Real Exploits, Testbed Validation, Policy Gaps in Maritime Connectivity
Juwon Cho
Policy @ DEF CON 33 · Day 1 · Policy @ DEF CON
Overview
In an era of increasing digitalization and autonomy for modern vessels, the talk "Real Exploits, Testbed Validation, Policy Gaps in Maritime Connectivity" by Juwon Cho and his team sheds critical light on the severe cybersecurity vulnerabilities present in maritime satellite communication systems, specifically Very Small Aperture Terminals (VSETs). This presentation, delivered at Policy @ DEF CON, goes beyond theoretical discussions, demonstrating practical exploitation paths from a ship's VSET to its crucial operational technology (OT) systems, including PLCs and HMIs, capable of causing physical damage and disrupting vessel operations.

Key moments
- 0:00 Introduction and real-world maritime cyber attack
- 2:20 Understanding VSET: Critical satellite communication on ships
- 4:10 Research focus: ACU web interface vulnerabilities
- 6:00 Firmware reversing methodology to bypass hardware costs
- 8:00 Firmware extraction and re-hosting methodology
- 9:00 Discovery of 6 vulnerabilities, including RCE
- 10:00 Ship testbed construction and modern vessel trends
Real Exploits, Testbed Validation, Policy Gaps in Maritime Connectivity
Speakers: Juwon Cho (Maritime Cyber Security Research Engineer, Cyber Inc.), Jono (Master's Student, Jansen University), Sun Lee (Student, Hanong University)
Conference: Policy @ DEF CON
YouTube: https://www.youtube.com/watch?v=Wc9GPvu-Yso
Overview
In an era of increasing digitalization and autonomy for modern vessels, the talk "Real Exploits, Testbed Validation, Policy Gaps in Maritime Connectivity" by Juwon Cho and his team sheds critical light on the severe cybersecurity vulnerabilities present in maritime satellite communication systems, specifically Very Small Aperture Terminals (VSETs). This presentation, delivered at Policy @ DEF CON, goes beyond theoretical discussions, demonstrating practical exploitation paths from a ship's VSET to its crucial operational technology (OT) systems, including PLCs and HMIs, capable of causing physical damage and disrupting vessel operations.
The research team, comprising security engineers and university students, highlighted the alarming reality that VSET systems, essential for safety, security, operational efficiency, and crew welfare, are often inadequately secured and exposed to the public internet. They uncovered multiple vulnerabilities, including command injection and remote code execution (RCE), in VSET Antenna Control Unit (ACU) web interfaces from major vendors. The talk underscores the urgent need for a paradigm shift in maritime cybersecurity policy, moving from checklist-based individual equipment certification to comprehensive, ship-wide threat modeling and penetration testing, especially as the lines between IT and OT infrastructure on vessels continue to blur.
This work is particularly significant given recent real-world incidents, such as the Dr. gun hacker group's alleged cyberattack in March 2023, which reportedly paralyzed communication networks on 116 iron vessels. The researchers' findings not only validate the potential for such widespread disruption but also illustrate the deeper implications, revealing how VSET vulnerabilities can serve as a critical entry point for sophisticated attackers to compromise a vessel's entire operational integrity. Their detailed methodology, involving firmware rehosting and the construction of a five-level maritime testbed, provides a compelling case for proactive and systemic cybersecurity measures in the maritime industry.
Background
▶ Watch: Introduction and real-world maritime cyber attack (0:00)
Modern maritime operations are undergoing a profound transformation, driven by the adoption of remote support solutions, autonomous navigation technologies, and increased data transmission requirements. At the heart of this evolution are VSET (Very Small Aperture Terminal) systems, small satellite communication terminals that are becoming increasingly critical for various purposes on ships, military applications, and aviation. VSETs are not merely for general communication; they are integrated into the Global Maritime Distress and Safety System (GMDSS), making them a vital component of search and rescue operations during accidents.
A typical VSET system comprises three main components: the antenna (handling signal transmission and reception), the Antenna Control Unit (ACU), and the modem. The ACU is typically a rack-mounted device responsible for antenna control, monitoring, and often provides a web interface for remote management. The modem converts RF signals to digital data, supporting protocols like DVB-S2 and DVB-RCS2, and includes TCP/IP acceleration for optimized satellite links.
The research team strategically chose to focus on the ACU web interface as their primary target. This decision was driven by several factors:
- Accessibility: Unlike proprietary satellite modem protocols or complex RF processing, ACU web interfaces use standard HTTP/HTTPS, making them accessible with a common web browser to anyone who gains access to a ship's network. Crucially, the researchers also found these interfaces frequently exposed directly on the internet, often protected only by default credentials.
