News: 1673082084

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Here's how to remotely takeover a Ferrari...account, that is

(2023/01/07)


Multiple bugs affecting millions of vehicles from almost all major car brands could allow miscreants to perform any manner of mischief — in some cases including full takeovers — by exploiting vulnerabilities in the vehicles' telematic systems, automotive APIs and supporting infrastructure, according to security researchers.

Specifically, the vulnerabilities affect Mercedes-Benz, BMW, Rolls Royce, Ferrari, Ford, Porsche, Toyota, Jaguar and Land Rover, plus fleet management company Spireon and digital license plate company Reviver.

The research builds on Yuga Labs' Sam Curry's earlier car hacking expeditions that uncovered flaws affecting [1]Hyundai and Genesis vehicles , as well as Hondas, Nissans, Infinitis and Acuras via an authorization flaw in [2]Sirius XM's Connected Vehicle Services .

[3]

All of the bugs have since been fixed.

[4]

[5]

"The affected companies all fixed the issues within one or two days of reporting," Curry told The Register . " We worked with all of them to validate them and make sure there weren't any bypasses."

The most serious bugs, at least from a public safety perspective, were found in Spireon, which owns several GPS vehicle tracking and fleet management brands including OnStar, GoldStar, LoJack, FleetLocate, and NSpire spanning 15 million connected vehicles.

[6]

Spireon, it turns out, would have been a treasure trove for miscreants. Curry and the team discovered multiple vulnerabilities in SQL injection and authorization bypass to perform remote code execution across all of Spireon and fully take over any fleet vehicle.

"This would've allowed us to track and shut off starters for police, ambulances, and law enforcement vehicles for a number of different large cities and dispatch commands to those vehicles," the researchers [7]wrote .

The bugs also gave them full administrator access to Spireon and a company-wide administration panel from which an attacker could send arbitrary commands to all 15 million vehicles, thus remotely unlocking doors, honking horns, starting engines and disabling starters.

[8]

"Our cybersecurity professionals met with the security researcher to discuss and evaluate the purported system vulnerabilities and immediately implemented remedial measures to the extent required," a Spireon spokesperson told The Register . "We also took proactive steps to further strengthen the security across our product portfolio as part of our continuing commitment to our customers as a leading provider of aftermarket telematics solutions."

"Spireon takes all security matters seriously and utilizes an extensive industry leading toolset to monitor and scan its products and services for both known and novel potential security risks," the spokesperson added.

Ferrari, BMW and Rolls Royce

Moving on to many petrol-head's dream car: Ferrari.

With Ferrari, the researchers found overly permissive access controls that allowed them to access JavaScript code for several internal applications. The code contained API keys and credentials that could have allowed attackers to access customer records and takeover (or delete) customer accounts.

"Additionally, an attacker could POST to the "/core/api/v1/Users/:id/Roles" endpoint to edit their user roles, setting themselves to have super-user permissions or become a Ferrari owner," the researchers said.

The lack of access controls also could have allowed miscreants to create and delete employee "back office" admin user accounts, and then modify Ferrari-owned websites including its CMS system.

Meanwhile, a misconfigured single-sign on (SSO) portal for all employees and contractors of BMW, which owns Rolls-Royce, would have allowed access to any application behind the portal.

So, for example, an attacker could access an internal dealer portal, query a VIN number and then retrieve all of the sales documents associated with the vehicle.

Neither Ferrari nor BMW responded to The Register 's requests for comment.

What not to say to a bug hunter

Similarly, a misconfigured SSO for Mercedes-Benz allowed the researchers to create a user account on a website intended for vehicle repair shops to request specific tools. They then used this account to sign in to the Mercedes-Benz Github, which held internal documentation and source code for various Mercedes-Benz projects including its Me Connect app used by customers to remotely connect to their vehicles.

The researchers reported this vulnerability to the automaker, and they noted that Mercedes-Benz "seemed to misunderstand the impact" and wanted further details about why this was a problem.

So the team used their newly created account credentials to login to several applications containing sensitive data. Then they "achieved remote code execution via exposed actuators, spring boot consoles, and dozens of sensitive internal applications used by Mercedes-Benz employees."

One of these was the carmaker's version of Slack. "We had permission to join any channel, including security channels, and could pose as a Mercedes-Benz employee who could ask whatever questions necessary for an actual attacker to elevate their privileges across the Benz infrastructure," the researchers explained.

A Mercedes-Benz spokesperson confirmed that Curry contacted the company about the vulnerability and that it had been fixed.

"The security of our organization, products and services is one of our top priorities," the spokesperson said, adding that "the identified vulnerability did not affect the security of our vehicles."

