Tencent research team scores free powerups for electric cars with Raspberry Pi-powered X-in-the-middle attack
(2021/05/11)
- Reference: 1620705866
- News link: https://www.theregister.co.uk/2021/05/11/black_hat_asia_car_hacking/
- Source link:
Black Hat Asia Researchers have used the Black Hat Asia conference to demonstrate the awesome power of the Raspberry Pi as a car-p0wning platform.
Chinese web giant Tencent's [1]Blade Team , a security research group, showed they could circumvent payment schemes used at electric vehicle charging stations. Their exploits also changed the charging voltage and current, an act that could damage the EV.
“The construction of charging stations is accelerating all over the world, but there is little research on the security of electric vehicle infrastructure,” said TenCent Blade Team senior security researcher Wu HuiYu.
[2]
[3]
[4]
HuiYu and fellow TenCent Blader, Li YuXiang, tried out the attack on five rented electric cars of different models through a security test tool called “XCharger” that captures, modifies, replays and fuzzes the data packets in the communication process between the charging pile and the electric vehicle. The XCharger uses a Raspberry Pi or STM 32 microcontroller and is inserted between the charging pile and electric vehicle.
Charging stations have largely moved toward automating payments. While some vehicle companies use their own authentication and communication protocols, others rely on the VIN number which is insecure because it is visible in plaintext - literally - through a vehicle's windshield.
To hack into these systems, the Tencent team used [5]CANtools , software that allows observation and interpretation of messages sent on the Controller Area Network (CAN bus) used to connect devices in cars. CANtools allowed the researchers to read messages generated during the charging process, and from there write their own messages, bypass authentication and avoid charges for charging.
[6]
The TenCent Blade team notified the vendors and the vulnerabilities have been addressed.
[7]Researchers say objects can hide from computer vision by seeking out unusual company that trips correlation bias
[8]'Incorrect software parameter' sends Formula E's Edoardo Mortara to hospital: Brakes' fail-safe system failed
[9]Tesla axes software engineer for allegedly pilfering secret Python scripts after just three days on the job
[10]K8s on a plane! US Air Force slaps Googly container tech on yet another war machine to 'run advanced ML algorithms'
In another presentation, Indian security consultancy Amynasec Labs intern and mechanical engineering student Kartheek Lade cracked a car and controlled it via the internet using messages sent over the Telegram messaging service.
Lade’s software tool [11]CANalyse analyses log files to find unique data sets. It can connect to a simple attacker interface like Telegram and can be installed inside a Raspberry Pi to exploit vehicles and control certain functions.
Lade demoed an attack in which he controlled some of a vehicle's functions with Telegram messages. The researcher said he could "brick" the car with commands sent in this way. He also warned others not to try his exploits without the necessary permission. ®
Get our [12]Tech Resources
[1] https://blade.tencent.com/en/
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YJpVv1Wnsq2LK-B9GXmzwQAAANc&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YJpVv1Wnsq2LK-B9GXmzwQAAANc&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YJpVv1Wnsq2LK-B9GXmzwQAAANc&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[5] https://github.com/eerimoq/cantools
[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YJpVv1Wnsq2LK-B9GXmzwQAAANc&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[7] http://www.theregister.com/2021/05/07/computer_vision_correlation_bias/
[8] http://www.theregister.com/2021/03/01/formula_e_bug/
[9] http://www.theregister.com/2021/01/24/tesla_sues_engineer/
[10] http://www.theregister.com/2020/10/08/usaf_u2_spyplane_kubernetes_britten_norman/
[11] https://github.com/KartheekLade/CANalyse
[12] https://whitepapers.theregister.com/
Chinese web giant Tencent's [1]Blade Team , a security research group, showed they could circumvent payment schemes used at electric vehicle charging stations. Their exploits also changed the charging voltage and current, an act that could damage the EV.
“The construction of charging stations is accelerating all over the world, but there is little research on the security of electric vehicle infrastructure,” said TenCent Blade Team senior security researcher Wu HuiYu.
