Showing posts with label Defcon Hacking Conference. Show all posts
Showing posts with label Defcon Hacking Conference. Show all posts

Friday, 31 July 2015

Hacker Makes Tool To Unlock GM Cars Remotely



The well-known hacker Samy Kamkar has a tool designed to cars from manufacturer General Motors (GM) are located remotely open and start. GM offers car owners a service called OnStar with which the car can be found via a smartphone app, opened and started.

Kamkar developed for 100 dollars a small device, the OwnStar that a car or truck should be placed and the communication of the smartphone to the app to intercept. The problem with the app is that SSL be used to exchange encrypted data, but the certificate does not correctly check to ensure that there is communication with the real OnStar servers.

The Ownstar consists of a Raspberry Pi and three radios and can occur as a friendly network. Once the user's GM Remote Link app launch and the smartphone within range of the device is a man-in-the-middle attack is carried out in order to steal the user's credentials. Then these data are from a 2G GSM connection is sent to the attacker. With the login information, an attacker then follow the car, open the doors, start the engine or to sound the horn or alarm.

Starting on distance is not possible, this is still requires a human operator. GM is now working on an update to address the problem, as a spokesperson of the automaker opposite Wired know. During the upcoming Def Con conference in Las Vegas will Kamkar provide more information about his attack. The following video shows already see a short demonstration.

Sunday, 19 July 2015

Hacker Develops Device To Surf The Internet Anonymously


A well-known hacker has developed a device that users can go online anonymously, without their actual location or IP address to give up. The ProxyGambit of Samy Kamkar is an "improvement and reincarnation" of the ProxyHam. The ProxyHam would be demonstrated at the Defcon hacking conference initially, but researcher Benjamin Caudill concluded his lecture for letting off unknown reasons.

Also destroyed it all prototypes of the ProxyHam and announced that the software and blueprints of the device would not be published. The ProxyHam was a device that consisted of a Raspberry Pi computer with Wi-Fi card and three antennas. An antenna connection made ​​with an open Wi-Fi network, for example at a Starbucks or library, and two antennas that sent the data to and from the user via a 900Mhz frequency. A user could be at a position of 4 kilometers.

ProxyGambit

Kamkar, which in recent months regularly with all kinds of hardware hacks in the news came out, decided to develop its own solution based on the idea of ProxyHam. The ProxyGambit however, leave more space between the user and the used Wi-Fi network. The device supports both a radio link as a mobile bridge to connect to a Wi-Fi network. In the case of the GSM network can bridge the thousands of kilometers away there. Is made ​​using a direct link, the distance 10 kilometers.

Like the ProxyHam assigns the IP address that is visible to the outside world to the Wi-Fi network that uses the ProxyGambit. To connect to the mobile bridge, which used 2G, can be used as Kamkar a prepaid SIM card, which can be obtained anonymously. "In both cases, your connection proxied by local Wi-Fi networks in the vicinity of the unit, making it difficult to determine your actual location, IP and identity," Kamkar says.

The hardware for the ProxyGambit consists of an Arduino Nano, Raspberry Pi, GSM Fona, USB hub, wifi adapter, Ubiquiti Nano Station and a Power over Ethernet injector. The cost of the parts amounts include 200 dollars. The software for the device, the hacker on GitHub placed while a Linux image via Dropbox is available for download. Kamkar warns that this is still a "proof of concept" goes and users for whom privacy and anonymity is important to do further research.