the Landscape in 20...Alkin Tezuysal
 
Bridging Between CAD & GIS: 6 Ways to Automate Your Data Integration
Bridging Between CAD & GIS:  6 Ways to Automate Your Data IntegrationBridging Between CAD & GIS:  6 Ways to Automate Your Data Integration
Bridging Between CAD & GIS: 6 Ways to Automate Your Data Integrationmarketing932765
 
[Webinar] SpiraTest - Setting New Standards in Quality Assurance
[Webinar] SpiraTest - Setting New Standards in Quality Assurance[Webinar] SpiraTest - Setting New Standards in Quality Assurance
[Webinar] SpiraTest - Setting New Standards in Quality AssuranceInflectra
 
A Deep Dive on Passkeys: FIDO Paris Seminar.pptx
A Deep Dive on Passkeys: FIDO Paris Seminar.pptxA Deep Dive on Passkeys: FIDO Paris Seminar.pptx
A Deep Dive on Passkeys: FIDO Paris Seminar.pptxLoriGlavin3
 
Scale your database traffic with Read & Write split using MySQL Router
Scale your database traffic with Read & Write split using MySQL RouterScale your database traffic with Read & Write split using MySQL Router
Scale your database traffic with Read & Write split using MySQL RouterMydbops
 
Transcript: New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024Transcript: New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024BookNet Canada
 
New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024
New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024
New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024BookNet Canada
 
Potential of AI (Generative AI) in Business: Learnings and Insights
Potential of AI (Generative AI) in Business: Learnings and InsightsPotential of AI (Generative AI) in Business: Learnings and Insights
Potential of AI (Generative AI) in Business: Learnings and InsightsRavi Sanghani
 
Zeshan Sattar- Assessing the skill requirements and industry expectations for...
Zeshan Sattar- Assessing the skill requirements and industry expectations for...Zeshan Sattar- Assessing the skill requirements and industry expectations for...
Zeshan Sattar- Assessing the skill requirements and industry expectations for...itnewsafrica
 
Digital Identity is Under Attack: FIDO Paris Seminar.pptx
Digital Identity is Under Attack: FIDO Paris Seminar.pptxDigital Identity is Under Attack: FIDO Paris Seminar.pptx
Digital Identity is Under Attack: FIDO Paris Seminar.pptxLoriGlavin3
 
Abdul Kader Baba- Managing Cybersecurity Risks and Compliance Requirements i...
Abdul Kader Baba- Managing Cybersecurity Risks  and Compliance Requirements i...Abdul Kader Baba- Managing Cybersecurity Risks  and Compliance Requirements i...
Abdul Kader Baba- Managing Cybersecurity Risks and Compliance Requirements i...itnewsafrica
 
QCon London: Mastering long-running processes in modern architectures
QCon London: Mastering long-running processes in modern architecturesQCon London: Mastering long-running processes in modern architectures
QCon London: Mastering long-running processes in modern architecturesBernd Ruecker
 
Long journey of Ruby standard library at RubyConf AU 2024
Long journey of Ruby standard library at RubyConf AU 2024Long journey of Ruby standard library at RubyConf AU 2024
Long journey of Ruby standard library at RubyConf AU 2024Hiroshi SHIBATA
 
Decarbonising Buildings: Making a net-zero built environment a reality
Decarbonising Buildings: Making a net-zero built environment a realityDecarbonising Buildings: Making a net-zero built environment a reality
Decarbonising Buildings: Making a net-zero built environment a realityIES VE
 

Recently uploaded (20)

How AI, OpenAI, and ChatGPT impact business and software.
How AI, OpenAI, and ChatGPT impact business and software.How AI, OpenAI, and ChatGPT impact business and software.
How AI, OpenAI, and ChatGPT impact business and software.
 
