# Network Security FAIL... Chrysler vulnerability

**URL:** <https://forums.speedlife.net/t/network-security-fail-chrysler-vulnerability/272708>\
**Category:** NYSpeed Automotive\
**Created:** [July 21, 2015, 7:09pm UTC](https://forums.speedlife.net/t/network-security-fail-chrysler-vulnerability/272708 "2015-07-21T19:09:50Z")\
**Posts on this page:** 16\
**Page:** 1

<div class="post-metadata">

**Author:** ![Unknown923](https://yyz2.discourse-cdn.com/flex034/user_avatar/forums.speedlife.net/unknown923/32/6803_2.png) [@Unknown923](https://forums.speedlife.net/u/Unknown923)\
**Post date:** [July 21, 2015, 7:09pm UTC](https://forums.speedlife.net/t/network-security-fail-chrysler-vulnerability/272708/1 "2015-07-21T19:09:50Z")

</div>

Jeep Cherokee Hacked… Apparently there’s a lack of vulnerability testing among a handful of manufacturers. Thoughts?

> **[Hackers Remotely Kill a Jeep on the Highway—With Me in It](https://www.wired.com/2015/07/hackers-remotely-kill-jeep-highway/)**
>
> I was driving 70 mph on the edge of downtown St. Louis when the exploit began to take hold.

---

<div class="post-metadata">

**Author:** ![LZ1](https://avatars.discourse-cdn.com/v4/letter/l/7ab992/32.png) [@LZ1](https://forums.speedlife.net/u/LZ1)\
**Post date:** [July 22, 2015, 4:49am UTC](https://forums.speedlife.net/t/network-security-fail-chrysler-vulnerability/272708/2 "2015-07-22T04:49:15Z")

</div>

I posted this in another thread but these issues are fairly common across brands each company does various levels of testing.

Modern cars are basically large networks with everything interconnected via the CAN bus so doing something stupid like taking over a radio on a car could potentially give you the ability to inject CAN bus packets and make other systems do unintended things.

If you’re looking at a modern car you can attack from a lot of avenues TPMS sensors, onboard wifi, MP3 parsing in the radio, Onstar, bluetooth, etc

[http://resources.infosecinstitute.com/car-hacking-safety-without-security/](http://resources.infosecinstitute.com/car-hacking-safety-without-security/)

Free eBook on the topic here - [http://opengarages.org/handbook/](http://opengarages.org/handbook/)

---

<div class="post-metadata">

**Author:** ![JayS](https://yyz2.discourse-cdn.com/flex034/user_avatar/forums.speedlife.net/jays/32/15375_2.png) [@JayS](https://forums.speedlife.net/u/JayS)\
**Post date:** [July 22, 2015, 5:01am UTC](https://forums.speedlife.net/t/network-security-fail-chrysler-vulnerability/272708/3 "2015-07-22T05:01:42Z")

</div>

I’m wondering how they were able to disable the brakes because that’s pretty scary stuff. I’m guessing they got into the ABS routines and made the ABS system think there was a wheel lockup when there wasn’t.

---

<div class="post-metadata">

**Author:** ![TradersBASE](https://yyz2.discourse-cdn.com/flex034/user_avatar/forums.speedlife.net/tradersbase/32/5321_2.png) [@TradersBASE](https://forums.speedlife.net/u/TradersBASE)\
**Post date:** [July 22, 2015, 5:24am UTC](https://forums.speedlife.net/t/network-security-fail-chrysler-vulnerability/272708/4 "2015-07-22T05:24:40Z")

</div>

I’m looking forward to a script that will force drivers to listen to the 1950’s station on Sirius.

---

<div class="post-metadata">

**Author:** ![LZ1](https://avatars.discourse-cdn.com/v4/letter/l/7ab992/32.png) [@LZ1](https://forums.speedlife.net/u/LZ1)\
**Post date:** [July 22, 2015, 5:36am UTC](https://forums.speedlife.net/t/network-security-fail-chrysler-vulnerability/272708/5 "2015-07-22T05:36:54Z")

</div>

“Should we add vulnerability assessments to the 21-point vehicle inspection? “Um, sir, I can’t pass you until we patch that vuln.””

---

<div class="post-metadata">

**Author:** ![JayS](https://yyz2.discourse-cdn.com/flex034/user_avatar/forums.speedlife.net/jays/32/15375_2.png) [@JayS](https://forums.speedlife.net/u/JayS)\
**Post date:** [July 22, 2015, 5:50am UTC](https://forums.speedlife.net/t/network-security-fail-chrysler-vulnerability/272708/6 "2015-07-22T05:50:02Z")

</div>

> [@LZ](#):
>
> “Should we add vulnerability assessments to the 21-point vehicle inspection? “Um, sir, I can’t pass you until we patch that vuln.””

That probably makes sense actually. This Chrysler one you can even download and install yourself.

