This Domain is for Sale. To make an offer please get contact.
Make an Offer
  • Home
  • News
  • Technology
  • Law & Regulations
  • Informative
  • Tug&Barge&Salvage
Maritime and Salvage Wolrd News - Latest Ship Technologies
No Result
View All Result
No Result
View All Result
Maritime and Salvage Wolrd News - Latest Ship Technologies
No Result
View All Result

Inmarsat Shipboard Communication Platform Found Vulnerable to Hacking

marinesalvage by marinesalvage
April 3, 2023
in News
0
ship's bridge
ship's bridge

Inmarsat Shipboard Communication Platform Found Vulnerable to Hacking

Seattle- based cybersecurity company IOActive has actually revealed what it calls crucial protection imperfections in among Inmarsat’s shipboard interaction systems that can leave the system and also vessels’ networks at risk to remote cyberpunks.

IOActive launched information of susceptabilities after recording crucial cybersecurity susceptabilities impacting Stratos Global’s AmosConnect variation 8.0 interaction shipboard system. Stratos Global, an Inmarsat business, is the leading supplier of maritime interactions solutions worldwide and also made use of by countless ship vessels internationally.

Inmarsat stated it recognized the record and also stated the system concerned is no more in solution.

“The flaws IOActive discovered include blind SQL injection in a login form, and a backdoor account that provides full system privileges that could allow remote unauthenticated attackers to execute arbitrary code on the AmosConnect server,” the IOActive stated in a news release. “If compromised, this flaw can be leveraged to gain unauthorized network access to sensitive information stored in the AmosConnect server and potentially open access to other connected systems or networks.”

The protection concerns were found by IOActive scientist, Mario Ballano, that performed the “research” in September of 2016. Ballano discovered that he can get complete system advantages, basically coming to be the manager of package where AmosConnect is set up. If there were to be any type of various other software application or information saved package, the aggressor would certainly have accessibility to those and also possibly to various other networks attached to it, according to IOActive.

“Essentially anyone interested in sensitive company information or looking to attack a vessel’s IT infrastructure could take advantage of these flaws,” statedBallano “This leaves crew member and company data extremely vulnerable, and could present risks to the safety of the entire vessel. Maritime cybersecurity must be taken seriously as our global logistics supply chain relies on it and as cyber criminals increasingly find new methods of attack.”

IOActive stated it educated Inmarsat of the susceptabilities in October 2016, and also finished the disclosure procedure in July of 2017.

Inmarsat has actually considering that stopped the 8.0 variation of the system and also has actually advised that clients change back to AmosConnect 7.0, or button to an e-mail remedy from among their accepted companions.

In a declaration, Inmarsat stated it understands the IOActive record and also stated that it is very important to keep in mind AmosConnect 8 (AC8) is no more in solution.

Inmarsat’s declaration proceeded:

“Inmarsat had actually started a procedure to retire AmosConnect 8 from our profile before IOActive’s record and also, in 2016, we interacted to our clients that the solution would certainly be ended in July 2017.

“When IOActive brought the possible susceptability to our focus, early in 2017, and also regardless of the item getting to end of life, Inmarsat provided a safety and security spot that was put on AC8 to considerably minimize the danger possibly positioned. We likewise got rid of the capacity for individuals to download and install and also turn on AC8 from our public internet site.

“Inmarsat’s main web server no more approves links from AmosConnect 8 e-mail customers, so clients can not utilize this software application also if they desired also.

“It is important to note that this vulnerability would have been very difficult to exploit as it would require direct access to the shipboard PC that ran the AC8 email client. This could only be done by direct physical access to the PC, which would require an intruder to gain access to the ship and then to the computer. While remote access was deemed to be a remote possibility as this would have been blocked by Inmarsat’s shoreside firewalls.”

Source of This New

Tags: cyber security
Previous Post

Three former Austal USA execs face DOJ and SEC charges

Next Post

Vietnam Offshore Vessel Saves 154 Rohingya from Sinking Boat, Transfers Them to Myanmar Navy

Related Posts

Hunt for Black Boxes Still On After AirAsia Plane’s Tail Located
News

Hunt for Black Boxes Still On After AirAsia Plane’s Tail Located

July 13, 2024
capesize bulk carrier terminal iron ore dry bulk
News

Capesize Rates at Six-Year Lows, Could Slide Further

July 13, 2024
jennifer turecamo moran tug chesapeake bay winter
News

Cold Morning on the Chesapeake

July 13, 2024
Video: Aboard the Mighty CSCL Globe in Felixstowe – ShippingTV
News

Video: Aboard the Mighty CSCL Globe in Felixstowe – ShippingTV

July 13, 2024
Eco Marine Power and Nakashima Propeller Cooperate on Composites
News

Eco Marine Power and Nakashima Propeller Cooperate on Composites

July 12, 2024
odfjell
News

Odfjell Announces Layoffs, Reduction of European Officers

July 12, 2024
Next Post
Vietnam Offshore Vessel Saves 154 Rohingya from Sinking Boat, Transfers Them to Myanmar Navy

Vietnam Offshore Vessel Saves 154 Rohingya from Sinking Boat, Transfers Them to Myanmar Navy

Quick Search

No Result
View All Result

Recent Posts

  • Hunt for Black Boxes Still On After AirAsia Plane’s Tail Located July 13, 2024
  • Capesize Rates at Six-Year Lows, Could Slide Further July 13, 2024
  • Cold Morning on the Chesapeake July 13, 2024
  • Video: Aboard the Mighty CSCL Globe in Felixstowe – ShippingTV July 13, 2024
  • Eco Marine Power and Nakashima Propeller Cooperate on Composites July 12, 2024

Categories

  • Informative
  • Law & Regulations
  • News
  • Technology
  • Tug&Barge&Salvage
Hunt for Black Boxes Still On After AirAsia Plane’s Tail Located
News

Hunt for Black Boxes Still On After AirAsia Plane’s Tail Located

by marinesalvage
July 13, 2024
0

Hunt for Black Boxes Still On After AirAsia Plane’s Tail Located By Fathiya Dahrul and Rieka Rahadiana (Bloomberg) — Divers...

Read more
capesize bulk carrier terminal iron ore dry bulk

Capesize Rates at Six-Year Lows, Could Slide Further

July 13, 2024
jennifer turecamo moran tug chesapeake bay winter

Cold Morning on the Chesapeake

July 13, 2024
Video: Aboard the Mighty CSCL Globe in Felixstowe – ShippingTV

Video: Aboard the Mighty CSCL Globe in Felixstowe – ShippingTV

July 13, 2024
Eco Marine Power and Nakashima Propeller Cooperate on Composites

Eco Marine Power and Nakashima Propeller Cooperate on Composites

July 12, 2024
Maritime and Salvage Wolrd News - Latest Ship Technologies

© 2023 - Marine-Salvage.net

Navigate Site

  • Home Page
  • Privacy Policy
  • Contact Us
  • About Us

Follow Us

No Result
View All Result
  • Home
  • News
  • Technology
  • Law & Regulations
  • Informative
  • Tug&Barge&Salvage

© 2023 - Marine-Salvage.net

Manage Cookie Consent
We use cookies to optimize our website and our service.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
Manage options Manage services Manage vendors Read more about these purposes
View preferences
{title} {title} {title}