DPS Sector - 84

LEAKED CODE EXPOSED SEVERAL VULNERABILITIES IN THE BOIENG 787 INTERNATIONAL SYSTEMS

                                                                   LEAKED CODE EXPOSED SEVERAL VULNERABILITIES IN THE BOIENG 787 INTERNATIONAL SYSTEMS
There are multiple serious security flaws in the code for a component of the 787 known as Crew Information Service/Maintenance System (CIS/MS).
These vulnerabilities can be abused by an attacker to send malicious commands to far more sensitive components that control the plane’s safety-critical systems.

Last year, a security researcher Ruben Santamarta had uncovered a fully unprotected server on Boeing’s network. This server contained code used to run on the company’s giant 737 and 787 passenger jets.
Now nearly a year later, IOActive industrial cybersecurity expert Ruben Santamarta claims that the leaked code can be used to conduct cyberattacks on Boeing 787 Dreamliner systems.
What’s the matter?
                                              At the Black Hat security conference in Las Vegas, Santamarta revealed that there are multiple serious security flaws in the code for a component of the 787 known as Crew Information Service/Maintenance System (CIS/MS).
The CIS/MS is responsible for applications like maintenance systems and the electronic flight bag.
What can the hackers do with the code?

The hacker can basically get the crew information and misuse them for spam calls, mails and messeges etc, there is no surety that he may even hack their accounts.
He can also send fake commands directly to the pilot which may lead into fairly serious damages to a really large amount of people.
He can also hack in through the vulnerabilities of the plane and even crack the controls. Basically he may control the whole plane by a simple mobile phone or software. 
As suggested by me, the boieng company should look upon these kinds of vulnerabilities and not provide security flaws and an access to code on the internet in front of like 3 billion people, of course hacking had to take place because of their carelessness in cyber security. Do you agree with what I say, comment down below to present for the same.     

No comments

Powered by Blogger.