Scientists have been working on ways to hack car security systems. Increasingly, lots of things in new cars tie in to a central bus: engine control unit, anti-lock brakes, air bags, transmission, door locks. And the car stereo. The scientists have found a way to create a specially-crafted MP3 which, if played on certain models, lets them take control of the car, potentially by bluetooth or the car's celllular system.
Older cars without centralized buses would be immune, as would installing your own stereo. The sad thing is that car makers do not seem to be doing much to create a reasonably secure system, you'd think they'd learn with the news of all the systems being exploited out in the world.
(Speaking of which, my favorite recent hack is HB Gary Federal going against Anonymous: they totally pwnd their CEO, up to and including remote-wiping the guy's iPad!)
http://www.itworld.com/print/139794
http://it.slashdot.org/story/11/03/12/0114219/Hacking-a-Car-With-Music
Older cars without centralized buses would be immune, as would installing your own stereo. The sad thing is that car makers do not seem to be doing much to create a reasonably secure system, you'd think they'd learn with the news of all the systems being exploited out in the world.
(Speaking of which, my favorite recent hack is HB Gary Federal going against Anonymous: they totally pwnd their CEO, up to and including remote-wiping the guy's iPad!)
http://www.itworld.com/print/139794
http://it.slashdot.org/story/11/03/12/0114219/Hacking-a-Car-With-Music
no subject
Date: 2011-03-13 06:01 pm (UTC)no subject
Date: 2011-03-13 06:34 pm (UTC)How to? Find a dealership selling models that Hacker X has an exploit for. Get with a local band of reasonable quality, offer to make them a demo disc for free. Make a nice marketing package of the band with the car, offer to give them to the dealership for free as it only has 4 tracks or so with an offer to buy a full CD for a low rate. Discs go out to dealership employees which frequently drive the cars they're selling, they also give them to people buying new cars. Instant ability to steal a dozen cars or so. You could do the same thing at a car rental company. You might even be able to have the infected car report where it's at to you so you could go and steal it then reprogram it.
There was an incident in Florida last year (IIRC) where a guy who used to work at a 'low/no credit' car company, they always installed LoJack's in their cars to make repossessing them easy. The guy got fired, remoted in to their control console, and tripped every car to disable them and sound the horn continuously. He was easily identified and arrested.
no subject
Date: 2011-03-13 06:35 pm (UTC)no subject
Date: 2011-03-13 07:36 pm (UTC)Still, why are we developing cars with a CPU and not apparently taking concerns that such a thing is a vulnerability seriously?