Remotely Control Cars through a Pre-Installed Internet of Vehicle Device

No ratings

Presented at BSidesSpringfield 2017 by

As the rapid growth of Internet of Thing (IoT) in recent years, car makers have developed various technologies to fulfill the demand of connected cars. These Internet of Vehicle (IoV) devices are bringing better driving experiences to customers, but they are also bringing new security issues in the same time. In this research, we will discuss attacks on a pre-installed IoV device provided by a major car manufacture in all its new models. The device can provide customers various functions through a mobile app or the infotainment system in their cars. It can monitor driving behavior of customers and the status of their cars, as well as assistance to find parking lots, gas stations, roadsides assistance, and service centers. We will talk about the vulnerabilities of this system from different aspects, such as the mobile app, wireless communication protocol, firmware, hardware, and in-car network. First, we will discuss the vulnerabilities of the mobile app and how we exploit the Bluetooth communication and over-the-air update mechanism. Later on, we will talk about how we bypass the hardware protection to dump the firmware by identifying a backdoor through firmware analysis. After that, we will explain the checksum protection of firmware and the circumvent of it. Finally, we will demonstrate how to modify the firmware to exploit in-car network and achieve remotely car controlling, such as unlocking doors, lowering windows, and folding rear view mirrors. We will introduce the approaches and tools, such as logic analyzer, JLink, KDS and IDA Pro, used to analyze and discover these issues as well.