SlideShare ist ein Scribd-Unternehmen logo
1© 2016 IXIA AND/OR ITS AFFILIATES. ALL RIGHTS RESERVED. |
Smart car forensics &
vehicle weaponization
Gabriel Cirlig – Software Engineer
Stefan Tanase – Security Researcher
2© 2016 IXIA AND/OR ITS AFFILIATES. ALL RIGHTS RESERVED. |
INGENIOUS! A ROMANIAN managed
to modify public transportation cards!
whoami
3© 2016 IXIA AND/OR ITS AFFILIATES. ALL RIGHTS RESERVED. |
whoami2
4© 2016 IXIA AND/OR ITS AFFILIATES. ALL RIGHTS RESERVED. |
./shameless_plug.sh
@hookgab
@stefant
5© 2016 IXIA AND/OR ITS AFFILIATES. ALL RIGHTS RESERVED. |
6© 2016 IXIA AND/OR ITS AFFILIATES. ALL RIGHTS RESERVED. |
THE CONNECTED CAR
7© 2016 IXIA AND/OR ITS AFFILIATES. ALL RIGHTS RESERVED. |
THE MOTIVATION
8© 2016 IXIA AND/OR ITS AFFILIATES. ALL RIGHTS RESERVED. |
THE START
9© 2016 IXIA AND/OR ITS AFFILIATES. ALL RIGHTS RESERVED. |
THE TECH
• Freescale i.MX6 ARM Cortex-A9
• random *nix distribution
• GPS soldered on board
(even if you didn’t buy the nav package)
• 1GB RAM
• WIFI!!!1!1111
• revolutionary usb debugging ™
A lot of power for a car, eh?
10© 2016 IXIA AND/OR ITS AFFILIATES. ALL RIGHTS RESERVED. | 10© 2016 IXIA AND/OR ITS AFFILIATES. ALL RIGHTS RESERVED. |
Smart car forensics
11© 2016 IXIA AND/OR ITS AFFILIATES. ALL RIGHTS RESERVED. |
GETTING IN
• Abuse “autorun” script from USB
• disable iptables
• run SSHD for our platform
• …prophit!
• root/jci
• ez ‘till now
12© 2016 IXIA AND/OR ITS AFFILIATES. ALL RIGHTS RESERVED. |
WHAT WE FOUND
everything?
13© 2016 IXIA AND/OR ITS AFFILIATES. ALL RIGHTS RESERVED. |
EXTRA
• voice profiles
• vehicle status
• directory listings for your phone (wtf, the car is crawling me)
14© 2016 IXIA AND/OR ITS AFFILIATES. ALL RIGHTS RESERVED. |
AUTO INDUSTRY IN A NUTSHELL
15© 2016 IXIA AND/OR ITS AFFILIATES. ALL RIGHTS RESERVED. |
AUTO INDUSTRY IN A NUTSHELL
16© 2016 IXIA AND/OR ITS AFFILIATES. ALL RIGHTS RESERVED. | 16© 2016 IXIA AND/OR ITS AFFILIATES. ALL RIGHTS RESERVED. |
Vehicle weaponization
17© 2016 IXIA AND/OR ITS AFFILIATES. ALL RIGHTS RESERVED. |
WHAT WE CAN EXPLOIT
• deployed via the same script that granted ssh access
• uses cron to keep itself alive
• constantly looks for open wifis
• constantly logs GPS coordinates
• whenever we connect, upload new data
• WARDRIVING WITHOUT A LAPTOP!
18© 2016 IXIA AND/OR ITS AFFILIATES. ALL RIGHTS RESERVED. |
GIVING IT SOME LOVE
19© 2016 IXIA AND/OR ITS AFFILIATES. ALL RIGHTS RESERVED. |
LIVE DEMO
20© 2016 IXIA AND/OR ITS AFFILIATES. ALL RIGHTS RESERVED. |
https://www.youtube.com/watch?v=q0CjVHlEJuQ&feature=em-upload_owner
21© 2016 IXIA AND/OR ITS AFFILIATES. ALL RIGHTS RESERVED. |
SMART CAR RANSOMWARE
22© 2016 IXIA AND/OR ITS AFFILIATES. ALL RIGHTS RESERVED. |
THE FUTURE
23© 2016 IXIA AND/OR ITS AFFILIATES. ALL RIGHTS RESERVED. |
THE FUTURE
24© 2016 IXIA AND/OR ITS AFFILIATES. ALL RIGHTS RESERVED. |
THE FUTURE
25© 2016 IXIA AND/OR ITS AFFILIATES. ALL RIGHTS RESERVED. |
THE FUTURE
26© 2016 IXIA AND/OR ITS AFFILIATES. ALL RIGHTS RESERVED. |
THE FUTURE
27© 2016 IXIA AND/OR ITS AFFILIATES. ALL RIGHTS RESERVED. |
THE FUTURE
28© 2016 IXIA AND/OR ITS AFFILIATES. ALL RIGHTS RESERVED. |
Our privacy is threatened
Travelers always rent cars, car sharing programs
are becoming popular in big cities, shared corporate car fleets
Evolution of technology – a double edged sword
We *want* smartphones, tablets, smart watches,
smart cars, self driving cars, internet of things etc.
EURONCAP for automotive cybersecurity
We already have crash-tests for physical safety. Seatbelts and airbags are
mandatory. Why is the industry ignoring cybersecurity?
CONCLUSIONS
29© 2016 IXIA AND/OR ITS AFFILIATES. ALL RIGHTS RESERVED. |
THE AFTERMATH
30© 2016 IXIA AND/OR ITS AFFILIATES. ALL RIGHTS RESERVED. |
Follow us on Twitter!
@hookgab
@stefant