Time Series Foundation Models - current state and future directions
Time Series Foundation Models - current state and future directionsTime Series Foundation Models - current state and future directions
Time Series Foundation Models - current state and future directions
 
Glenn Lazarus- Why Your Observability Strategy Needs Security Observability
Glenn Lazarus- Why Your Observability Strategy Needs Security ObservabilityGlenn Lazarus- Why Your Observability Strategy Needs Security Observability
Glenn Lazarus- Why Your Observability Strategy Needs Security Observability
 
The Role of FIDO in a Cyber Secure Netherlands: FIDO Paris Seminar.pptx
The Role of FIDO in a Cyber Secure Netherlands: FIDO Paris Seminar.pptxThe Role of FIDO in a Cyber Secure Netherlands: FIDO Paris Seminar.pptx
The Role of FIDO in a Cyber Secure Netherlands: FIDO Paris Seminar.pptx
 
How to write a Business Continuity Plan
How to write a Business Continuity PlanHow to write a Business Continuity Plan
How to write a Business Continuity Plan
 
The Future Roadmap for the Composable Data Stack - Wes McKinney - Data Counci...
The Future Roadmap for the Composable Data Stack - Wes McKinney - Data Counci...The Future Roadmap for the Composable Data Stack - Wes McKinney - Data Counci...
The Future Roadmap for the Composable Data Stack - Wes McKinney - Data Counci...
 
Unleashing Real-time Insights with ClickHouse_ Navigating the Landscape in 20...
Unleashing Real-time Insights with ClickHouse_ Navigating the Landscape in 20...Unleashing Real-time Insights with ClickHouse_ Navigating the Landscape in 20...
Unleashing Real-time Insights with ClickHouse_ Navigating the Landscape in 20...
 
Bridging Between CAD & GIS: 6 Ways to Automate Your Data Integration
Bridging Between CAD & GIS:  6 Ways to Automate Your Data IntegrationBridging Between CAD & GIS:  6 Ways to Automate Your Data Integration
Bridging Between CAD & GIS: 6 Ways to Automate Your Data Integration
 
[Webinar] SpiraTest - Setting New Standards in Quality Assurance
[Webinar] SpiraTest - Setting New Standards in Quality Assurance[Webinar] SpiraTest - Setting New Standards in Quality Assurance
[Webinar] SpiraTest - Setting New Standards in Quality Assurance
 
A Deep Dive on Passkeys: FIDO Paris Seminar.pptx
A Deep Dive on Passkeys: FIDO Paris Seminar.pptxA Deep Dive on Passkeys: FIDO Paris Seminar.pptx
A Deep Dive on Passkeys: FIDO Paris Seminar.pptx
 
Scale your database traffic with Read & Write split using MySQL Router
Scale your database traffic with Read & Write split using MySQL RouterScale your database traffic with Read & Write split using MySQL Router
Scale your database traffic with Read & Write split using MySQL Router
 
Transcript: New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024Transcript: New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024
Transcript: New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024
 
New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024
New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024
New from BookNet Canada for 2024: Loan Stars - Tech Forum 2024
 
Potential of AI (Generative AI) in Business: Learnings and Insights
Potential of AI (Generative AI) in Business: Learnings and InsightsPotential of AI (Generative AI) in Business: Learnings and Insights
Potential of AI (Generative AI) in Business: Learnings and Insights
 
Zeshan Sattar- Assessing the skill requirements and industry expectations for...
Zeshan Sattar- Assessing the skill requirements and industry expectations for...Zeshan Sattar- Assessing the skill requirements and industry expectations for...
Zeshan Sattar- Assessing the skill requirements and industry expectations for...
 
Digital Identity is Under Attack: FIDO Paris Seminar.pptx
Digital Identity is Under Attack: FIDO Paris Seminar.pptxDigital Identity is Under Attack: FIDO Paris Seminar.pptx
Digital Identity is Under Attack: FIDO Paris Seminar.pptx
 
Abdul Kader Baba- Managing Cybersecurity Risks and Compliance Requirements i...
Abdul Kader Baba- Managing Cybersecurity Risks  and Compliance Requirements i...Abdul Kader Baba- Managing Cybersecurity Risks  and Compliance Requirements i...
Abdul Kader Baba- Managing Cybersecurity Risks and Compliance Requirements i...
 
