Vulnerability Assessment and Exploitation of

il y a 1 semaine


Paris, France Quarkslab Temps plein

Quarkslab is a privately held company founded in 2011 with currently more than 100 employees. The company focuses on vulnerability research, reverse engineering and design of security solutions and has developed leading software in the area of threat detection and code/data protection.
Quarkslab provides a broad set of products and services based on deep knowledge in the area of Cybersecurity.

**Job description**:
This internship project focuses on assessing and exploiting vulnerabilities in satellite communication systems, to improve their resilience against cyber threats. The intern will simulate various cyber-attacks on a selected satellite system, analyzing its communication interfaces, and attempting to identify and exploit weaknesses. The project will also involve designing and testing mitigation strategies that can defend satellite systems against these attacks. Over the six months, the intern will develop practical cybersecurity skills while working with satellite communication technology and conducting in-depth research.
- ** Cybersecurity Knowledge**: Understanding of security assessment techniques, vulnerability research, and penetration testing.

**What you will do**
- ** Satellite System Selection**: Identify and analyze a suitable satellite system (e.g., aging weather satellite, decommissioned research satellite) for vulnerability testing.
- ** Communication Interface Analysis**: Perform a detailed analysis of the satellite’s communication systems, including uplink (command) and downlink (data) channels, identifying potential security vulnerabilities in these pathways.
- ** Attack Simulations**: Conduct simulated cyber-attacks on the selected satellite.
- ** Data Retrieval and Analysis**: Attempt to retrieve valuable data from the satellite's transmissions, such as telemetry and operational commands. Analyze the data for potential security risks and sensitive information leaks.
- ** Mitigation Strategy Development**: Propose and validate cybersecurity measures to protect the satellite from future threats, based on the results of attack simulations.

**Profile**:

- ** Programming Skills**: Proficiency in Python, C++, or related languages for scripting attack simulations and data analysis.
- ** Data Analysis**: Knowledge of data analysis tools to retrieve and analyze intercepted satellite signals.
- ** Cybersecurity Knowledge**: Understanding of security assessment techniques, vulnerability research, and penetration testing.

**Assignment**
- ** Choose a Relevant CVE**:
Select a CVE from 2022 or later that impacts satellite communication systems, satellite ground stations, or related components. For example: CVE-2024-44910, CVE-2024-44912, CVE-2024-44911. There exists a detailed blogpost explaining the latter mentioned CVEs, if you choose either of them try to dig deeper.
- ** Detailed Analysis**:

- ** Root Cause Analysis**:
Describe the root cause of the vulnerability, including the affected components and how the flaw originated. Discuss any relevant design or implementation flaws that led to the vulnerability.
- ** Impact Assessment**:
Explain the potential impact of the vulnerability on satellite operations and security. Consider scenarios such as data interception, service disruption, or unauthorized control.
- ** Exploitation Path**:

- Outline a clear exploitation path for the vulnerability. Describe the steps an attacker would need to take to exploit the identified vulnerability effectively.
- Include any prerequisites or conditions required for successful exploitation.
- ** Proof of Concept (PoC)**:

- Develop a non-functional proof of concept to demonstrate the feasibility of your exploitation path. This could be a code snippet, a detailed walkthrough, or a flowchart illustrating the attack steps.
- Provide clear instructions on how the PoC can be replicated or tested.



  • Paris, France Blackfluo.ai Temps plein

    Position OverviewWe are seeking a Cybersecurity Vulnerability Management Specialist to identify, assess, prioritize, and remediate security vulnerabilities across our enterprise infrastructure and applications, utilizing advanced scanning tools and implementing comprehensive vulnerability management programs to maintain organizational security posture.Key...


  • Paris, France Apple Temps plein

    A leading technology company in Paris is seeking a manager for their security team, focusing on embedded security and the iOS/macOS architecture. This role requires leadership in conducting security assessments and vulnerability research, ensuring the safety of their technologies. Ideal candidates will demonstrate strong communication skills and a passion...


  • Paris, France OECD Temps plein

    THE EXECUTIVE DIRECTORATE (EXD)The Executive Directorate (EXD) is the steward of OECD resources on behalf of the Secretary‑General. Our focus is on people and their wellbeing; the effective and efficient management of the budget; the safety and security of staff Delegations visitors and of the OECDs data; maintaining and sustaining physical and digital...

  • Vulnerability Researcher

    il y a 2 jours


    Paris, France Apple Temps plein

    Our team is dedicated to safeguarding Apple products encompassing everything from the microarchitecture to applications like Safari Mail and Messages. Our responsibilities include evaluating the security of iOS and macOS (kernel and user‑land) boot ROMs firmware and hardware. By collaborating with a diverse range of teams and vendors your influence will be...


  • Paris, France MANGOPAY Temps plein

    Company Description MANGOPAY’s mission is to shape the future of exchanges! We empower all marketplaces and platforms by providing them with powerful and flexible payment and regulatory solutions. Since 2013, we have accelerated the success of some of the biggest names in e-commerce, retail, and cutting-edge platforms like Vinted, Rakuten, Chrono24, La...

  • Vulnerability Researcher

    il y a 2 jours


    Paris, France Apple Temps plein

    A leading technology company is seeking a security engineer to evaluate the security of its products, including iOS and macOS. You will leverage proven experience in vulnerability research and binary exploitation to influence security across Apple’s range of devices, including iPhone and iPad. Strong problem-solving, analytical, and communication skills...


  • Paris, France GeoPolist Temps plein

    The IOC Marine Policy and Regional Coordination Section of the IOC engages with diverse partners to develop science-based tools and approaches for sustainable ocean management, including marine spatial planning, sustainable ocean planning and management, and the management of large marine ecosystems. It also leads the coordination of the UN Ocean Decade. The...

  • Vulnerability Researcher

    il y a 2 semaines


    Paris, Île-de-France Apple Temps plein

    Apple's Security Engineering & Architecture organization is responsible for the security of all Apple products. Passionate about safeguarding our users, we believe that the best defense requires a great offense. When it comes to securing more than a billion devices running the world's most sophisticated operating systems, that means finding vulnerabilities...


  • Paris, France Apple Inc. Temps plein

    Paris, Ile-de-France, France Software and ServicesDescriptionWe are looking for a manager with experience in dealing with complex systems and bringing ideas to the level of products. Our organization focuses on securing low-level technologies such as the iOS and macOS kernel, boot ROMs, firmware and hardware. Working alongside a wide variety of teams and...


  • Paris, France University of Groningen Temps plein

    Post-doc proposal "quantitative assessment of the energy transition"Friday, 31 July 2020 10:06Post-doc proposal "quantitative assessment of the energy transition"In the framework of the EU funded project TIPPING+ (Enabling Positive Tipping Points towards clean-energy transitions in Coal and Carbon Intensive Regions), the Paris School of Economics is...