Weitere ähnliche Inhalte

Ähnlich wie Gabrial Cirlig & Stefan Tanase - Smart Car Forensics and Vehicle Weaponization

Codemotion Warsaw 2016
Codemotion Warsaw 2016Codemotion Warsaw 2016
Codemotion Warsaw 2016Karina Popova
 
Official Devoxx 2016 e-health
Official Devoxx 2016 e-healthOfficial Devoxx 2016 e-health
Official Devoxx 2016 e-healthKarina Popova
 
Expert Insight on Implementing New Service Channels
Expert Insight on Implementing New Service ChannelsExpert Insight on Implementing New Service Channels
Expert Insight on Implementing New Service ChannelsErica Marois
 
Mesh the Gears: Mastering the Economics of Digital Leverage
Mesh the Gears: Mastering the Economics of Digital LeverageMesh the Gears: Mastering the Economics of Digital Leverage
Mesh the Gears: Mastering the Economics of Digital LeverageApigee | Google Cloud
 
Hello Watch! Build your First Apple Watch App
Hello Watch! Build your First Apple Watch AppHello Watch! Build your First Apple Watch App
Hello Watch! Build your First Apple Watch AppKristina Fox
 
Lean and Mean – Authorization for kick-ass APIs (Jonas Markström)
Lean and Mean – Authorization for kick-ass APIs (Jonas Markström)Lean and Mean – Authorization for kick-ass APIs (Jonas Markström)
Lean and Mean – Authorization for kick-ass APIs (Jonas Markström)Nordic APIs
 
Genivi paris open source summit 2016 intro
Genivi paris open source summit 2016 introGenivi paris open source summit 2016 intro
Genivi paris open source summit 2016 introFabMob
 
Acquiaご紹介(クラウドファーストとオープンソースで進めるデジタル変革)[動画あり]
Acquiaご紹介(クラウドファーストとオープンソースで進めるデジタル変革)[動画あり]Acquiaご紹介(クラウドファーストとオープンソースで進めるデジタル変革)[動画あり]
Acquiaご紹介(クラウドファーストとオープンソースで進めるデジタル変革)[動画あり]CI&T Japan
 
Getting smart about identity management in air transport - Renaud Irminger, D...
Getting smart about identity management in air transport - Renaud Irminger, D...Getting smart about identity management in air transport - Renaud Irminger, D...
Getting smart about identity management in air transport - Renaud Irminger, D...SITA
 
How to Deliver a More Seamless Customer Experience
How to Deliver a More Seamless Customer Experience How to Deliver a More Seamless Customer Experience
How to Deliver a More Seamless Customer Experience Erica Marois
 
Microservices: The Building Blocks for a Digital Future
Microservices: The Building Blocks for a Digital FutureMicroservices: The Building Blocks for a Digital Future
Microservices: The Building Blocks for a Digital FutureSAP Customer Experience
 
Hal Yang Diharapkan Pelanggan Pada Brand Anda
Hal Yang Diharapkan Pelanggan Pada Brand AndaHal Yang Diharapkan Pelanggan Pada Brand Anda
Hal Yang Diharapkan Pelanggan Pada Brand Anda8COMMERCE
 
NYC Identity Summit Business Day: Identity is the Center of Everything (Mike ...
NYC Identity Summit Business Day: Identity is the Center of Everything (Mike ...NYC Identity Summit Business Day: Identity is the Center of Everything (Mike ...
NYC Identity Summit Business Day: Identity is the Center of Everything (Mike ...ForgeRock
 
How the Dutch Police became “Chatbot” interactive
How the Dutch Police became “Chatbot” interactiveHow the Dutch Police became “Chatbot” interactive
How the Dutch Police became “Chatbot” interactiveSoham Dasgupta
 
Talent Acquisition Technology Trifecta: Where Recruitment Marketing Fits
Talent Acquisition Technology Trifecta: Where Recruitment Marketing FitsTalent Acquisition Technology Trifecta: Where Recruitment Marketing Fits
Talent Acquisition Technology Trifecta: Where Recruitment Marketing FitsSmashFly Technologies
 
[CB16] Background Story of "Operation neutralizing banking malware" and highl...
[CB16] Background Story of "Operation neutralizing banking malware" and highl...[CB16] Background Story of "Operation neutralizing banking malware" and highl...
[CB16] Background Story of "Operation neutralizing banking malware" and highl...CODE BLUE
 
World Rail Festival 2017 - Preparing for today, tomorrow and the day after by...
World Rail Festival 2017 - Preparing for today, tomorrow and the day after by...World Rail Festival 2017 - Preparing for today, tomorrow and the day after by...
World Rail Festival 2017 - Preparing for today, tomorrow and the day after by...Amadeus Rail
 
