Showing posts with label vehicle cybersecurity. Show all posts
Showing posts with label vehicle cybersecurity. Show all posts

Tuesday, January 9, 2024

Diversity of Data

 

I’ve said many times data is the new gold. This may be used/sold many times and cut for the purchaser’s needs. Another aspect which makes this attractive to attackers is diversity. If a company has more than one type of data, there are more targets of different types which could be liberated from the company and sold or ransomed. For example, they may be industrial data with schematics and product design. This would certainly be a crown jewel to seek. Couple this data warehouse with another data set (e.g., consumer data) and there are more targets.

This is notable as Nissan Motor Corporation and Nissan Financial Services in Australia and New Zealand experienced a breach. This was confirmed on December 22, 2023. In this case, the company is assessing the extent of the breach. What is known however is an estimated 100GB of data were stolen by the infamous Akira ransomware group.

While this is troubling, there are lessons to learn from this to assist others in not making the same oversight. With each set of data, a security check should be done. The data could be held in different locations or platforms. Each of these should be reviewed for vulnerabilities. The greater likelihood is these are not co-located and may present unique vulnerabilities on their own.

Thank you.


Services 

Enterprise and Embedded System Cybersecurity Engineering & Architecture

Red Team Pentesting | HW & SW BoMs | CBoM | 

Vulnerability Management | Tabletop Exercises (TTX) | 

Embedded Systems Architecture | Threat Intelligence | 

TARA (Threat Assessment and Remediation Analysis) 


Disabled Veteran Owned and Operated 

 


Tuesday, June 29, 2021

Tesla; still targeted

 

Over the years since that fateful day in 2015, there have been many people who have made their name with vehicle hacks. The attacks can be mundane or affect critical systems. Disabling the A/C is by far different than the engine or braking system.

Any vehicle system will have vulnerabilities. The researcher just must find them. One auto manufacturer targeted in the last approximately three years has been Tesla. The vulnerabilities found have required physical access and others have not. In this instance, the vulnerability was found by a Canadian software developer from Quebec (Shankar Gomare). Normally the vulnerabilities are found by cybersecurity researchers. In this case, he was working on his “Voice for Tesla” iOS app early in 2021 and noted the significant vulnerability with Tesla’s Bluetooth key technology. The developer’s app functions much like Amazon’s Alexa providing reminders via voice. The difference with this is the application would not require a specific word or phrase, as Alexa does.

Through developing the application, the developer noted Tesla uses two different forms of Bluetooth sensors in the vehicle. These are Bluetooth Basic Rate/Enhanced Data Rate (BR/EDR). This is used generally for streaming music. The other is Bluetooth Low Energy (BLE). The phone key uses this method. You would use this as a convenience as this use allows the keyholder to unlock the vehicle by being proximate to the vehicle with the connected mobile device (e.g., phone).

As you can figure, the exploit involves Bluetooth. The vehicle’s sensors are coded to detect the strongest Bluetooth signal for connected devices within its range prior to the execute unlock function. This occurs generally with the owner’s mobile device. Here is the issue. The researcher noted the BLE connection did not require authentication to connect to the vehicle. This ends up allowing the researcher to unlock any Tesla by acting as the phone key by forcing the vehicle the request the key from the actual mobile device-by pulling on the door handle.

For this to work, the actual owner’s mobile device would still need to be within 200m-400m for the BLE range. This may seem a bit risky if the owner were walking to their vehicle at the end of the day and saw the person. Where this would work much better would be if the Tesla were parked in the driveway in the evening. Yes, this was patched with an over-the-air (OTA) update.

This is another example of the importance of allowing legitimate cybersecurity researchers to act. The researcher conducted himself appropriately and worked with Tesla for a responsible disclosure. Think through what could have happened if the bad actor had this method and went another route.

Tuesday, May 4, 2021

Interesting new Tesla Hack!

 This is from the “What will they think of next” file. Imagine you have just purchased your dream car-the Tesla Model X. You drive it home, with the windows down and the music on. Life is good. You park in the driveway and start to walk up to your house with a smile on your face. Just before you unlock the door, you look back at your new purchase. There’s an annoying drone nearby. Your new pride and joy starts acting odd, especially since you are not in the vehicle. The doors begin to open together, then one at a time. The trunk opens and closes rhythmically with the doors. 


As odd as this sounds, this is possible and has been done. Researchers presented this work at the CanSecWest conference (virtual) on April 29, 2021. The researchers used two vulnerabilities to attack the Tesla vehicle. Their new exploit was termed TBONE. 


Method

The Tesla uses ConnMan in their network. The researchers focused on this point for their attack. To design portions of the attack, the researchers used a ConnMan emulation tool, KunnaEmu. With this, they did not require access and use of Tesla at all times when testing. What makes this a bit different and interesting is the configuration. 


ConnMan is used to manage the network connections. The attack itself combined a stack buffer overflow when processing DNS requests vulnerability (CVE-2021-26675) with a loophole in the DHCP stack (CVE-2021-26676). 