- Impact: Compromising the ACU grants control over the antenna, enabling attackers to disrupt satellite connections or mispoint the antenna, effectively isolating the vessel.
- Practical Attack Vector: This makes the ACU web interface a highly practical and likely first target for an attacker already inside or seeking to enter a ship's network.
Prior cybersecurity research into maritime systems, notably studies presented at Black Hat in 2014 and 2018, identified potential vulnerabilities. However, these studies often stopped short of demonstrating real and practical attack scenarios, largely due to the prohibitive cost of acquiring and testing on actual, expensive VSET equipment. This research aimed to bridge that gap by developing a cost-effective methodology for in-depth analysis and demonstrating practical attack paths without requiring physical access to live, expensive hardware. Their goal was to definitively prove whether VSET web interfaces exposed online could indeed serve as a direct entry point for ship penetration.
Key Findings
▶ Watch: Research focus: ACU web interface vulnerabilities (4:10)
The research yielded several critical findings that underscore the severe cybersecurity risks facing the maritime industry:
- Widespread Vulnerabilities in VSET ACU Web Interfaces: The team successfully identified and rehosted firmware from two major VSET vendors, Cobham and Intellian. In Cobham ACU web interfaces, they discovered six distinct vulnerabilities: four Cross-Site Scripting (XSS) vulnerabilities in various web settings and two command injection vulnerabilities in report functions (specifically, the
statistics reportanddiagnostic reportfeatures). These command injections were particularly dangerous as they occurred because user input was passed directly into system functions without sufficient validation, making them "dangerously easy to trigger." While specific details were withheld for the Intellian equipment, the researchers confirmed the discovery of Remote Code Execution (RCE) vulnerabilities within their ACU web binaries.
- Alarming Online Exposure and Default Credentials: Through OSINT tools like Shodan and Criminal IP, the researchers conducted a scan in 2023 and found 104 Cobham and 14 Intellian ACU web interfaces exposed online. Of these, a significant 25.96% of Cobham systems and a staggering 100% of Intellian systems were found to have known vulnerabilities. Furthermore, many VSET manufacturers, including Cobham, publish default credentials directly in their equipment manuals, which are easily found online. This means attackers can often gain immediate access to sensitive information like satellite configurations, vessel location data, and network topologies without needing to exploit any technical vulnerability, simply by logging in with default passwords.
- Blurring IT/OT Boundaries and Increased Dependence: Visits to the Korean Maritime and Ocean University's research labs and discussions with navigators and engineers revealed three key trends:
- The traditional network separation between IT (Information Technology) and OT (Operational Technology) infrastructure on ships is rapidly eroding.
- As automation replaces human crew roles, ships are becoming heavily reliant on satellite communication for remote data transmission.
- Ethernet is now commonly used for ICS (Industrial Control System) equipment control, further integrating previously isolated OT networks.
- Zero-Day Vulnerabilities in Network Infrastructure: During their lateral movement phase, the researchers purchased widely used network switches from the market and conducted a vulnerability analysis. They surprisingly discovered four zero-day vulnerabilities in these devices. One specific vulnerability demonstrated allowed bypassing administrator login with a manipulated POST request, highlighting the widespread insecurity in critical, off-the-shelf network equipment used in maritime environments.
- Proof of Concept for Physical Damage: The team successfully constructed a five-level maritime testbed, ranging from the VSET to a network gateway, PLC, and HMI. They demonstrated a full attack chain where an attacker, starting from a compromised VSET ACU, could pivot through network devices, access the HMI running Windows CE, and then maliciously overwrite or delete PLC projects. This ability to manipulate the PLC could ultimately lead to physical damage to the vessel, such as forcibly shutting down propulsion systems (demonstrated by stopping a fan representing a ship's propeller) or deploying ransomware disguised as manual PDFs, severely compromising ship availability.
Technical Deep Dive
▶ Watch: Firmware reversing methodology to bypass hardware costs (6:00)
The technical core of this research revolved around two main areas: firmware rehosting to enable cost-effective vulnerability analysis, and the construction of a maritime testbed to validate multi-stage attack scenarios.
Firmware Rehosting and Vulnerability Discovery
To overcome the prohibitive cost of physical VSET equipment, the team developed a robust firmware rehosting methodology.
- Firmware Collection: Firmware for VSET ACUs from two selected vendors, Cobham and Intellian, was acquired through official channels. Cobham's software, in particular, was noted for its use across more than 13 different devices, indicating potential for widespread impact.