The Revolution to Stay Relevant in Travel
The Revolution to Stay Relevant in TravelThe Revolution to Stay Relevant in Travel
The Revolution to Stay Relevant in TravelSabre Corporation
 
SIM based connectivity solution for IoT
SIM based connectivity solution for IoTSIM based connectivity solution for IoT
SIM based connectivity solution for IoTKarina Popova
 
Edge 2016 barbarians at the gateway
Edge 2016 barbarians at the gatewayEdge 2016 barbarians at the gateway
Edge 2016 barbarians at the gatewayakamaidevrel
 

Ähnlich wie Gabrial Cirlig & Stefan Tanase - Smart Car Forensics and Vehicle Weaponization (20)

Codemotion Warsaw 2016
Codemotion Warsaw 2016Codemotion Warsaw 2016
Codemotion Warsaw 2016
 
Official Devoxx 2016 e-health
Official Devoxx 2016 e-healthOfficial Devoxx 2016 e-health
Official Devoxx 2016 e-health
 
Expert Insight on Implementing New Service Channels
Expert Insight on Implementing New Service ChannelsExpert Insight on Implementing New Service Channels
Expert Insight on Implementing New Service Channels
 
Mesh the Gears: Mastering the Economics of Digital Leverage
Mesh the Gears: Mastering the Economics of Digital LeverageMesh the Gears: Mastering the Economics of Digital Leverage
Mesh the Gears: Mastering the Economics of Digital Leverage
 
Hello Watch! Build your First Apple Watch App
Hello Watch! Build your First Apple Watch AppHello Watch! Build your First Apple Watch App
Hello Watch! Build your First Apple Watch App
 
Lean and Mean – Authorization for kick-ass APIs (Jonas Markström)
Lean and Mean – Authorization for kick-ass APIs (Jonas Markström)Lean and Mean – Authorization for kick-ass APIs (Jonas Markström)
Lean and Mean – Authorization for kick-ass APIs (Jonas Markström)
 
Genivi paris open source summit 2016 intro
Genivi paris open source summit 2016 introGenivi paris open source summit 2016 intro
Genivi paris open source summit 2016 intro
 
Acquiaご紹介(クラウドファーストとオープンソースで進めるデジタル変革)[動画あり]
Acquiaご紹介(クラウドファーストとオープンソースで進めるデジタル変革)[動画あり]Acquiaご紹介(クラウドファーストとオープンソースで進めるデジタル変革)[動画あり]
Acquiaご紹介(クラウドファーストとオープンソースで進めるデジタル変革)[動画あり]
 
Getting smart about identity management in air transport - Renaud Irminger, D...
Getting smart about identity management in air transport - Renaud Irminger, D...Getting smart about identity management in air transport - Renaud Irminger, D...
Getting smart about identity management in air transport - Renaud Irminger, D...
 
How to Deliver a More Seamless Customer Experience
How to Deliver a More Seamless Customer Experience How to Deliver a More Seamless Customer Experience
How to Deliver a More Seamless Customer Experience
 
Microservices: The Building Blocks for a Digital Future
Microservices: The Building Blocks for a Digital FutureMicroservices: The Building Blocks for a Digital Future
Microservices: The Building Blocks for a Digital Future
 
Hal Yang Diharapkan Pelanggan Pada Brand Anda
Hal Yang Diharapkan Pelanggan Pada Brand AndaHal Yang Diharapkan Pelanggan Pada Brand Anda
Hal Yang Diharapkan Pelanggan Pada Brand Anda
 
NYC Identity Summit Business Day: Identity is the Center of Everything (Mike ...
NYC Identity Summit Business Day: Identity is the Center of Everything (Mike ...NYC Identity Summit Business Day: Identity is the Center of Everything (Mike ...
NYC Identity Summit Business Day: Identity is the Center of Everything (Mike ...
 
How the Dutch Police became “Chatbot” interactive
How the Dutch Police became “Chatbot” interactiveHow the Dutch Police became “Chatbot” interactive
How the Dutch Police became “Chatbot” interactive
 
Talent Acquisition Technology Trifecta: Where Recruitment Marketing Fits
Talent Acquisition Technology Trifecta: Where Recruitment Marketing FitsTalent Acquisition Technology Trifecta: Where Recruitment Marketing Fits
Talent Acquisition Technology Trifecta: Where Recruitment Marketing Fits
 
[CB16] Background Story of "Operation neutralizing banking malware" and highl...
[CB16] Background Story of "Operation neutralizing banking malware" and highl...[CB16] Background Story of "Operation neutralizing banking malware" and highl...
[CB16] Background Story of "Operation neutralizing banking malware" and highl...
 
World Rail Festival 2017 - Preparing for today, tomorrow and the day after by...
World Rail Festival 2017 - Preparing for today, tomorrow and the day after by...World Rail Festival 2017 - Preparing for today, tomorrow and the day after by...
World Rail Festival 2017 - Preparing for today, tomorrow and the day after by...
 
