BMW ConnectedDrive flaws could be misused to tamper with car settings

Security researcher Benjamin Kunz Mejri has found two vulnerabilities in the BMW ConnectedDrive web portal/web application. About the vulnerabilities in BMW ConnectedDrive The first one is a client-side cross site scripting web vulnerability that could be exploited by a remote attacker without a privileged account to inject his own malicious script codes to the client-side of the affected module context. Minimal user interaction is needed for this attack to work. “Successful exploitation of the vulnerability … More Continue reading BMW ConnectedDrive flaws could be misused to tamper with car settings

Flaw Allows Attackers to Remotely Tamper with BMW’s In-Car Infotainment System

The Internet of things or connected devices are the next big concerns, as more Internet connectivity means more access points which mean more opportunities for hackers.

When it comes to the threat to Internet of Things, Car Hacking is a hot topic.

Si… Continue reading Flaw Allows Attackers to Remotely Tamper with BMW’s In-Car Infotainment System

Books You Should Read: The Car Hacker’s Handbook

I just had my car in for an inspection and an oil change. The garage I take my car to is generally okay, they’re more honest than a stealership, but they don’t cross all their t’s and dot all their lowercase j’s. A few days after I picked up my car, low and behold, I noticed the garage didn’t do a complete oil change. The oil life indicator wasn’t reset, which means every time I turn my car on, I’ll have to press a button to clear an ominous glowing warning on my dash.

For my car, resetting the oil …read more

Continue reading Books You Should Read: The Car Hacker’s Handbook

Mitsubishi Hybrid SUV Hack Puts Drivers At Risk, Says Researcher

Researchers discover a vulnerability in Mitsubishi’s Outlander Hybrid SUV that allows hackers to disable the anti-theft alarm from a laptop and control the car’s heat and AC. Continue reading Mitsubishi Hybrid SUV Hack Puts Drivers At Risk, Says Researcher

Mitsubishi Outlander Car’s Theft Alarm Hacked through Wi-Fi

From GPS system to satellite radio to wireless locks, today vehicles are more connected to networks than ever, and so they are more hackable than ever.

It is not new for security researchers to hack connected cars. Latest in the series of hackable con… Continue reading Mitsubishi Outlander Car’s Theft Alarm Hacked through Wi-Fi

Car Hackers Could Face Life In Prison. That’s Insane!

Yes, you heard it right.

You can now end up your whole life behind bars if you intentionally hack into a vehicle’s electronic system or exploit its internal flaws.

Car Hacking is a hot topic. Today, many automobiles companies are offering cars that r… Continue reading Car Hackers Could Face Life In Prison. That’s Insane!

Review: The Car Hacker’s Handbook

About the author Craig Smith runs Theia Labs, a research firm that focuses on security auditing and building hardware and software prototypes. He is also a founder of the Hive13 hackerspace and OpenGarages. He has worked for several auto manufacturers, where he provided public research on vehicle security and tools. Inside The Car Hacker’s Handbook Car hacking and the insecurity of modern, computerized, connected cars has been a topic of much interest in the last … More Continue reading Review: The Car Hacker’s Handbook

Cheap radio attack can be used to unlock and steal 24 car models

A group of researchers from ADAC, the largest automobile club in Germany and Europe, have demonstrated how the keyless “comfort locking” system used by most automakers on most modern cars provides no security against vehicle theft. This finding, in itself, is not new, as previous research demonstrated how easy is to fool the system into unlocking the car and starting its engine by relaying messages between the car and the smart key, at a considerable … More Continue reading Cheap radio attack can be used to unlock and steal 24 car models