- Initial Analysis (Binwalk): The Binwalk tool was employed to quickly analyze the firmware images. This revealed that the firmware was ARM-based and contained a fully embedded file system. This initial check also helped identify any encrypted firmware, which had to be excluded from the study as the goal was to analyze systems without actual hardware.
- File System Extraction: Upon extraction, three directories were identified. The primary
squashfs-rootdirectory contained the main file system structure. - Boot Script Analysis: Investigation of the boot scripts, specifically
etc/init.d/rcSwithin thesquashfs-rootpartition, revealed calls to another script. This script was responsible for setting up symbolic links and directories for mounting. - Second File System Discovery: Following the script's logic, the team found
mount_appl.sh, which usedsu_mount.awkto mount a second file system,squashfs-root-one, into/mnt/applwithin the main root. This second file system proved to be the "gold mine," containing the actual web interface code, which was observed to be running on a lighttpd server. - Rehosting with QEMU: For rehosting, ARM QEMU user-mode emulation was utilized to port the ARM-based firmware environment to a host PC. The
squashfs-root-onefile system was manually mounted into the main root at/mnt/appl, mimicking the real device's setup. The web interface binaries were then started. This meticulous process resulted in a fully functional ACU management web interface running locally, including login pages, settings, and all associated functionalities. This proved that deep, hands-on security research could be conducted without the need for expensive physical hardware.
Vulnerability Details
The rehosting process enabled the discovery of several critical vulnerabilities:
- Cobham ACU Web Interfaces:
- Four XSS vulnerabilities: Found in various ACU web settings, indicating insufficient user input validation. While XSS might seem less critical than RCE, in an authenticated context or combined with other flaws, it can lead to session hijacking or further client-side attacks.
- Two Command Injection vulnerabilities (RCE): These were identified in report functions, specifically the
statistics reportfeature and thediagnostic reportfeature. The core issue was that user input was passed directly intosystem()functions without proper sanitization. This allows an attacker to inject arbitrary shell commands, which are then executed by the underlying operating system. The simplicity of triggering these vulnerabilities was emphasized, requiring no complex explanations or sophisticated techniques.
- Intellian ACU Web Interfaces:
- RCE vulnerability: The researchers confirmed an RCE vulnerability during their analysis of the Intellian ACU web binary. They specifically pinpointed a function,
sub_219C4, which failed to validate user input before passing it tosystem()functions, thereby allowing arbitrary command execution.
Maritime Testbed Construction and Attack Scenario
To validate the real-world impact of these vulnerabilities, a comprehensive maritime testbed was built:
- Iterative Construction: The testbed was developed in two phases: Mark 1 verified basic communication between components at each level, and Mark 2 assembled all equipment into an actual small rack, forming a full maritime testbed.
- Five-Level Architecture: The testbed was designed to represent a typical ship's network, comprising five distinct levels:
- VSET: The entry point, featuring the vulnerable ACU web interface.
- Network Gateway: Connecting the VSET to the internal ship network.
- Network Devices: Representing switches and other infrastructure.
- PLC (Programmable Logic Controller): The core of the OT system, controlling physical processes (e.g., propulsion).
- HMI (Human-Machine Interface): The interface for operators to monitor and control the PLC, running on a Windows CE operating system.
The end-to-end attack scenario demonstrated involved six steps:
- OSINT Hunting: Using Shodan and Criminal IP to identify publicly exposed VSET ACU web interfaces.
- Initial Intrusion: Gaining access via default credentials (common for Cobham and other vendors) or exploiting the discovered RCE vulnerabilities (e.g., in Intellian systems). This grants access to sensitive VSET configurations and network data.
- Internal Network Reconnaissance: Once inside the VSET, attackers use commands like
pingorifconfigto map out connected internal gateways and network devices. - Lateral Movement: Exploiting vulnerabilities in internal network devices. The researchers demonstrated this by discovering four zero-day vulnerabilities in a widely used commercial network switch, allowing them to bypass administrator login.
- HMI Access: Pivoting through the compromised network equipment to reach the HMI, which is connected to the PLC via industrial switching hubs.
- PLC Manipulation and Physical Damage: Gaining control of the HMI allows an attacker to overwrite or delete PLC projects, potentially causing physical damage (e.g., shutting down propulsion) or deploying ransomware disguised as legitimate files.
This detailed technical approach, from firmware analysis to a multi-stage attack validation on a realistic testbed, provides undeniable evidence of the systemic cybersecurity risks in modern maritime operations.