The Revolution to Stay Relevant in Travel
The Revolution to Stay Relevant in TravelThe Revolution to Stay Relevant in Travel
The Revolution to Stay Relevant in Travel
 
SIM based connectivity solution for IoT
SIM based connectivity solution for IoTSIM based connectivity solution for IoT
SIM based connectivity solution for IoT
 
Edge 2016 barbarians at the gateway
Edge 2016 barbarians at the gatewayEdge 2016 barbarians at the gateway
Edge 2016 barbarians at the gateway
 

Mehr von hacktivity

Zsombor Kovács - Cheaters for Everything from Minesweeper to Mobile Banking ...
Zsombor Kovács - 	Cheaters for Everything from Minesweeper to Mobile Banking ...Zsombor Kovács - 	Cheaters for Everything from Minesweeper to Mobile Banking ...
Zsombor Kovács - Cheaters for Everything from Minesweeper to Mobile Banking ...hacktivity
 
Vincent Ruijter - ~Securing~ Attacking Kubernetes
Vincent Ruijter - ~Securing~ Attacking KubernetesVincent Ruijter - ~Securing~ Attacking Kubernetes
Vincent Ruijter - ~Securing~ Attacking Kuberneteshacktivity
 
Balázs Bucsay - XFLTReaT: Building a Tunnel
Balázs Bucsay - XFLTReaT: Building a TunnelBalázs Bucsay - XFLTReaT: Building a Tunnel
Balázs Bucsay - XFLTReaT: Building a Tunnelhacktivity
 
Mikhail Egorov - Hunting for bugs in Adobe Experience Manager webapps
Mikhail Egorov - Hunting for bugs in Adobe Experience Manager webappsMikhail Egorov - Hunting for bugs in Adobe Experience Manager webapps
Mikhail Egorov - Hunting for bugs in Adobe Experience Manager webappshacktivity
 
Rodrigo Branco - How Offensive Security is Defining the Way We Compute // Key...
Rodrigo Branco - How Offensive Security is Defining the Way We Compute // Key...Rodrigo Branco - How Offensive Security is Defining the Way We Compute // Key...
Rodrigo Branco - How Offensive Security is Defining the Way We Compute // Key...hacktivity
 
Csongor Tamás - Examples of Locality Sensitive Hashing & their Usage for Malw...
Csongor Tamás - Examples of Locality Sensitive Hashing & their Usage for Malw...Csongor Tamás - Examples of Locality Sensitive Hashing & their Usage for Malw...
Csongor Tamás - Examples of Locality Sensitive Hashing & their Usage for Malw...hacktivity
 
Matthias Deeg - Bypassing an Enterprise-Grade Biometric Face Authentication S...
Matthias Deeg - Bypassing an Enterprise-Grade Biometric Face Authentication S...Matthias Deeg - Bypassing an Enterprise-Grade Biometric Face Authentication S...
Matthias Deeg - Bypassing an Enterprise-Grade Biometric Face Authentication S...hacktivity
 
Gergely Biczók - Interdependent Privacy & the Psychology of Likes
Gergely Biczók - Interdependent Privacy & the Psychology of LikesGergely Biczók - Interdependent Privacy & the Psychology of Likes
Gergely Biczók - Interdependent Privacy & the Psychology of Likeshacktivity
 
Paolo Stagno - A Drone Tale: All Your Drones Belong To Us
Paolo Stagno - A Drone Tale: All Your Drones Belong To UsPaolo Stagno - A Drone Tale: All Your Drones Belong To Us
Paolo Stagno - A Drone Tale: All Your Drones Belong To Ushacktivity
 
Jack S (linkcabin) - Becoming The Quiz Master: Thanks RE.
Jack S (linkcabin) - Becoming The Quiz Master: Thanks RE.Jack S (linkcabin) - Becoming The Quiz Master: Thanks RE.
Jack S (linkcabin) - Becoming The Quiz Master: Thanks RE.hacktivity
 
Zoltán Balázs - Ethereum Smart Contract Hacking Explained like I’m Five
Zoltán Balázs - Ethereum Smart Contract Hacking Explained like I’m FiveZoltán Balázs - Ethereum Smart Contract Hacking Explained like I’m Five
Zoltán Balázs - Ethereum Smart Contract Hacking Explained like I’m Fivehacktivity
 

Mehr von hacktivity (11)

Zsombor Kovács - Cheaters for Everything from Minesweeper to Mobile Banking ...
Zsombor Kovács - 	Cheaters for Everything from Minesweeper to Mobile Banking ...Zsombor Kovács - 	Cheaters for Everything from Minesweeper to Mobile Banking ...
Zsombor Kovács - Cheaters for Everything from Minesweeper to Mobile Banking ...
 
