Showing posts with label VehicleCybersecurity. Show all posts
Showing posts with label VehicleCybersecurity. Show all posts

Tuesday, June 29, 2021

Tesla; still targeted

 

Over the years since that fateful day in 2015, there have been many people who have made their name with vehicle hacks. The attacks can be mundane or affect critical systems. Disabling the A/C is by far different than the engine or braking system.

Any vehicle system will have vulnerabilities. The researcher just must find them. One auto manufacturer targeted in the last approximately three years has been Tesla. The vulnerabilities found have required physical access and others have not. In this instance, the vulnerability was found by a Canadian software developer from Quebec (Shankar Gomare). Normally the vulnerabilities are found by cybersecurity researchers. In this case, he was working on his “Voice for Tesla” iOS app early in 2021 and noted the significant vulnerability with Tesla’s Bluetooth key technology. The developer’s app functions much like Amazon’s Alexa providing reminders via voice. The difference with this is the application would not require a specific word or phrase, as Alexa does.

Through developing the application, the developer noted Tesla uses two different forms of Bluetooth sensors in the vehicle. These are Bluetooth Basic Rate/Enhanced Data Rate (BR/EDR). This is used generally for streaming music. The other is Bluetooth Low Energy (BLE). The phone key uses this method. You would use this as a convenience as this use allows the keyholder to unlock the vehicle by being proximate to the vehicle with the connected mobile device (e.g., phone).

As you can figure, the exploit involves Bluetooth. The vehicle’s sensors are coded to detect the strongest Bluetooth signal for connected devices within its range prior to the execute unlock function. This occurs generally with the owner’s mobile device. Here is the issue. The researcher noted the BLE connection did not require authentication to connect to the vehicle. This ends up allowing the researcher to unlock any Tesla by acting as the phone key by forcing the vehicle the request the key from the actual mobile device-by pulling on the door handle.

For this to work, the actual owner’s mobile device would still need to be within 200m-400m for the BLE range. This may seem a bit risky if the owner were walking to their vehicle at the end of the day and saw the person. Where this would work much better would be if the Tesla were parked in the driveway in the evening. Yes, this was patched with an over-the-air (OTA) update.

This is another example of the importance of allowing legitimate cybersecurity researchers to act. The researcher conducted himself appropriately and worked with Tesla for a responsible disclosure. Think through what could have happened if the bad actor had this method and went another route.

Tuesday, May 4, 2021

Interesting new Tesla Hack!

 This is from the “What will they think of next” file. Imagine you have just purchased your dream car-the Tesla Model X. You drive it home, with the windows down and the music on. Life is good. You park in the driveway and start to walk up to your house with a smile on your face. Just before you unlock the door, you look back at your new purchase. There’s an annoying drone nearby. Your new pride and joy starts acting odd, especially since you are not in the vehicle. The doors begin to open together, then one at a time. The trunk opens and closes rhythmically with the doors. 


As odd as this sounds, this is possible and has been done. Researchers presented this work at the CanSecWest conference (virtual) on April 29, 2021. The researchers used two vulnerabilities to attack the Tesla vehicle. Their new exploit was termed TBONE. 


Method

The Tesla uses ConnMan in their network. The researchers focused on this point for their attack. To design portions of the attack, the researchers used a ConnMan emulation tool, KunnaEmu. With this, they did not require access and use of Tesla at all times when testing. What makes this a bit different and interesting is the configuration. 


ConnMan is used to manage the network connections. The attack itself combined a stack buffer overflow when processing DNS requests vulnerability (CVE-2021-26675) with a loophole in the DHCP stack (CVE-2021-26676). 


For the attack hardware, the equipment is easy to source. All the attacker needs is a Wi Fi dongle and a drone. Nothing too complicated. There is also no user interaction required. The complete attack can be done in three minutes. Once done, the attacker can, among other things, inject malicious code. 


Result 

Once exploited, the attacker can do most things a driver can, except start the vehicle. This includes unlocking the doors, unlocking the trunk, changing seat positions, changing steering modes, and changing acceleration modes. This allows full access to the vehicle. This isn’t a thought experiment. The researchers had a full recording of the attack, which they played during the presentation. 


On a tangent, they could have weaponized this. The vehicle could have uploaded the malware, and be used as an access point to infect other Teslas. This is a big deal since this could compromise any Tesla Model X that has not received the patch, even the parked ones. What makes it worse is the system is used by other OEMs who may not have patched this yet. 


Responsible Disclosure 

The vulnerability and attack weren’t sprung on the interested parties a week prior to the conference. They did inform Intel, who created ConnMan. The vulnerability was remediated with FOTA update 2020.44 by Tesla in late October 2020. 




Resources 

https://www.forbes.com/sites/thomasbrewster/2021/04/29/watch-a-tesla-have-its-doors-hacked-open-by-a-drone/?sh=d6f4c271a2bd 


https://flipboard.com/@HotCars2020/aerial-attack-cybersecurity-researchers-managed-to-hack-tesla-with-a-drone/a-li8iYV-aTQC9yfvTZ3ivig%3Aa%3A3466759924-982d88ebd6%2Fhotcars.com 


https://securityaffairs.co/wordpress/117441/hacking/tesla-model-x-hacking.html?utm_source=rss&utm_medium=rss&utm_campaign=tesla-model-x-hacking 


https://www.autoevolution.com/news/hackers-break-into-tesla-using-a-drone-flying-over-the-car-160447.html 


https://www.deskvip.com/a-tesla-car-has-its-doors-hacked-open-by-a-drone 


https://www.torquenews.com/1/tesla-hacked-drone-company-informed-and-fixed-loophole 


https://www.hackread.com/tesla-cars-remotely-hacked-with-drone/ 


https://dronedj.com/2021/04/30/german-pilots-film-their-drone-hack-of-a-tesla/ 


https://www.hotcars.com/aerial-attack-cybersecurity-researchers-managed-to-hack-tesla-with-a-drone/ 


https://kunnamon.io/tbone/