QCon London: Mastering long-running processes in modern architectures
QCon London: Mastering long-running processes in modern architecturesQCon London: Mastering long-running processes in modern architectures
QCon London: Mastering long-running processes in modern architectures
 
Long journey of Ruby standard library at RubyConf AU 2024
Long journey of Ruby standard library at RubyConf AU 2024Long journey of Ruby standard library at RubyConf AU 2024
Long journey of Ruby standard library at RubyConf AU 2024
 
Decarbonising Buildings: Making a net-zero built environment a reality
Decarbonising Buildings: Making a net-zero built environment a realityDecarbonising Buildings: Making a net-zero built environment a reality
Decarbonising Buildings: Making a net-zero built environment a reality
 

Hacking a Bird in the Sky: The Revenge of Angry Birds

  • 1. Hacking a Bird in the Sky The Revenge of Angry Birds Jim Geovedi, Raditya Iryandi, Raoul Chiesa
  • 2. Satellite Communication When terrestrial communication FAIL, we PREVAIL! Arthur C. Clarke 1917-2008
  • 3. Broadcast Video to Cable Headends Local ISPs Direct Broadcast TV Video Last-mile Broadband Contribution Corporate Data Networks Teleport PSTN (Interactive & Multicast) End Users Teleport Internet End Users
  • 4. average distance to moon: 384,400 km Medium Earth Orbit Altitude: 8,000-20,000 km Low Earth Orbit EARTH Altitude: 500-2,000 km Geostationary Orbit Altitude: 35,786 km Highly Elliptical Orbit Altitude: >35,786 km
  • 5. Propulsion System Telemetry, Attitude Control, Solar Arrays Commanding, Fuel, Batteries, Solar Arrays Power/Thermal Systems Transponder Down-converter, High Power, Transponder Receiver Pre-amplifier, Amplifier, Transmitter Section Filter Filter Section RX Antenna TX Antenna Jakarta Jayapura Uplink Downlink Earth Stations / Antennas
  • 6. Telkom-1 Footprint / 108.0º East (C Band) C Band 38 40 42
  • 8. Example of Frequency and Polarisation Distribution Transmit 3720 3760 3800 3840 3880 3920 3960 4000 4040 4080 4120 4160 4199 1 3 5 7 9 11 13 15 17 19 21 23 T/M Polarisation Horizontal 3701 3740 3780 3820 3860 3900 3940 3980 4020 4060 4100 4140 4180 T/M 2 4 6 8 10 12 14 16 18 20 22 24 Polarisation Vertical Frequency MHz 3700 4200 Receive 5945 5985 6025 6065 6105 6145 6185 6225 6265 6305 6345 6385 6424 1 3 5 7 9 11 13 15 17 19 21 23 CMD Polarisation Vertical 5965 6005 6045 6085 6125 6165 6205 6245 6285 6325 6365 6405 2 4 6 8 10 12 14 16 18 20 22 24 Polarisation Horizontal Frequency MHz 5925 6245 Channel spacing = 40 MHz — Usable bandwidth = 36 MHz
  • 9. VSAT / Very Small Aperture Terminal ‣ Two-way satellite communication ‣ Use small dish antennas (diameter: 75cm-2,4m) ‣ Managed by the HUB (master earth station)
  • 10. VSAT / Services ‣ One-way multicast ‣ One-way with terrestrial return ‣ Two-way satellite access
  • 11. VSAT Network Topologies / Simplex Transmission Hub Equipment Hub Equipment Hub Equipment Hub Equipment TV Station / HQ Network Affiliated TV Stations
  • 12. VSAT Network Topologies / Point-to-Point Duplex Transmission Public Network Public Network Private Network CPE CPE Private Network Customer Site Customer Site
  • 13. VSAT Network Topologies / Point-to-Multipoint Transmission CPE CPE CPE Network or Sites Network or Sites Network or Sites
  • 14. VSAT Network Topologies / Mobile Antenna Service Public Network Hub Equipment Private Network Customer Site
  • 15. VSAT Network Topologies / Star Network Hub Equipment Hub Equipment Hub Equipment Hub Equipment Public/Private Networks Networks or Sites
  • 16. VSAT Network Topologies / Mesh Network Hub Equipment Hub Equipment Hub Equipment Networks or Sites Networks or Sites Networks or Sites
  • 17. Access Methods / FDMA (Frequency Division Multiple Access) f1 f2 f3 Transponder f1 f2 f3
