• Home
  • Shop
  • Privacy Policy
  • Terms of Service
  • Contact us
Friday, March 24, 2023
  • Home
  • Esports
  • PC Games
  • PS4
  • PS5
  • Switch
  • Wii U
  • XBox 360
  • XBox One
  • Xbox Series X
  • Mobile
  • Game News
No Result
View All Result
GameNewsUSA
wow warcraft alliance horde cataclysm leveling guide
  • Home
  • Esports
  • PC Games
  • PS4
  • PS5
  • Switch
  • Wii U
  • XBox 360
  • XBox One
  • Xbox Series X
  • Mobile
  • Game News
No Result
View All Result
GameNewsUSA
No Result
View All Result
Home Switch

Researchers discover ‘kill switch’ in Starlink terminals – Security

March 5, 2023
in Switch
0




Crashed Starlink terminal.


arXiv:2303.00582

Starlink quietly shipped software that patched a “kill switch” in its user terminals in December last year.

The discovery was made by a team of academics from Oxford University and a researcher from Switzerland’s Federal Office for Defence Procurement, who published their work at arXiv.

The researchers first learned the structure of commands sent to the terminal’s management interface, and discovered that “the payload always consists of four null bytes, followed by a byte containing the length of the command, followed by the command itself.”

Although the commands use a “non-human-readable encoding”, the structure provided sufficient information for the team to build a fuzzer that cycled through correctly-formatted commands to see which had an effect.

The fuzzing “led to the discovery of the ‘kill’ command 00 00 00 00 03 EA 3E 00, which causes the command handler of the user terminal to crash”.

The crash is only partially a denial-of-service: the terminal will continue to function as a receiver and modem, but will not respond to new commands until it’s power cycled, with its settings and state frozen.

“By attacking the admin interface, the attacker can affect the physical state of the dish, opening up new approaches to denial of service by turning the dish away from the sky. Furthermore, motors and other hardware can be damaged in this way through overuse,” the researchers said.

While the researchers only demonstrated a compromise over the local network, “executing
the attack only requires a few seconds of connection on the local network”, and they note that in some settings, Starlink might be serving a large network.

They also said that there is “some potential for remote attack, provided the attacker can in some way cause a device on the same network as the dish to send HTTP requests.

The team reported their findings to Starlink, which deployed a patch in December.

The researchers said their work is an example of how the advent of low earth orbit (LEO) satellites has led companies to develop their own terminal/modem devices, “without the institutional memory” of broadband router developers’ vulnerabilities and their mitigations.

“Since the router is often part of a physical system including a motorised dish, securing the admin interface is of even greater importance,” the researchers said. 

The paper calls for satellite terminal designers to implement “known security improvements from terrestrial router design”, including password authentication for the management interface, using TLS to encrypt management traffic, and only permitting access to the management interface from a dedicated admin network.

Related Posts

Switch

Bloodstained: Curse Of The Moon Double Pack Physical Switch Release Announced

March 24, 2023
Switch

All Resident Evil Games Available On Switch

March 24, 2023
Game News

Coming Next Week to Nintendo Switch™ – Learn Japanese Through Puzzles in Kana Quest

March 23, 2023
Switch

Diablo 4 – How to switch weapons

March 23, 2023
Switch

Wu accuses China of bribing officials as Honduras switch nears

March 23, 2023
Switch

Switch update out now (version 16.0.1), patch notes

March 23, 2023
Load More
Next Post

Mario Kart 8 Fan Creates Playable Custom Track Based on Zelda: Ocarina of Time

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Esports News

Scuderia Ferrari Esports Team announces nine-driver lineup for 2023

March 24, 2023

The best Tempus Torrent loadout in Modern Warfare 2

March 24, 2023

Motorsport UK Esports offers exclusive Base Performance Simulators opportunity

March 23, 2023

Teaching Esports in schools transcends gaming

March 23, 2023

PC Games

MLB The Show 23 Controls Guide (PS4, PS5, Xbox One, and Xbox Series X|S)

March 24, 2023

Overdose PS5 Western Release Dates Revealed By NIS America

March 24, 2023

Scuderia Ferrari Esports Team announces nine-driver lineup for 2023

March 24, 2023

Pizza Possum Eats Garbage, Causes Havoc on PS5

March 24, 2023
No Result
View All Result

Categories

  • Esports News
  • Game News
  • Mobile
  • PC Games
  • PS4
  • PS5 News
  • Switch
  • Uncategorized
  • Wii U
  • XBox 360
  • XBox One
  • Xbox Series X

PS4

Overdose PS5 Western Release Dates Revealed By NIS America

March 24, 2023

Wii U

Sony Makes Disingenuous Claim About Minecraft

March 24, 2023

Nintendo Cuts Functionality for Free 3DS App Early

March 24, 2023

Recent News

The Crown of Wu Unleash Your Inner Monkey King Today on PlayStation and PC Platforms

March 24, 2023

MLB The Show 23 Controls Guide (PS4, PS5, Xbox One, and Xbox Series X|S)

March 24, 2023
  • Home
  • Shop
  • Privacy Policy
  • Terms of Service
  • Contact us

© 2022 GameNewsUSA

No Result
View All Result
  • Home
  • Esports
  • PC Games
  • PS4
  • PS5
  • Switch
  • Wii U
  • XBox 360
  • XBox One
  • Xbox Series X
  • Mobile
  • Game News

© 2022 GameNewsUSA