Showing posts with label Vehicles Hacking. Show all posts
Showing posts with label Vehicles Hacking. Show all posts

Sunday, 16 August 2015

Hacker Can Now Access Remote BMW And Mercedes



The famous hacker Samy Kamkar recently a tool presented that he cars from General Motors could open remote start and has expanded its device, which also cars from BMW, Mercedes-Benz and Chrysler are no longer safe. This has Kamkar via Twitter announced.

Like General Motoros other manufacturers offer a smartphone app to locate car, open and start. It involves BMW RemoteMercedes-Benz mbrace and Uconnect Chrysler. Kamkar developed for 100 dollars a small device, the OwnStar that a car or truck should be placed and the communication of the smartphone to the app to intercept.

The Ownstar consists of a Raspberry Pi and three radios and can occur as a friendly network. Once the user starts the app and the phone within range of the device is a man-in-the-middle attack is carried out to steal the user's credentials. Then this data via a 2G GSM connection is sent to the attacker. With the login information, an attacker then follow the car, open the doors, start the engine or to sound the horn or alarm.

The problem is that with the apps who do use SSL to exchange encrypted data, but the certificate not control well to ensure that there are also communicates with the real servers of the mobile service. General Motors fixed it the problem but Kamkar discovered that the problem with BMW, Mercedes-Benz and Chrysler plays. According to the hacker, the cars thus easy to fall into. Manufacturers are now working on an update, but that is not yet available. Kamkar advises car owners not to use temporarily the corresponding apps.

Thursday, 13 August 2015

Researchers Hack Corvette Via SMS



A vulnerability ( pdf ) in a dongle which is used by insurance companies and fleet managers to monitor cars remote makes it possible for attackers to operate all kinds of parts via SMS. That the researchers today at the Usenix Security Conference show in Washington.

The C4 OBD2 dongle of the French Mobile Devices makes it possible to monitor the location, speed and efficiency of vehicles. The devices are plugged into the diagnostic port (OBD-II) of the car, that is usually located under the steering wheel.The device features a GPS receive, mobile phone chip and onboard microprocessor. If the car driving is the dongle communicates with CAN bus of the car. This is the internal network that controls the physical components of the car.

The dongle then sends information from the car via the GSM network to the provider. Researchers at the University of California managed by sending text messages to the dongle to control the CAN bus of the car. For their demonstration, the researchers used a red Corvette, as in the video below shows. Via text message, they could eventually turn the brakes and turn off and turn on the windshield wipers.

Update

The US insurance company which distributes the Metro Mile dongles in the US was warned in June by investigators for the leak. Both Mobile Devices as Metro Mile argue that they have rolled out an update that automatically over-the-air is installed.The CERT Coordination Center (CERT / CC) at Carnegie Mellon University warns that there is no way to verify that the update is installed.

Users who do not know whether their dongle is vulnerable therefore be advised to remove the device until the update can be confirmed. Through the leak, an attacker can cause damage to the car or provide human injury, according to the CERT / CC.According to Wired would still driving thousands of vulnerable cars, mainly in Spain.

Wednesday, 29 July 2015

Wifi System Skoda Cars Vulnerable To Attackers


Several vehicles carmaker Skoda has a wifi system so that it can be read on a tablet or smartphone information from the car, but according to researchers is inadequate security. The SmartGate system lets users create through wifi to connect to the car.

Then all kinds of data can be read, such as speed, fuel consumption, number of days until the next service and other information. Researchers at Trend Micro discovered that an attacker more than twenty different parameters can be read out and the owner of the car from the SmartGuard system can exclude. To carry out the attack, an attacker must remain in the vicinity of the Wi-Fi network of the car and then crack the wifi password. That's according to the researchers, however, rather weak. Also, it is no problem to stay close to the Wi-Fi network. With a speed of up to 40 kilometers per hour they managed to crack the Wi-Fi network.

Reading the data even managed a speed of 120 kilometers per hour. The researchers argue that an attacker can modify the wifi settings and the user so can eliminate the system. Then it must return to the dealer to put make back its institutions. The researchers advise owners of a Skoda with SmartGate to put the wif-range at 10% and change the wifi password and network name. Skoda is advised to set the standard signal strong at 10% and an on / off switch SmartGate design. SmartGate would be present at least in the Octavia, Yeti and Superb.