Vincent Ruijter - ~Securing~ Attacking Kubernetes
Vincent Ruijter - ~Securing~ Attacking KubernetesVincent Ruijter - ~Securing~ Attacking Kubernetes
Vincent Ruijter - ~Securing~ Attacking Kubernetes
 
Balázs Bucsay - XFLTReaT: Building a Tunnel
Balázs Bucsay - XFLTReaT: Building a TunnelBalázs Bucsay - XFLTReaT: Building a Tunnel
Balázs Bucsay - XFLTReaT: Building a Tunnel
 
Mikhail Egorov - Hunting for bugs in Adobe Experience Manager webapps
Mikhail Egorov - Hunting for bugs in Adobe Experience Manager webappsMikhail Egorov - Hunting for bugs in Adobe Experience Manager webapps
Mikhail Egorov - Hunting for bugs in Adobe Experience Manager webapps
 
Rodrigo Branco - How Offensive Security is Defining the Way We Compute // Key...
Rodrigo Branco - How Offensive Security is Defining the Way We Compute // Key...Rodrigo Branco - How Offensive Security is Defining the Way We Compute // Key...
Rodrigo Branco - How Offensive Security is Defining the Way We Compute // Key...
 
Csongor Tamás - Examples of Locality Sensitive Hashing & their Usage for Malw...
Csongor Tamás - Examples of Locality Sensitive Hashing & their Usage for Malw...Csongor Tamás - Examples of Locality Sensitive Hashing & their Usage for Malw...
Csongor Tamás - Examples of Locality Sensitive Hashing & their Usage for Malw...
 
Matthias Deeg - Bypassing an Enterprise-Grade Biometric Face Authentication S...
Matthias Deeg - Bypassing an Enterprise-Grade Biometric Face Authentication S...Matthias Deeg - Bypassing an Enterprise-Grade Biometric Face Authentication S...
Matthias Deeg - Bypassing an Enterprise-Grade Biometric Face Authentication S...
 
Gergely Biczók - Interdependent Privacy & the Psychology of Likes
Gergely Biczók - Interdependent Privacy & the Psychology of LikesGergely Biczók - Interdependent Privacy & the Psychology of Likes
Gergely Biczók - Interdependent Privacy & the Psychology of Likes
 
Paolo Stagno - A Drone Tale: All Your Drones Belong To Us
Paolo Stagno - A Drone Tale: All Your Drones Belong To UsPaolo Stagno - A Drone Tale: All Your Drones Belong To Us
Paolo Stagno - A Drone Tale: All Your Drones Belong To Us
 
Jack S (linkcabin) - Becoming The Quiz Master: Thanks RE.
Jack S (linkcabin) - Becoming The Quiz Master: Thanks RE.Jack S (linkcabin) - Becoming The Quiz Master: Thanks RE.
Jack S (linkcabin) - Becoming The Quiz Master: Thanks RE.
 
Zoltán Balázs - Ethereum Smart Contract Hacking Explained like I’m Five
Zoltán Balázs - Ethereum Smart Contract Hacking Explained like I’m FiveZoltán Balázs - Ethereum Smart Contract Hacking Explained like I’m Five
Zoltán Balázs - Ethereum Smart Contract Hacking Explained like I’m Five
 

Kürzlich hochgeladen

Quantum Computing: Current Landscape and the Future Role of APIs
Quantum Computing: Current Landscape and the Future Role of APIsQuantum Computing: Current Landscape and the Future Role of APIs
Quantum Computing: Current Landscape and the Future Role of APIsVlad Stirbu
 
Dev Dives: Train smarter, not harder – active learning and UiPath LLMs for do...
Dev Dives: Train smarter, not harder – active learning and UiPath LLMs for do...Dev Dives: Train smarter, not harder – active learning and UiPath LLMs for do...
Dev Dives: Train smarter, not harder – active learning and UiPath LLMs for do...UiPathCommunity
 
FIDO Alliance Osaka Seminar: Passkeys at Amazon.pdf
FIDO Alliance Osaka Seminar: Passkeys at Amazon.pdfFIDO Alliance Osaka Seminar: Passkeys at Amazon.pdf
FIDO Alliance Osaka Seminar: Passkeys at Amazon.pdfFIDO Alliance
 
Smart TV Buyer Insights Survey 2024 by 91mobiles.pdf
Smart TV Buyer Insights Survey 2024 by 91mobiles.pdfSmart TV Buyer Insights Survey 2024 by 91mobiles.pdf
Smart TV Buyer Insights Survey 2024 by 91mobiles.pdf91mobiles
 
From Siloed Products to Connected Ecosystem: Building a Sustainable and Scala...
From Siloed Products to Connected Ecosystem: Building a Sustainable and Scala...From Siloed Products to Connected Ecosystem: Building a Sustainable and Scala...
From Siloed Products to Connected Ecosystem: Building a Sustainable and Scala...Product School
 
When stars align: studies in data quality, knowledge graphs, and machine lear...
When stars align: studies in data quality, knowledge graphs, and machine lear...When stars align: studies in data quality, knowledge graphs, and machine lear...
When stars align: studies in data quality, knowledge graphs, and machine lear...Elena Simperl
 
IoT Analytics Company Presentation May 2024
IoT Analytics Company Presentation May 2024IoT Analytics Company Presentation May 2024
IoT Analytics Company Presentation May 2024IoTAnalytics
 
PHP Frameworks: I want to break free (IPC Berlin 2024)
PHP Frameworks: I want to break free (IPC Berlin 2024)PHP Frameworks: I want to break free (IPC Berlin 2024)
PHP Frameworks: I want to break free (IPC Berlin 2024)Ralf Eggert
 