[2]
[3]
[4]
HuiYu and fellow TenCent Blader, Li YuXiang, tried out the attack on five rented electric cars of different models through a security test tool called “XCharger” that captures, modifies, replays and fuzzes the data packets in the communication process between the charging pile and the electric vehicle. The XCharger uses a Raspberry Pi or STM 32 microcontroller and is inserted between the charging pile and electric vehicle.
Charging stations have largely moved toward automating payments. While some vehicle companies use their own authentication and communication protocols, others rely on the VIN number which is insecure because it is visible in plaintext - literally - through a vehicle's windshield.
To hack into these systems, the Tencent team used [5]CANtools , software that allows observation and interpretation of messages sent on the Controller Area Network (CAN bus) used to connect devices in cars. CANtools allowed the researchers to read messages generated during the charging process, and from there write their own messages, bypass authentication and avoid charges for charging.
[6]
The TenCent Blade team notified the vendors and the vulnerabilities have been addressed.
[7]Researchers say objects can hide from computer vision by seeking out unusual company that trips correlation bias
[8]'Incorrect software parameter' sends Formula E's Edoardo Mortara to hospital: Brakes' fail-safe system failed
[9]Tesla axes software engineer for allegedly pilfering secret Python scripts after just three days on the job
[10]K8s on a plane! US Air Force slaps Googly container tech on yet another war machine to 'run advanced ML algorithms'
In another presentation, Indian security consultancy Amynasec Labs intern and mechanical engineering student Kartheek Lade cracked a car and controlled it via the internet using messages sent over the Telegram messaging service.
Lade’s software tool [11]CANalyse analyses log files to find unique data sets. It can connect to a simple attacker interface like Telegram and can be installed inside a Raspberry Pi to exploit vehicles and control certain functions.
Lade demoed an attack in which he controlled some of a vehicle's functions with Telegram messages. The researcher said he could "brick" the car with commands sent in this way. He also warned others not to try his exploits without the necessary permission. ®
Get our [12]Tech Resources
[1] https://blade.tencent.com/en/
[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YJpVv1Wnsq2LK-B9GXmzwQAAANc&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0
[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YJpVv1Wnsq2LK-B9GXmzwQAAANc&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YJpVv1Wnsq2LK-B9GXmzwQAAANc&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0
[5] https://github.com/eerimoq/cantools
[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YJpVv1Wnsq2LK-B9GXmzwQAAANc&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0
[7] http://www.theregister.com/2021/05/07/computer_vision_correlation_bias/
[8] http://www.theregister.com/2021/03/01/formula_e_bug/
[9] http://www.theregister.com/2021/01/24/tesla_sues_engineer/
[10] http://www.theregister.com/2020/10/08/usaf_u2_spyplane_kubernetes_britten_norman/
[11] https://github.com/KartheekLade/CANalyse
[12] https://whitepapers.theregister.com/
Re: I love Asian names...
Hubert Cumberdale
The 1970s called...
Re: 1970s
Anonymous Coward
Ahh! Happier times...
Re: 1970s
Yet Another Hierachial Anonynmous Coward
When the sun never stopped shining, it never rained, we had proper snow in winter, electricity and petrol were so cheap they were not worth the hassle of billing, 3 TV channels was excessive, computers were the size of tennis courts. And you could make jokes without people being offended. Oh, and there was decent music on the radio to listen to, too
Yes, much happier times.
Re: 1970s
Red Ted
It was really only 2.5 channels on the TV, as BBC2 broadcast Open University lectures and the like during the day.
As for the music quality, your impression is coloured by Survivor Bias. I can find lots of examples of rubbish music from that decade!
I love Asian names...
Wu HuiYu, Sum Ting Wong, Bing Ding Pow, Mai Ding Ling, Sum Dum Gai, and all the other attrocious puns that are possible when you're insane. =-)p
Then there's my own pseudo Asian name: Sum Dum Fook! =-D
*Wanders off singing "I like Chinese" & practicing my patented Silly Walk*