메뉴
BL
Ars Technica • 45일 전

DEF CON 해커들, 비행기 내 가짜 Wi-Fi로 피싱 의심

IMP
7/10
핵심 요약

보안 컨퍼런스인 DEF CON이 끝난 직후, 라스베이거스에서 애틀랜타로 향하던 델타항공 항공기 내에서 악성 가짜 Wi-Fi 핫스팟이 운영된 사건이 발생했습니다. 보안 전문가로 추정되는 승객들이 기내 네트워크를 방해하고 피싱 페이지를 통해 탑승객들의 개인정보를 탈취하려 한 정황이 포착되어 현재 FBI가 수사에 나섰습니다.

번역된 본문

월요일, 라스베이거스에서 애틀랜타로 향하던 델타항공 591편 승객들이 기내 Wi-Fi를 사칭했다는 혐의를 받으며 연방 수사 기관의 주목을 받았습니다. 이 사건은 라스베이거스에서 열린 보안 컨퍼런스 'DEF CON'이 종료된 지 하루 만에 발생했으며, 항공기와 지상 간의 공개 통신 메시지인 ACARS를 추적하는 소셜 미디어 계정을 통해 처음 알려졌습니다.

'ACARS Drama' 계정에 따르면, 해당 항공기의 조종사가 보낸 메시지에 다음과 같이 적혀 있었습니다. "현재 파악된 바로는, 라스베이거스 사이버 컨퍼런스에 참석했던 승객들이 우리의 Wi-Fi를 교란(Jam)하고 자신들의 신호를 방송하고 있다는 것입니다."

Reddit에 올라온 사건 설명글은 이 승객들이 "Delta WiFi Fast"라는 이름의 가짜 핫스팟을 만들고, 탑승객들의 개인 인증 정보를 수집하기 위해 설계된 피싱 랜딩 페이지를 운영했다고 추가로 밝혔습니다. 가짜 Wi-Fi 네트워크를 구축한 뒤 로그인 자격 증명 및 기타 데이터를 가로채는 이 기술은 '이블 트윈(Evil Twin)' 공격으로 알려져 있으며 IT 보안 업계에 오랫동안 알려져 왔습니다.

델타항공의 대변인인 모건 듀란트(Morgan Durrant)는 본지(Ars)에 이러한 세부 사항을 확인해주었습니다. 듀란트는 이메일을 통해 "델타항공이 제공, 운영 또는 공급하지 않은 승인되지 않은 Wi-Fi 네트워크가 비행 중 잠시 항공기 내에 존재했다는 것이 초기 조사 결과"라고 밝혔습니다. 델타항공은 또한 항공기의 안전은 "전혀 위협받지 않았으며 어떤 항공기 운영 시스템도 영향을 받지 않았다"고 강조했으며 비상사태가 선포되지는 않았다고 덧붙였습니다. 다만 실제 기내 Wi-Fi는 30분 동안 사용 중지되었습니다.

애틀랜타 경찰국은 모든 문의를 FBI로 넘겼습니다. 애틀랜타 FBI 지국은 본지에 이 사안을 조사하고 있다고 밝혔습니다. 당국은 체포된 사람이 없으며 FBI 요원이 게이트에서 항공기를 직접 조우하지는 않았다고 전했습니다. FBI 애틀랜타 대변인 토니 토마스(Tony Thomas)는 성명을 통해 "FBI 애틀랜타는 델타항공 591편과 관련된 잠재적인 Wi-Fi 사건 보고를 인지하고 있다"며 "이 문제와 관련하여 지역 및 기업 파트너들과 접촉하고 있으며, 현 시점에서 추가로 제공할 정보는 없다"고 이메일로 밝혔습니다.

원문 보기
원문 보기 (영어)
Text settings Story text Size Small Standard Large Width * Standard Wide Links Standard Orange * Subscribers only Learn more Minimize to nav On Monday, passengers aboard Delta flight 591 going from Las Vegas to Atlanta allegedly spoofed the onboard Wi-Fi, raising the attention of federal law enforcement. The incident came one day after the DEF CON security conference concluded in Las Vegas, and was first described on social media accounts that follow publicly available air-to-ground messages, known as ACARS. According to the “ACARS Drama” account, a message was sent by pilots from the plane stated: “NO INFO AS OF NOW WE HAVE A BUNCH OF PAX THAT WERE AT A CYBER CONFERENCE IN LAS THEY WERE ABLE TO JAM OUR WIFI AND BROADCAST THEIR SIGNAL.” A description of the incident posted to Reddit further stated that these passengers created a fake hotspot (“Delta WiFi Fast”), with a phishing landing page “designed to harvest passengers’ personal credentials.” This technique, sometimes known as an “ evil twin ” attack, has been long-known to the IT security community. It involves setting up a fake Wi-Fi network and then capturing login credentials and other data. Morgan Durrant, a Delta spokesperson, confirmed the details to Ars. “One initial finding is an unauthorized WiFi network, which was not provided, operated, or supplied by Delta, was present onboard the aircraft for a short time during the flight,” Durrant told Ars via email. Delta further noted that the flight’s safety was “never in question and no aircraft operating systems were affected,” and that no emergency was declared. The actual onboard Wi-Fi was disabled for 30 minutes. The Atlanta Police Department referred all inquiries to the FBI. Atlanta’s FBI bureau told Ars that it is looking into the matter. Officials there noted that no arrests were made, and that FBI agents did not meet the flight at the gate. “FBI Atlanta is aware of reports regarding a potential Wi-Fi-related incident involving Delta Flight 591,” Tony Thomas, a spokesperson for FBI Atlanta, emailed Ars in a statement. “We are in contact with our local and corporate partners on this matter. We have no additional information to provide at this time.” 54 Comments