Showing posts with label Krypton Security. Show all posts
Showing posts with label Krypton Security. Show all posts

Saturday, 19 September 2015

Chrysler Drivers Warned Of USB Sticks And Wifi



Owners of a Chrysler should not USB flash drives, connect memory cards or CDs from strangers on their car and ensure that the Wi-Fi network of the vehicle is secured with WPA2. It advises the Industrial Control Systems Cyber ​​Emergency Response Team (ICS-CERT), part of the US Department of Homeland Security.

The reason for the recommendation is a vulnerability in the UConnect infotainment system, which allows the operation of the vehicle can be controlled. An attacker could remotely login without credentials on the UConnect system.Subsequently, it is possible to control or information, such as to adjust the speedometer of the brake, the steering wheel and the air conditioning. Because of the vulnerability was demonstrated in July, Chrysler decided to 1.4 million cars to recall that a patch could be installed. For this, also USB sticks with the update sent to clients.

Network provider Sprint decided to block ports that attackers could communicate with the UConnect system. According to the ICS-CERT, it is difficult to develop a working attack that makes use of the leak abuse. In addition, the UConnect systems currently are unattainable because Sprint is blocking the ports, which reduces the likelihood of a successful attack.

Despite the measures adopted previously by Chrysler and Sprint advises the government organization Chrysler drivers to take protective measures. In addition to enabling WPA2 for the Wi-Fi network and avoiding unreliable media are also advised to ensure that all the connected devices and / or systems are not accessible from the Internet and remote access is still required there using a VPN must be made.

Wednesday, 29 July 2015

Experts Denounce Sending USB Drives By Chrysler


Last week, carmaker Chrysler announced that the 1.4 million cars because of a vulnerability in the software recall. The vulnerability allows an attacker cars via the Internet partly control. So the brakes can be switched on and off and it is possible to turn off the engine.

Chrysler developed an update for the security vulnerability and offers now via three ways. Consumers can download the update itself and update the car software via a USB stick. This is now a comprehensive manual ( pdf ) appeared online. The second option is to return the car to the dealer who then installs the update. In addition, there is also a third possibility.Namely to allow sending a USB stick with the update.

And it is this last option that can count on criticism from security experts. "This is the dumbest action that I've heard in a long time," said Khalil Sehnaoui Krypton Security embarrassed about ZDNet . Also Tod Beardsley security company Rapid7 is not happy with the action. "Just a USB stick into the computer stabbing without knowing exactly where it comes from is a bad idea," he observes. He warns that teaching users that they have a USB stick that can confidence be sent by post creates a dangerous behavior and opens the door for criminals to take advantage of this.

Chris Kennedy of anti-fraud business Trustev takes the decision to send around USB sticks "incredibly irresponsible" and "unsafe". Kennedy is especially worried that the USB sticks be intercepted. Also on Twitter users react with amazement."Now is a good time to send USB sticks containing exploits for any Chrysler owners", as a late Twitterer know. Beardsley advises owners of Chrysler to go to a dealer. Since there are then at least one more track is that paper shows that there is a reliable party is searched. Chrysler states in response that the measure is selected to increase convenience for customers.