Mission to Decommission: Importance of Decommissioning Products to Increase E...
Mission to Decommission: Importance of Decommissioning Products to Increase E...Mission to Decommission: Importance of Decommissioning Products to Increase E...
Mission to Decommission: Importance of Decommissioning Products to Increase E...Product School
 
In-Depth Performance Testing Guide for IT Professionals
In-Depth Performance Testing Guide for IT ProfessionalsIn-Depth Performance Testing Guide for IT Professionals
In-Depth Performance Testing Guide for IT ProfessionalsExpeed Software
 
GenAISummit 2024 May 28 Sri Ambati Keynote: AGI Belongs to The Community in O...
GenAISummit 2024 May 28 Sri Ambati Keynote: AGI Belongs to The Community in O...GenAISummit 2024 May 28 Sri Ambati Keynote: AGI Belongs to The Community in O...
GenAISummit 2024 May 28 Sri Ambati Keynote: AGI Belongs to The Community in O...Sri Ambati
 
Knowledge engineering: from people to machines and back
Knowledge engineering: from people to machines and backKnowledge engineering: from people to machines and back
Knowledge engineering: from people to machines and backElena Simperl
 
UiPath Test Automation using UiPath Test Suite series, part 2
UiPath Test Automation using UiPath Test Suite series, part 2UiPath Test Automation using UiPath Test Suite series, part 2
UiPath Test Automation using UiPath Test Suite series, part 2DianaGray10
 
Kubernetes & AI - Beauty and the Beast !?! @KCD Istanbul 2024
Kubernetes & AI - Beauty and the Beast !?! @KCD Istanbul 2024Kubernetes & AI - Beauty and the Beast !?! @KCD Istanbul 2024
Kubernetes & AI - Beauty and the Beast !?! @KCD Istanbul 2024Tobias Schneck
 
Search and Society: Reimagining Information Access for Radical Futures
Search and Society: Reimagining Information Access for Radical FuturesSearch and Society: Reimagining Information Access for Radical Futures
Search and Society: Reimagining Information Access for Radical FuturesBhaskar Mitra
 
ODC, Data Fabric and Architecture User Group
ODC, Data Fabric and Architecture User GroupODC, Data Fabric and Architecture User Group
ODC, Data Fabric and Architecture User GroupCatarinaPereira64715
 
FIDO Alliance Osaka Seminar: FIDO Security Aspects.pdf
FIDO Alliance Osaka Seminar: FIDO Security Aspects.pdfFIDO Alliance Osaka Seminar: FIDO Security Aspects.pdf
FIDO Alliance Osaka Seminar: FIDO Security Aspects.pdfFIDO Alliance
 
IOS-PENTESTING-BEGINNERS-PRACTICAL-GUIDE-.pptx
IOS-PENTESTING-BEGINNERS-PRACTICAL-GUIDE-.pptxIOS-PENTESTING-BEGINNERS-PRACTICAL-GUIDE-.pptx
IOS-PENTESTING-BEGINNERS-PRACTICAL-GUIDE-.pptxAbida Shariff
 
Accelerate your Kubernetes clusters with Varnish Caching
Accelerate your Kubernetes clusters with Varnish CachingAccelerate your Kubernetes clusters with Varnish Caching
Accelerate your Kubernetes clusters with Varnish CachingThijs Feryn
 
AI for Every Business: Unlocking Your Product's Universal Potential by VP of ...
AI for Every Business: Unlocking Your Product's Universal Potential by VP of ...AI for Every Business: Unlocking Your Product's Universal Potential by VP of ...
AI for Every Business: Unlocking Your Product's Universal Potential by VP of ...Product School
 

Kürzlich hochgeladen (20)

Quantum Computing: Current Landscape and the Future Role of APIs
Quantum Computing: Current Landscape and the Future Role of APIsQuantum Computing: Current Landscape and the Future Role of APIs
Quantum Computing: Current Landscape and the Future Role of APIs
 
Dev Dives: Train smarter, not harder – active learning and UiPath LLMs for do...
Dev Dives: Train smarter, not harder – active learning and UiPath LLMs for do...Dev Dives: Train smarter, not harder – active learning and UiPath LLMs for do...
Dev Dives: Train smarter, not harder – active learning and UiPath LLMs for do...
 
FIDO Alliance Osaka Seminar: Passkeys at Amazon.pdf
FIDO Alliance Osaka Seminar: Passkeys at Amazon.pdfFIDO Alliance Osaka Seminar: Passkeys at Amazon.pdf
FIDO Alliance Osaka Seminar: Passkeys at Amazon.pdf
 
Smart TV Buyer Insights Survey 2024 by 91mobiles.pdf
Smart TV Buyer Insights Survey 2024 by 91mobiles.pdfSmart TV Buyer Insights Survey 2024 by 91mobiles.pdf
Smart TV Buyer Insights Survey 2024 by 91mobiles.pdf
 
From Siloed Products to Connected Ecosystem: Building a Sustainable and Scala...
From Siloed Products to Connected Ecosystem: Building a Sustainable and Scala...From Siloed Products to Connected Ecosystem: Building a Sustainable and Scala...
From Siloed Products to Connected Ecosystem: Building a Sustainable and Scala...
 