For the attack hardware, the equipment is easy to source. All the attacker needs is a Wi Fi dongle and a drone. Nothing too complicated. There is also no user interaction required. The complete attack can be done in three minutes. Once done, the attacker can, among other things, inject malicious code. 


Result 

Once exploited, the attacker can do most things a driver can, except start the vehicle. This includes unlocking the doors, unlocking the trunk, changing seat positions, changing steering modes, and changing acceleration modes. This allows full access to the vehicle. This isn’t a thought experiment. The researchers had a full recording of the attack, which they played during the presentation. 


On a tangent, they could have weaponized this. The vehicle could have uploaded the malware, and be used as an access point to infect other Teslas. This is a big deal since this could compromise any Tesla Model X that has not received the patch, even the parked ones. What makes it worse is the system is used by other OEMs who may not have patched this yet. 


Responsible Disclosure 

The vulnerability and attack weren’t sprung on the interested parties a week prior to the conference. They did inform Intel, who created ConnMan. The vulnerability was remediated with FOTA update 2020.44 by Tesla in late October 2020. 




Resources 

https://www.forbes.com/sites/thomasbrewster/2021/04/29/watch-a-tesla-have-its-doors-hacked-open-by-a-drone/?sh=d6f4c271a2bd 


https://flipboard.com/@HotCars2020/aerial-attack-cybersecurity-researchers-managed-to-hack-tesla-with-a-drone/a-li8iYV-aTQC9yfvTZ3ivig%3Aa%3A3466759924-982d88ebd6%2Fhotcars.com 


https://securityaffairs.co/wordpress/117441/hacking/tesla-model-x-hacking.html?utm_source=rss&utm_medium=rss&utm_campaign=tesla-model-x-hacking 


https://www.autoevolution.com/news/hackers-break-into-tesla-using-a-drone-flying-over-the-car-160447.html 


https://www.deskvip.com/a-tesla-car-has-its-doors-hacked-open-by-a-drone 


https://www.torquenews.com/1/tesla-hacked-drone-company-informed-and-fixed-loophole 


https://www.hackread.com/tesla-cars-remotely-hacked-with-drone/ 


https://dronedj.com/2021/04/30/german-pilots-film-their-drone-hack-of-a-tesla/ 


https://www.hotcars.com/aerial-attack-cybersecurity-researchers-managed-to-hack-tesla-with-a-drone/ 


https://kunnamon.io/tbone/ 


Friday, October 12, 2018

Another key fob attack!

Vehicles are synonymous with the US culture. These are pervasive through commercials, print ads, radio, the vast number of vehicles on the road, and various other sources. As these continue to grow in technology being implemented and autonomy, these become more of a target for attack and research. Vehicle and embedded systems cybersecurity is a growing field to complete research in based on this. One relevant, significant attack and the researchers have their 15 minutes of fame, and hopefully a bug bounty for their efforts.

Recently another vulnerability was detected with a Tesla vehicle. The researchers were students at the University of Leuven in Belgium. The researchers were working at the Belgium Uni’s Computer Security and Industrial Cryptography (COSIC) research group. In particular, the researchers focussed on the Passive Keyless Entry and Start (PKES) system used int eh Tesla model S, McLaren vehicles, and others.

Target/Affected Vehicles
The PKES is a common feature in vehicles. Although in nearly all vehicles in current production, the two primary vehicles affected are the Tesla and McLaren, and any other vehicle using the Pektron PKES system. Two other vehicle manufacturers using this are Karma and Triumph.

Method
With a simple tool, the researchers were able to steal a vehicle within a few seconds. In short, this operates to clone the key fob signal.

As noted, the key fob system is manufactured by Pektron. COSIC analyzed the key fob communication and designed a Trade-Off (TMTO) attack. As this was successful, the researchers were able to gain access to the internal area of the vehicle.

With this type of vehicle, seemingly the tools required for this would be rather expensive and complex. To the contrary, the equipment used for the attack tools included a Raspberry Pi 3 Model B+, a smartphone hotspot, Proxmark 3, yard Stick One, and USB battery pack. The cell phone hot spot was needed to access the 6TB drive containing the TMTO table. This equipment is not costly or expensive. The Raspberry Pi 3 Model B+ was $35, Yard Stick One ($100), Proxmark 3 RDV4 kit $300. The USB battery pack would vary greatly in price. Thus the researchers spent approximately $435 to access a $77k (starting price) vehicle.

The security issue which allowed this access was an exceptionally weak cipher for the encryption. The 40-bit cipher was used, which allowed this quick compromise, due to the fob’s limited processing power. 

The traffic was sniffed from the car radio transmitter to the fob and back. This signal is transmitted continuously. Once the researchers captured two responses, they used the 6TB table of the pre-computed keys. The process to crack this was merely a few seconds.

Remediation
Naturally, this is a rather serious issue. The attack process leads to a significant compromise and entry to the vehicle. For Tesla remediating the issue consisted of a software update requiring the user to input a PIN to enable the vehicle to be driven. McLaren, on the other hand, took a physical route. McLaren mailed a pouch to put the key fob in. This acts as a Faraday pouch for the user to block the signal from reaching as far as it had been.

