Showing posts with label Uconnect. Show all posts
Showing posts with label Uconnect. Show all posts

Sunday, 16 August 2015

Hacker Can Now Access Remote BMW And Mercedes



The famous hacker Samy Kamkar recently a tool presented that he cars from General Motors could open remote start and has expanded its device, which also cars from BMW, Mercedes-Benz and Chrysler are no longer safe. This has Kamkar via Twitter announced.

Like General Motoros other manufacturers offer a smartphone app to locate car, open and start. It involves BMW RemoteMercedes-Benz mbrace and Uconnect Chrysler. Kamkar developed for 100 dollars a small device, the OwnStar that a car or truck should be placed and the communication of the smartphone to the app to intercept.

The Ownstar consists of a Raspberry Pi and three radios and can occur as a friendly network. Once the user starts the app and the phone within range of the device is a man-in-the-middle attack is carried out to steal the user's credentials. Then this data via a 2G GSM connection is sent to the attacker. With the login information, an attacker then follow the car, open the doors, start the engine or to sound the horn or alarm.

The problem is that with the apps who do use SSL to exchange encrypted data, but the certificate not control well to ensure that there are also communicates with the real servers of the mobile service. General Motors fixed it the problem but Kamkar discovered that the problem with BMW, Mercedes-Benz and Chrysler plays. According to the hacker, the cars thus easy to fall into. Manufacturers are now working on an update, but that is not yet available. Kamkar advises car owners not to use temporarily the corresponding apps.

Thursday, 6 August 2015

Manufacturer: Vulnerable Infotainment System Only At Chrysler


Recently, two researchers demonstrated how vulnerable infotainment system via a car manufacturer Chrysler could attack, but fragile models are used only by Chrysler as the manufacturer of the infotainment system. Researchers Charlie Miller and Chris Valasek demonstrated how to turn on and off remotely the brakes on a car. It was also possible to turn off the motor.

The problem was in Uconnect, a component that gives the car's online capabilities and with which the navigation and entertainment system are to operate. The functionality even offers a wifi hotspot and makes phone calls possible. Uconnect allows anyone with a vehicle connection as long as the IP address of the car is known. Due to the problem Chrysler decided to 1.4 million cars to recall. However, it was a voluntary recall, in which drivers were advised to (have) the software of their auto update.

An infotainment system made ​​by audio manufacturer Harman Kardon is part of Uconnect. According to CEO Dinesh Paliwal, Harman Kardon, the researchers used a GSM connection to connect to the radio system, where then the brakes and other key functions were controlled. "Our system was safe," so let Paliwal opposite Reuters know.

The problem would be caused by an open port in a network. "If you open the door of the house open late, will someone come in and they can do anything," said Paliwal. He also announced that the problem only plays with the infotainment systems developed for Chrysler. The hacked infotainment system would also be made ​​five years ago. Current models have much more security, so the CEO noted. Meanwhile, the US government agency that started to millions Harman systems research is responsible for road safety, reports the Associated Press .

Saturday, 25 July 2015

Chrysler Raises 1.4 Million Cars Back Because Of Vulnerability



Carmaker Chrysler raises some 1.4 million cars and trucks back because of a vulnerability in the software that allow attackers over the internet can access the vehicles. It is then possible to switch on the brakes, to turn off and to turn off the motor at low speeds.

The vulnerability was by researchers Charlie Miller and Chris Valasek discovered . The problem is in Uconnect, a component that gives the cars online capabilities and that the entertainment and navigation are operable. The functionality even offers a wifi hotspot and makes phone calls possible. Uconnect allows anyone with a vehicle connection as long as the IP address of the car is known.

After the connection was made with a car, the researchers succeeded in order to adapt the firmware of the system. This custom firmware can then send instructions via the internal network of the car to the physical components such as the engine and the wheels.

Recall

After Chrysler nine months ago was informed, was the manufacturer on July 16 with a security update . The update must be installed via a USB stick by car owners. The fear was that many owners would not do this. Therefore Chrysler now launched a voluntary recall, let the manufacturer through their own website to know. It is about 1.4 million vehicles. According to Chrysler there are no attacks still in the "wild" that have been observed using the vulnerability.

The problem is present in the MY Dodge Viper and different models of RAM pickup, the Jeep Grand Cherokee and Cherokee SUVs, Dodge Durango SUVs, different My Chrysler and Dodge Charger sedans and Dodge Challenger sports coupe.Customers of an affected vehicle will have received a USB device that they can use to upgrade the car software. The upgrade not only resolves the vulnerability, but also adds additional security measures, according to Chrysler.

Wednesday, 22 July 2015

Brakes Chrysler Cars To Be Operated By Remote Leak


Two well-known security researchers have discovered a vulnerability in cars of Chrysler manufacturer, making it possible to remotely activate the brakes of hundreds of thousands of vehicles, and also to turn off to turn off the motor at low speeds.

It is also possible to control the climate control system and to control the radio, and windshield wipers. The researchers are working on the possibility to take control of the wheel. Currently this is only possible if the car is in reverse. The problem is in Uconnect, a component that gives the cars online capabilities and that the entertainment and navigation are operable. The functionality even offers a wifi hotspot and makes phone calls possible.

Uconnect allows anyone with a vehicle connection as long as the IP address of the car is known. After the connection had been made with a car managed researchers Charlie Miller and Chris Valasek therein in order to adapt the firmware of the system. This custom firmware can then send instructions via the internal network of the car to the physical components such as the engine and the wheels.

The attack would work on any Chrysler vehicle features Uconnect and the end of 2013, has been delivered in 2014 or early 2015. According to researchers, there would be an estimated 471,000 vulnerable cars are in the United States. The researchers will present their work at the upcoming Black Hat conference demonstrated, in which part of the exploit will be published, reports Wired .

Update

Chrysler was almost nine months ago already informed by the researchers. The manufacturer warned car owners on July 16 that an update was available. However, it is a cryptic message saying that a software update is available that improves the cars' electronic security "and communication systems, without letting you know what the impact of the vulnerability can be repaired. An additional problem is that the update of Chrysler manually using a USB flash drive must be installed. Users can do this yourself or have it done through the dealer. However, chances are that this many vehicles will never receive the update.