When stars align: studies in data quality, knowledge graphs, and machine lear...
When stars align: studies in data quality, knowledge graphs, and machine lear...When stars align: studies in data quality, knowledge graphs, and machine lear...
When stars align: studies in data quality, knowledge graphs, and machine lear...
 
IoT Analytics Company Presentation May 2024
IoT Analytics Company Presentation May 2024IoT Analytics Company Presentation May 2024
IoT Analytics Company Presentation May 2024
 
PHP Frameworks: I want to break free (IPC Berlin 2024)
PHP Frameworks: I want to break free (IPC Berlin 2024)PHP Frameworks: I want to break free (IPC Berlin 2024)
PHP Frameworks: I want to break free (IPC Berlin 2024)
 
Mission to Decommission: Importance of Decommissioning Products to Increase E...
Mission to Decommission: Importance of Decommissioning Products to Increase E...Mission to Decommission: Importance of Decommissioning Products to Increase E...
Mission to Decommission: Importance of Decommissioning Products to Increase E...
 
In-Depth Performance Testing Guide for IT Professionals
In-Depth Performance Testing Guide for IT ProfessionalsIn-Depth Performance Testing Guide for IT Professionals
In-Depth Performance Testing Guide for IT Professionals
 
GenAISummit 2024 May 28 Sri Ambati Keynote: AGI Belongs to The Community in O...
GenAISummit 2024 May 28 Sri Ambati Keynote: AGI Belongs to The Community in O...GenAISummit 2024 May 28 Sri Ambati Keynote: AGI Belongs to The Community in O...
GenAISummit 2024 May 28 Sri Ambati Keynote: AGI Belongs to The Community in O...
 
Knowledge engineering: from people to machines and back
Knowledge engineering: from people to machines and backKnowledge engineering: from people to machines and back
Knowledge engineering: from people to machines and back
 
UiPath Test Automation using UiPath Test Suite series, part 2
UiPath Test Automation using UiPath Test Suite series, part 2UiPath Test Automation using UiPath Test Suite series, part 2
UiPath Test Automation using UiPath Test Suite series, part 2
 
Kubernetes & AI - Beauty and the Beast !?! @KCD Istanbul 2024
Kubernetes & AI - Beauty and the Beast !?! @KCD Istanbul 2024Kubernetes & AI - Beauty and the Beast !?! @KCD Istanbul 2024
Kubernetes & AI - Beauty and the Beast !?! @KCD Istanbul 2024
 
Search and Society: Reimagining Information Access for Radical Futures
Search and Society: Reimagining Information Access for Radical FuturesSearch and Society: Reimagining Information Access for Radical Futures
Search and Society: Reimagining Information Access for Radical Futures
 
ODC, Data Fabric and Architecture User Group
ODC, Data Fabric and Architecture User GroupODC, Data Fabric and Architecture User Group
ODC, Data Fabric and Architecture User Group
 
FIDO Alliance Osaka Seminar: FIDO Security Aspects.pdf
FIDO Alliance Osaka Seminar: FIDO Security Aspects.pdfFIDO Alliance Osaka Seminar: FIDO Security Aspects.pdf
FIDO Alliance Osaka Seminar: FIDO Security Aspects.pdf
 
IOS-PENTESTING-BEGINNERS-PRACTICAL-GUIDE-.pptx
IOS-PENTESTING-BEGINNERS-PRACTICAL-GUIDE-.pptxIOS-PENTESTING-BEGINNERS-PRACTICAL-GUIDE-.pptx
IOS-PENTESTING-BEGINNERS-PRACTICAL-GUIDE-.pptx
 
Accelerate your Kubernetes clusters with Varnish Caching
Accelerate your Kubernetes clusters with Varnish CachingAccelerate your Kubernetes clusters with Varnish Caching
Accelerate your Kubernetes clusters with Varnish Caching
 
AI for Every Business: Unlocking Your Product's Universal Potential by VP of ...
AI for Every Business: Unlocking Your Product's Universal Potential by VP of ...AI for Every Business: Unlocking Your Product's Universal Potential by VP of ...
AI for Every Business: Unlocking Your Product's Universal Potential by VP of ...
 