Demo / Proof of Concept
▶ Watch: Discovery of 6 vulnerabilities, including RCE (9:00)
The talk included a compelling live demonstration of the multi-stage attack scenario on their constructed testbed, visually reinforcing the severity of their findings. The demo showcased the following steps:
- Initial ACU Access and Password Change:
- The researchers began by showing an attempt to SSH into the rehosted VSET ACU (running on a Raspberry Pi) with an incorrect password, demonstrating failed access.
- They then leveraged a discovered vulnerability in the ACU web interface to change the root password without authentication. This critical step highlights the ease with which administrative access can be obtained.
- Following the password change, they successfully connected to the ACU via SSH, gaining a command-line interface to the system.
- Internal Network Reconnaissance:
- Once on the ACU, standard Linux commands like
ifconfigwere used to identify connected network interfaces and their IP addresses (e.g.,212and250). - Recognizing the environment as an IoT setting, they proceeded with basic network scanning using
pingandnmap(or similar port scanning commands). Thepingresults identified connected devices at.1and.94. - Subsequent port scanning revealed open ports, such as port 22 (SSH) on
.94and port 80 (HTTP) on.1, indicating a web server, likely a network switch, on the internal network.
- Lateral Movement to Network Switch:
- To access the internal network switch (on IP
.1) from their external attacking machine, the researchers set up port forwarding using SSH. Specifically, they forwarded local port5555to port80on the internal IP.1. - Connecting to
localhost:5555from their machine successfully displayed the login page for the internal network switch. - They then exploited one of the zero-day vulnerabilities discovered in the switch's web interface, allowing them to bypass authentication and gain administrative access to the switch.
- Accessing OT Equipment (Raspberry Pi):
- The ultimate goal of this phase was to verify reachability from the ACU all the way down to a simulated OT equipment, represented by another Raspberry Pi.
- With access to the internal network (via the compromised switch), they successfully SSH'd into the Raspberry Pi at IP
.94, gaining a shell on the simulated OT device. This confirmed the ability to move laterally from the VSET entry point to critical internal systems.
- HMI and PLC Manipulation (Physical Damage):
- The demonstration continued by showing remote access to the HMI (running Windows CE) within the testbed.
- The HMI was depicted as controlling a small fan, simulating a ship's propulsion system.
- The attacker, having infiltrated the ship's network and gained HMI access, proceeded to override the PLC project without requiring further authentication.
- Upon a simulated device restart and pressing the "start" button on the HMI, the fan, which was previously operating, stopped. This visually compelling moment directly demonstrated how a cyberattack originating from a VSET vulnerability could lead to tangible physical damage or operational disruption on a vessel.
- The demo concluded by showing the attacker's ability to even manipulate the HMI interface itself, further asserting complete control over the operator's view of the system.
This comprehensive demonstration provided undeniable proof that VSET vulnerabilities are not isolated issues but represent critical entry points for attackers to pivot into a ship's entire operational technology stack, with the potential for severe physical consequences.
Defensive Implications
▶ Watch: Ship testbed construction and modern vessel trends (10:00)
The findings presented in this talk necessitate a significant re-evaluation of current cybersecurity strategies within the maritime industry. Defenders, including ship operators, equipment manufacturers, and regulatory bodies, must implement a multi-faceted approach to mitigate the systemic risks highlighted.
- Prioritize VSET Security:
- Secure Web Interfaces: Immediately change all default credentials on VSET ACU web interfaces. Implement strong, unique passwords for every device.
- Patch Management: Promptly apply security patches and firmware updates released by vendors for VSET systems. The high percentage of vulnerable Intellian and Cobham systems found online underscores this critical need.
- Restrict Exposure: VSET ACU web interfaces should never be exposed directly to the public internet. Implement strict firewall rules and network segmentation to ensure these interfaces are only accessible from authorized internal networks, ideally through secure remote access solutions (e.g., VPNs) for maintenance.
- Input Validation: Manufacturers must implement robust input validation mechanisms in all web interfaces to prevent vulnerabilities like XSS and command injection. User input should never be passed directly to system functions without sanitization.
- Enhance Network Segmentation:
- Strict IT/OT Separation: Given the blurring lines between IT and OT networks, it is crucial to re-establish and enforce strict network segmentation. Critical OT systems (PLCs, HMIs, navigation systems) must be isolated from less secure IT networks, and especially from external internet connections.
- Industrial Firewalls and IDS/IPS: Deploy industrial-grade firewalls and Intrusion Detection/Prevention Systems (IDS/IPS) at the boundaries between IT and OT networks, and within OT networks themselves, to monitor for malicious traffic and prevent unauthorized lateral movement.