  • 18. Access Methods / TDMA (Time Division Multiple Access) f1 Transponder f1 f1 f1 f1
  • 19. Access Methods / CDMA (Code Division Multiple Access) ++++++++++++++++++++++++++++++++++++++++++ xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx oooooooooooooooooooooooooooooooooooooooooo ------------------------------------------ Transponder f1 f1 f1 f1
  • 20. Satellite Vulnerabilities Current systems are vulnerable to a variety of attacks, and future systems promise little improvement.
  • 21. Unless you have millions of dollars and a team of engineers, you have no hope of taking over commercial or governmental satellites. If someone did put together the power to try such a stunt, they would be more likely to damage a satellite than take it over. How to Break into Satellites: Not! Carolyn Meinel’s GUIDE TO (mostly) HARMLESS HACKING Gobbles!
  • 22. hackers will eventually find a way to hack
  • 23. employees management vendors customers spieS government network of trust
  • 24. It is worth noting that the most likely cause of damage to or loss of service from a satellite is the actual operator. Dan Veeneman
  • 25. Dan Veeneman Low Earth Orbit Satellites Dan Veeneman Future & Existing Satellite Systems Warezzman DVB Satellite Hacking Jim Geovedi, Raditya Iryandi, Hacking a Bird in the Sky: Hijacking VSAT Connection Jim Geovedi, Raditya Iryandi, Anthony Zboralski Hacking a Bird in the Sky: Exploiting Satellite Trust Relationship Adam Laurie $atellite Hacking for Fun & Pr0fit! Leonardo Nve Egea, Christian Martorella Playing in a Satellite Environment 1.2 Jim Geovedi, Raditya Iryandi Hacking Satellite: A New Universe to Discover Jim Geovedi, Raditya Iryandi, Raoul Chiesa Hacking a Bird in the Sky: The Revenge of Angry Birds 1996 1998 2004 2006 2008 2009 2011
  • 26. Veeneman’s Satellite Hypothetical Attacks Denial of Service Orbital Positioning Takeover Spare Satellite Raging Transponder Spoofing ? Jam Uplink Direct Commanding Overpower Uplink Command Replay Jam Downlink Insertion
  • 27.
  • 28. Satellite TT&C Ground Networks Frequency Network Gateway Receivers/Modems Conversion Ground Geolocation Antenna Digital/Analog Spectrum Record and Replay Monitoring IP Network Gateway COMSEC Front-end Processor Command and Control
  • 30. Satellite-based Attacks Against ATMs and Bank Networks It's not a big truck. It's a series of tubes.
  • 31. TRADE FINANCE TREASURY DATA WAREHOUSING ANTI MONEY LAUNDERING REMITTANCE CORE CRM ATM SWITCH COLLECTION SYSTEM MOBILE BANKING INTERNET BANKING ISLAMIC (SHARIA) BANKING CARD MANAGEMENT
  • 32. VSAT / Automated Teller Machine Networks ATM ATM ATM ATM Standard Network Hub Equipment Hub Equipment Hub Equipment Hub Equipment Equipment Core Banking Networks Automated Teller Machines
  • 33. VSAT / Automated Teller Machine Networks
  • 34.
  • 38.
  • 39. The Usual Culprits People Problems System Problems Weak Passwords Outdated Systems Lack of Awareness Insecure Configurations Lack of Skills Insecure Protocols
  • 41. Distributed Satellite Scanning Framework Identify potential problems at an early stage.
  • 42. Framework Goals ‣ Dead or Alive status / checking if the bird is still alive ‣ Protocols / understand which protocols the target is running ‣ Service type / knowing which service we can (ab)use ‣ Distributed IP C&C / widening the coverage
  • 44. Satellite Carrier Monitoring System ‣ Spectrum Analyser and Digital Spectrum Processor analysis ‣ Reference trace and measurement ‣ Automatic alerts for abnormal and missing carriers
  • 46. What’s Next? No, the journey doesn't end here.
  • 47.
  • 48.
  • 49.
  • 50.
  • 52. Fin. Jim Geovedi <jim@geovedi.com>, @geovedi Raoul Chiesa <raoul.chiesa@mediaservice.net>