Responsible Researchers
The COSIC disclosed the vulnerabilities to Tesla in August 2017, giving them time to fix the issue. Tesla did acknowledge the issue, the researchers were thanked and paid $10k for the bug bounty. To be fair, the researchers also contacted Pektron, the company which manufactured the PKES system. The other known vehicle manufacturers (McLaren, Karma, and Triumph) were also contacted.

To further the research, the attack was repeated during a live demonstration in April 2018, and presented the findings at the Cryptographic Hardware and Embedded Systems (CHES) 2018 Conference in Amsterdam on September 10th.


Resources
Allen, L. (2018, September 10). Security flaws in tesla and mclaren keyless entry found. Retrieved from https://www.autocar.co.uk/car-news/new-cars/security-flaws-tesla-and-mclaren-keyless-entry-found

Beckwith, J. (2018, August 29). Tesla introduces ‘PIN to Drive’ security feature. Retrieved from https://www.autocar.co.uk/car-news/new-cars/tesla-introduces-pin-drive-security-feature

Field, K. (2018, August 6). Tesla files FCC application for bluetooth key fobs for tesla model 3 owners. Retrieved from https://cleantechnica.com/2018/08/06/tesla-rolling-out-bluetooth-key-fobs-fortesla-model-3-owners/

Greenberg, A. (2018, September 10). Hackers can steal a tesla model s in seconds by cloning its key fob. Retrieved from https://www.wired.com/story/hackers-steal-tesla-model-s-seconds-key-fob/

Jones, R. (2018, September). Researchers show off method for hacking tesla’s keyless entry, so turn on two factor authentication. Retrieved from https://gizmodo.com/researchers-show-off-method-for-hacking-tesla-s-keyless-1828951056

Lambert, F. (2018, August 7). Tesla is working on a new key fob-potentially for keyless model 3. Retrieved from https://electrek.co/2018/08/07/tesla-new-key-fob-model-3/

Mahoney, J. (2018, September 12). Hackers discover security flaw with teslas and mclarens. Retrieved from https://www.motoring.com.au/hackers-discover-security-flow-with-teslas-and-mclarens-114580/

Malone, W. (2018, August 7). Potential model 3 fob: Tesla registers new BLE fob with FCC. Retrieved from https://insideevs.com/potential-model-3-fob-tesla-registers-new-ble-fob-with-FCC/

Morse, J. (2018, September 10). Your tesla is probably vulnerable to hackers, but there’s an easy fix. Retrieved from https://mashable.com/article/tesla-model-3-hack-key-fob/#VJLA4Bg8uaq0

Mott, N. (2018, September 11). Tesla’s keyless entry duped by cloned fobs. Retrieved from https://www.tomshardware.com/news/security-flaws-tesla-wireless-key-systems,37779.html

Sachdeva, A. (2018, September 11). Tesla model s can be hacked in seconds with this raspberry pi-powered equipment. Retrieved from https://fossbytes.com/tesla-model-s-keyfob-hacked-equipment/ 

Saturday, September 22, 2018

Vehicle Cybersecurity Positions are Difficult to Fill


Vehicle Cybersecurity Professionals-Still a Difficult Position to Fill
Charles Parker, II
>_

In the metro-Detroit area, the primary industry and revenue force is the auto industry. This is clearly due to the number and concentration of the vehicle manufacturer headquarters, assembly plants, and admin offices. As these vehicles are designed and engineered, they require cybersecurity testing. This ensures as much as possible the vehicles are safe and secure for being successfully attacks. Cybersecurity for the presently connected vehicles and future autonomous vehicles is paramount. Without this in place and the vehicles being active, directly tested, any vehicle on the road would not be safe itself or from other vehicles which could be hijacked.

To accomplish this vast task, the vehicle manufacturers require qualified people to complete the testing. This does not appear to be a significant issue. There are jobs to fill in a technology area creating a demand for years, and there should be people to fill the open positions. Unfortunately, this is not remotely the case. This is occurring presently in the field for many reasons. The primary reason for this is the available persons with this skill are limited. The persons with the skill and experience to test the cybersecurity of embedded, equipment is rather narrow. Of this narrow field, the applicants need to be vetted not only for their technological prowess but also for their ethics, as there are bad apples present who would not morally do the right thing 100% of the time. Based on this need/demand is far outpacing the demand. This is further exacerbated due to this need being across several industries, not only auto manufacturers.

As an option, the manufacturer may reach out to third parties to complete a portion of the testing. The manufacturer may also incorporate a bug bounty program into their process. Programs like this would pay the cybersecurity persons when they would find a bug in their product. By using a program as such there are a great number of persons reviewing the product and are paid for their time if a bug is found. GM and FCA’s Bug Bounty programs are well known.

There are a limited number of universities and colleges attempting to train persons for this vast need. There are also contests in which high school and college students may apply to be in to learn the basics. This will assist with increasing the pipeline for the cybersecurity talent.