- Implement Ship-Wide Threat Modeling and Penetration Testing:
- Move Beyond Checklists: The current reliance on checklist-based security and individual equipment certification (e.g., IMO requirements, ISO/IEC standards) is insufficient. Cyberattacks are systemic, exploiting interdependencies and cascading vulnerabilities across multiple connected devices.
- Holistic Approach: Adopt a holistic, ship-wide approach to cybersecurity. This involves comprehensive threat modeling to identify potential attack paths across the entire vessel architecture, followed by regular penetration testing that simulates real-world attack scenarios, including initial access via VSETs and lateral movement into OT systems.
- Customized Testbeds: Shipping companies should partner with security researchers to build customized testbeds that accurately mirror the specific equipment and network configurations on their vessels, allowing for realistic vulnerability assessment and defense validation.
- Secure Internal Network Infrastructure:
- Audit Network Devices: Regularly audit and secure all network devices (switches, routers, gateways) within the ship's network. This includes changing default credentials, patching known vulnerabilities, and implementing secure configurations. The discovery of zero-day vulnerabilities in widely used switches highlights the hidden risks in these foundational components.
- Least Privilege: Apply the principle of least privilege to all network devices and user accounts.
- Foster Collaboration and Policy Reform:
- Industry-Regulator Collaboration: The maritime industry, regulators, and cybersecurity researchers must collaborate to develop and enforce more adaptive and comprehensive cybersecurity policies that account for the rapid digitalization and evolving threat landscape (e.g., autonomous ships).
- Information Sharing: Establish mechanisms for sharing threat intelligence and vulnerability information across the maritime ecosystem to enable faster response and proactive defense.
By proactively addressing these defensive implications, the maritime industry can significantly reduce its attack surface, enhance resilience against cyber threats, and safeguard the safety and operational integrity of vessels.
Key Takeaways
- VSETs are Critical and Vulnerable Entry Points: VSET systems, essential for maritime communication and safety, are frequently exposed online with easily exploitable vulnerabilities (XSS, command injection, RCE) and often protected only by default credentials.
- Cost-Effective Research via Firmware Rehosting: The research demonstrated that firmware rehosting using tools like Binwalk and QEMU is a viable and cost-effective method to conduct in-depth security analysis of embedded systems without requiring expensive physical hardware.
- Vulnerabilities Allow Multi-Stage Attacks to OT: A compromised VSET ACU can serve as a pivot point for attackers to move laterally through internal ship networks, exploit zero-day vulnerabilities in network switches, and ultimately gain control over HMI and PLC systems, leading to physical damage or operational disruption.
- IT/OT Convergence Amplifies Risk: The blurring of IT and OT network boundaries on modern vessels, coupled with increased reliance on satellite communication and Ethernet-based ICS control, creates a larger and more interconnected attack surface, making systemic compromise more feasible.
- Current Maritime Security Policies are Inadequate: Existing checklist-based security policies and individual equipment certifications are insufficient to address the systemic nature of modern cyberattacks. A shift towards ship-wide threat modeling and comprehensive penetration testing is urgently needed.
- Collaboration is Essential for Future Security: Protecting maritime assets, especially with the advent of autonomous ships, requires concerted efforts from industry stakeholders, regulators, and cybersecurity researchers to develop robust, adaptive, and proactive security measures.
About the Speaker(s)
The research presented was a collaborative effort by Juwon Cho, Jono, and Sun Lee. Juwon Cho is a Maritime Cyber Security Research Engineer at Cyber Inc., contributing his expertise to securing critical infrastructure in the maritime domain. Jono is currently pursuing his Master's degree at Jansen University, indicating a focus on advanced academic research in cybersecurity. Sun Lee is a student at Hanong University, actively engaged in cyber security research, showcasing a commitment to practical application of security knowledge. Their collective work was conducted under KIT's Best of Best program, where they participated as the 12th cohort, a prestigious initiative aimed at fostering top-tier cybersecurity talent and research.
Reviews
Dr. Zero (Offensive Security Researcher) — STRONG ACCEPT
A genuinely solid piece of applied security research that earns its place at DEF CON by doing the actual work: firmware rehosting, real CVEs against named vendors, zero-days in commodity network hardware, and a five-level testbed that validates a full VSET-to-PLC kill chain. The policy framing fits the Policy @ DEF CON track and doesn't dilute the technical core. Minor reservations around the student-team execution polish and the fact that some of the policy recommendations are fairly standard hygiene, but the primary research contribution is real and the demo is damning.
Heather Calloway (CISO) — SOLID
Credible technical research with a clear attack chain and a policy argument that points in the right direction but never lands with force. The work is real; the governance case is underdeveloped.