Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

News

8/6/2015
12:00 PM
Connect Directly
Google+
Twitter
RSS
E-Mail
50%
50%

Jeep Hack 0Day: An Exposed Port

Researchers at Black Hat USA gave details on how they were able to remotely hack and control a Jeep Cherokee.

BLACK HAT USA -- Las Vegas -- In the end, it was an unnecessarily open port that led to the infamous -- and road-tested -- hack of the 2014 Jeep Cherokee by famed car hackers Charlie Miller and Chris Valasek.

Miller and Valasek here yesterday in their presentation on their remote hack of the vehicle revealed the "vulnerability" -- a wide open port 6667 -- that ultimately led to their ability to control the Jeep's steering, braking, high beams, turn signals, windshield wipers and fluid, and door locks, as well as reset the speedometer and tachometer, kill the engine, and disengage the transmission so the accelerator pedal failed.

After studying ways to hack via the car's optional WiFi service, the researchers discovered that the Harman uConnect infotainment system's built-in cellular connection from Sprint left Port 6667 open, which  gave them a connection to the car via their smartphones on the cellular network. The researchers employed a femtocell, and after testing various distances, found they could access the vehicle some 70 miles away via the cell connection. They were able to grab the Jeep's VIN number as well.

Miller and Valasek will publish a research paper on Monday with details on exactly what they found and how they were able to wrest control of the Jeep remotely.

But their attack is now basically history--Sprint since has locked down the exposed communications port.

"There's no way to use the attack … now," Valasek said in a press briefing. "We hope other researchers will take a look at other cards" for vulnerabilities, he said.

Miller and Valasek's groundbreaking and somewhat unnerving research and live demonstration of their hack with a driver on an open highway sent a ripple effect through the automobile industry. Fiat Chrysler last month issued a patch, and then a recall of some 1.4 million vehicles affected by the security flaw --  2013 to 2015 Dodge Vipers and Ram pickups; 2014 to 2015 Jeep Grand Cherokee, Cherokees and Dodge Durango SUVs; and 2015 Chrysler 200, Chrysler 300 and Dodge Chargers and Challengers.

The National Highway Traffic Safety Administration (NHTSA), meanwhile, is investigating the effectiveness of the recall.

The researchers had kept Chrysler updated on their findings along the way, including in March when they were able to send their own CAN messages to the vehicle.

"Cars got recalled. That's cool -- hackers did something" to make that happen, Miller said in their presentation.

But they say the security flaws they found in the infotainment system are not just a Fiat Chrysler issue: suppliers and telecommunications companies need to work with the automakers in these cases, they said.

Meanwhile, another pair of researchers was able to hack a Tesla S, but the attack required some physical tampering with the vehicle. The researchers will present their findings here this week at DEF CON, according to a Wired report.

Black Hat USA is happening! Check it out here.

Kelly Jackson Higgins is the Executive Editor of Dark Reading. She is an award-winning veteran technology and business journalist with more than two decades of experience in reporting and editing for various publications, including Network Computing, Secure Enterprise ... View Full Bio

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
theb0x
100%
0%
theb0x,
User Rank: Ninja
8/13/2015 | 9:40:37 AM
Port 6667
Now you can host your very own IRC channel on port 6667! Chat with other Jeep owners in realtime! Simply amazing!

 

Features coming soon:

 

XDCC File Transfers and Private Chat.

 
rrahmanov
50%
50%
rrahmanov,
User Rank: Apprentice
8/11/2015 | 3:49:59 PM
It only takes 1 (!!!) port
It is as simple as it sounds. One port and a person that knows what to do with it. 
It is interesting, I've just read about Tesla's Model S reporting 6 vulnerabilities related to a similar issue - old browser, outdated services (DNS proxy, HTTP Service) - basically indicating a lack of the up-to-date patching. 
COVID-19: Latest Security News & Commentary
Dark Reading Staff 9/21/2020
Hacking Yourself: Marie Moe and Pacemaker Security
Gary McGraw Ph.D., Co-founder Berryville Institute of Machine Learning,  9/21/2020
Startup Aims to Map and Track All the IT and Security Things
Kelly Jackson Higgins, Executive Editor at Dark Reading,  9/22/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Special Report: Computing's New Normal
This special report examines how IT security organizations have adapted to the "new normal" of computing and what the long-term effects will be. Read it and get a unique set of perspectives on issues ranging from new threats & vulnerabilities as a result of remote working to how enterprise security strategy will be affected long term.
Flash Poll
How IT Security Organizations are Attacking the Cybersecurity Problem
How IT Security Organizations are Attacking the Cybersecurity Problem
The COVID-19 pandemic turned the world -- and enterprise computing -- on end. Here's a look at how cybersecurity teams are retrenching their defense strategies, rebuilding their teams, and selecting new technologies to stop the oncoming rise of online attacks.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-5783
PUBLISHED: 2020-09-23
In IgniteNet HeliOS GLinq v2.2.1 r2961, the login functionality does not contain any CSRF protection mechanisms.
CVE-2020-11031
PUBLISHED: 2020-09-23
In GLPI before version 9.5.0, the encryption algorithm used is insecure. The security of the data encrypted relies on the password used, if a user sets a weak/predictable password, an attacker could decrypt data. This is fixed in version 9.5.0 by using a more secure encryption library. The library c...
CVE-2020-5781
PUBLISHED: 2020-09-23
In IgniteNet HeliOS GLinq v2.2.1 r2961, the langSelection parameter is stored in the luci configuration file (/etc/config/luci) by the authenticator.htmlauth function. When modified with arbitrary javascript, this causes a denial-of-service condition for all other users.
CVE-2020-5782
PUBLISHED: 2020-09-23
In IgniteNet HeliOS GLinq v2.2.1 r2961, if a user logs in and sets the ‘wan_type’ parameter, the wan interface for the device will become unreachable, which results in a denial of service condition for devices dependent on this connection.
CVE-2020-24213
PUBLISHED: 2020-09-23
An integer overflow was discovered in YGOPro ygocore v13.51. Attackers can use it to leak the game server thread's memory.