[9]Sirius XM flaw unlocks so-called smart cars thanks to code flaw

[10]Cops swoop after crooks use wireless keyfob hack to steal cars

[11]Hackers remotely start, unlock Honda Civics with $300 tech

[12]Japanese giants to offer security-as-a-service for connected cars

Curry and friends also discovered vulnerabilities affecting Porsche's telematics service that allowed them to remotely retrieve vehicle location and send vehicle commands.

Plus, they found an access-control vulnerability on the Toyota Financial app that disclosed the name, phone number, email address, and loan status of any customers. Toyota Motor Credit told The Register that it fixed the issue, and noted "this had no connection to Toyota vehicles or how they operate."

Additionally, a Porsche spokesperson told The Register "the safety and protection of the car software in our vehicles is always a top priority for Porsche."

"We permanently monitor our systems," the spokesperson said. "We take any indications of vulnerabilities very seriously. Our top priority is to prevent unauthorized access to the systems in our vehicles by third parties." ®

Get our [13]Tech Resources



[1] https://twitter.com/samwcyo/status/1597695281881296897?ref_src=twsrc%5Etfw%7Ctwcamp%5Etweetembed%7Ctwterm%5E1597695281881296897%7Ctwgr%5E7ffcb9ffe2f6f234cdb9dbb3d019b76c5eec10df%7Ctwcon%5Es1_&ref_url=https%3A%2F%2Fsamcurry.net%2Fweb-hackers-vs-the-auto-industry%2F

[2] https://www.theregister.com/2022/11/30/siriusxm_connected_cars_hacking/

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Y7lQzKcykDgCNYUUGwFzugAAAEQ&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Y7lQzKcykDgCNYUUGwFzugAAAEQ&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Y7lQzKcykDgCNYUUGwFzugAAAEQ&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[6] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Y7lQzKcykDgCNYUUGwFzugAAAEQ&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[7] https://samcurry.net/web-hackers-vs-the-auto-industry/

[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Y7lQzKcykDgCNYUUGwFzugAAAEQ&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[9] https://www.theregister.com/2022/11/30/siriusxm_connected_cars_hacking/

[10] https://www.theregister.com/2022/10/18/car_thieves_arrested_keyless_tech/

[11] https://www.theregister.com/2022/03/25/honda_civic_hack/

[12] https://www.theregister.com/2022/10/18/ntt_denso_security_for_cars/

[13] https://whitepapers.theregister.com/



Pure BS and security is really only a PR problem

Anonymous Coward

To me all of these 'security is top priority' -claims are pure bollocks: Security costs money and none of them spend money on actual security, which is proven when obvious total disregard of security goes into production systems.

Patching publicly known bugs is several decades cheaper, after someone else published them first. Bugs themselves has existed who know how many years and none of the companies could trace software development to the moment said bugs were created. Or didn't publish it because it's years or decades.

That tells how high the security actually is: A PR issue. No more, no less.

If it *really* was top priority, every software team would have one security expert who audits *every single row* of code they write. And company wide experts for infrastructure. and everything not related to their own software development.

I can bet none of companies mentioned has that kind of security: It costs money.

Re: Pure BS and security is really only a PR problem

simonlb

I've been saying for years that that there should be an inherently secure, fully audited, vendor agnostic, industry standard protocol for IoT devices to enforce security at every single point as far as practically possible.

Considering the vast majority of people buy (or lease) a car and then leave it outside for the entire period of time it's in their possession, it's obvious this requirement should also be extended to anything produced by the automotive industry.

Of course, when these two various industries eventually decide that's a good idea they won't all work together to do it, you'll get three 'alliances' of various companies working on their own 'better' version of a protocol and we'll end up with another royal VHS/Betamax/DVD/BluRay style battle of competing standards which will only be marginally beneficial until one of them is adopted as the industry standard.

Re: Pure BS and security is really only a PR problem

Lil Endian

Agreed.

I especially 'liked' this bit:

"Spireon takes all security matters seriously and utilizes an extensive industry leading toolset to monitor and scan its products and services for both known and novel potential security risks," the spokesperson added.

Yet that arrangement didn't detect ...multiple vulnerabilities in SQL injection and authorization bypass...

So, Spireon are either bullshitting (no toolset) or incompetent (dunno how to use the toolset). Or, their toolset supplier(s) bullshitted them.

All of you people should be ashamed of yourselves! MicroSoft is the reason
there are so many people in my IS department, and the reason half of us have
jobs. If Sun had won, we could probably get by with two people sleeping like
the Maytag man. But because of MS, there are eight people gainfully employed as
highly paid contracters, looking busy, feeding their kids. And the way it
looks, I stand to be employed and wealthy for a long, long time.

-- From Slashdot.org