Gabrial Cirlig & Stefan Tanase - Smart Car Forensics and Vehicle Weaponization

  • 1. 1© 2016 IXIA AND/OR ITS AFFILIATES. ALL RIGHTS RESERVED. | Smart car forensics & vehicle weaponization Gabriel Cirlig – Software Engineer Stefan Tanase – Security Researcher
  • 2. 2© 2016 IXIA AND/OR ITS AFFILIATES. ALL RIGHTS RESERVED. | INGENIOUS! A ROMANIAN managed to modify public transportation cards! whoami
  • 3. 3© 2016 IXIA AND/OR ITS AFFILIATES. ALL RIGHTS RESERVED. | whoami2
  • 4. 4© 2016 IXIA AND/OR ITS AFFILIATES. ALL RIGHTS RESERVED. | ./shameless_plug.sh @hookgab @stefant
  • 5. 5© 2016 IXIA AND/OR ITS AFFILIATES. ALL RIGHTS RESERVED. |
  • 6. 6© 2016 IXIA AND/OR ITS AFFILIATES. ALL RIGHTS RESERVED. | THE CONNECTED CAR
  • 7. 7© 2016 IXIA AND/OR ITS AFFILIATES. ALL RIGHTS RESERVED. | THE MOTIVATION
  • 8. 8© 2016 IXIA AND/OR ITS AFFILIATES. ALL RIGHTS RESERVED. | THE START
  • 9. 9© 2016 IXIA AND/OR ITS AFFILIATES. ALL RIGHTS RESERVED. | THE TECH • Freescale i.MX6 ARM Cortex-A9 • random *nix distribution • GPS soldered on board (even if you didn’t buy the nav package) • 1GB RAM • WIFI!!!1!1111 • revolutionary usb debugging ™ A lot of power for a car, eh?
  • 10. 10© 2016 IXIA AND/OR ITS AFFILIATES. ALL RIGHTS RESERVED. | 10© 2016 IXIA AND/OR ITS AFFILIATES. ALL RIGHTS RESERVED. | Smart car forensics
  • 11. 11© 2016 IXIA AND/OR ITS AFFILIATES. ALL RIGHTS RESERVED. | GETTING IN • Abuse “autorun” script from USB • disable iptables • run SSHD for our platform • …prophit! • root/jci • ez ‘till now
  • 12. 12© 2016 IXIA AND/OR ITS AFFILIATES. ALL RIGHTS RESERVED. | WHAT WE FOUND everything?
  • 13. 13© 2016 IXIA AND/OR ITS AFFILIATES. ALL RIGHTS RESERVED. | EXTRA • voice profiles • vehicle status • directory listings for your phone (wtf, the car is crawling me)
  • 14. 14© 2016 IXIA AND/OR ITS AFFILIATES. ALL RIGHTS RESERVED. | AUTO INDUSTRY IN A NUTSHELL
  • 15. 15© 2016 IXIA AND/OR ITS AFFILIATES. ALL RIGHTS RESERVED. | AUTO INDUSTRY IN A NUTSHELL
  • 16. 16© 2016 IXIA AND/OR ITS AFFILIATES. ALL RIGHTS RESERVED. | 16© 2016 IXIA AND/OR ITS AFFILIATES. ALL RIGHTS RESERVED. | Vehicle weaponization
  • 17. 17© 2016 IXIA AND/OR ITS AFFILIATES. ALL RIGHTS RESERVED. | WHAT WE CAN EXPLOIT • deployed via the same script that granted ssh access • uses cron to keep itself alive • constantly looks for open wifis • constantly logs GPS coordinates • whenever we connect, upload new data • WARDRIVING WITHOUT A LAPTOP!
  • 18. 18© 2016 IXIA AND/OR ITS AFFILIATES. ALL RIGHTS RESERVED. | GIVING IT SOME LOVE
  • 19. 19© 2016 IXIA AND/OR ITS AFFILIATES. ALL RIGHTS RESERVED. | LIVE DEMO
  • 20. 20© 2016 IXIA AND/OR ITS AFFILIATES. ALL RIGHTS RESERVED. | https://www.youtube.com/watch?v=q0CjVHlEJuQ&feature=em-upload_owner
  • 21. 21© 2016 IXIA AND/OR ITS AFFILIATES. ALL RIGHTS RESERVED. | SMART CAR RANSOMWARE
  • 22. 22© 2016 IXIA AND/OR ITS AFFILIATES. ALL RIGHTS RESERVED. | THE FUTURE
  • 23. 23© 2016 IXIA AND/OR ITS AFFILIATES. ALL RIGHTS RESERVED. | THE FUTURE
  • 24. 24© 2016 IXIA AND/OR ITS AFFILIATES. ALL RIGHTS RESERVED. | THE FUTURE
  • 25. 25© 2016 IXIA AND/OR ITS AFFILIATES. ALL RIGHTS RESERVED. | THE FUTURE
  • 26. 26© 2016 IXIA AND/OR ITS AFFILIATES. ALL RIGHTS RESERVED. | THE FUTURE
  • 27. 27© 2016 IXIA AND/OR ITS AFFILIATES. ALL RIGHTS RESERVED. | THE FUTURE
  • 28. 28© 2016 IXIA AND/OR ITS AFFILIATES. ALL RIGHTS RESERVED. | Our privacy is threatened Travelers always rent cars, car sharing programs are becoming popular in big cities, shared corporate car fleets Evolution of technology – a double edged sword We *want* smartphones, tablets, smart watches, smart cars, self driving cars, internet of things etc. EURONCAP for automotive cybersecurity We already have crash-tests for physical safety. Seatbelts and airbags are mandatory. Why is the industry ignoring cybersecurity? CONCLUSIONS
  • 29. 29© 2016 IXIA AND/OR ITS AFFILIATES. ALL RIGHTS RESERVED. | THE AFTERMATH
  • 30. 30© 2016 IXIA AND/OR ITS AFFILIATES. ALL RIGHTS RESERVED. | Follow us on Twitter! @hookgab @stefant