---

<div class="post-metadata">

**Author:** ![TradersBASE](https://yyz2.discourse-cdn.com/flex034/user_avatar/forums.speedlife.net/tradersbase/32/5321_2.png) [@TradersBASE](https://forums.speedlife.net/u/TradersBASE)\
**Post date:** [July 22, 2015, 6:17am UTC](https://forums.speedlife.net/t/network-security-fail-chrysler-vulnerability/272708/7 "2015-07-22T06:17:25Z")

</div>

> [@LZ](#):
>
> “Should we add vulnerability assessments to the 21-point vehicle inspection? “Um, sir, I can’t pass you until we patch that vuln.””

“What’d they fail you for, tires or emissions?” “Neither, the goddamn firmware was 3 revs behind.”

---

<div class="post-metadata">

**Author:** ![LZ1](https://avatars.discourse-cdn.com/v4/letter/l/7ab992/32.png) [@LZ1](https://forums.speedlife.net/u/LZ1)\
**Post date:** [July 22, 2015, 7:22am UTC](https://forums.speedlife.net/t/network-security-fail-chrysler-vulnerability/272708/8 "2015-07-22T07:22:45Z")

</div>

This slide deck is pretty solid

> **[The Current State of Automotive Security by Chris Valasek](https://www.slideshare.net/codeblue_jp/chris-valasek-enpub)**
>
> Automotive computers, or Electronic Control Units (ECU), were originally introduced to help with fuel efficiency and emissions problems of the 1970s but evolve…

---

<div class="post-metadata">

**Author:** ![JayS](https://yyz2.discourse-cdn.com/flex034/user_avatar/forums.speedlife.net/jays/32/15375_2.png) [@JayS](https://forums.speedlife.net/u/JayS)\
**Post date:** [July 22, 2015, 8:06am UTC](https://forums.speedlife.net/t/network-security-fail-chrysler-vulnerability/272708/9 "2015-07-22T08:06:09Z")

</div>

@LZ1 Saw one of your buddies was in a debate on FB about how these guys went about this the wrong way by forcing a car off the road and how it was bad for the professional hacker community etc etc.

What do you think?

Sadly I think I takes something headline grabbing like disabling the brakes on a Grand Cherokee and it ending up in a ditch to bring the issue into the mainstream. IS/IT/Security people have known about this issue but the general public didn’t seem to care so nothing really changed. Now that it’s a headline I’ve had 3 non-car people come up to me today and ask me about it. Car manufactures can’t dismiss now so something will get done to address it. Most likely breaking the critical systems off onto a separate network from the non-critical systems that use wireless communication (like TMPS, BT radio etc).

---

<div class="post-metadata">

**Author:** ![LZ1](https://avatars.discourse-cdn.com/v4/letter/l/7ab992/32.png) [@LZ1](https://forums.speedlife.net/u/LZ1)\
**Post date:** [July 22, 2015, 8:18am UTC](https://forums.speedlife.net/t/network-security-fail-chrysler-vulnerability/272708/10 "2015-07-22T08:18:47Z")

</div>

There are a couple views on this

1. Something dramatic like this grabs attention and makes people who don’t understand technology freak out. However that normally causes some knee jerk reaction which won’t fix the underlying issue.

2. Bringing it into a spot light and get companies to actively pursue fixes for this sort of technology.

Charlie and Chis are really really smart I don’t think they would have put anyone in actual risk or what they did was over the top. Everyone wants to be politically correct now a days which is what all the ranting is about my guess is most people in the hacker/sec community think it was really cool they just want take some higher politically correct stance.

Auto companies are taking this sort of stuff pretty seriously already I have friends at Tesla and have others who have done testing for GM. The company I work for currently just responded to a rather large RFP to have us test one of their auto platforms so it’s not like companies are not working towards more security.

The CAN bus design doesn’t lend its self to security which makes the entire thing :tif:

Surprised nobody made any comments about Chris Roberts - [http://www.cnn.com/2015/05/17/us/fbi-hacker-flight-computer-systems/](http://www.cnn.com/2015/05/17/us/fbi-hacker-flight-computer-systems/) seems like a way worse place to test security 🙂

---

<div class="post-metadata">

**Author:** ![JayS](https://yyz2.discourse-cdn.com/flex034/user_avatar/forums.speedlife.net/jays/32/15375_2.png) [@JayS](https://forums.speedlife.net/u/JayS)\
**Post date:** [July 22, 2015, 12:09pm UTC](https://forums.speedlife.net/t/network-security-fail-chrysler-vulnerability/272708/11 "2015-07-22T12:09:58Z")

</div>

> [@LZ](#):
>
> Surprised nobody made any comments about Chris Roberts - [http://www.cnn.com/2015/05/17/us/fbi-hacker-flight-computer-systems/](http://www.cnn.com/2015/05/17/us/fbi-hacker-flight-computer-systems/) seems like a way worse place to test security 🙂

Yeah, messing with a loaded commercial airliner mid-flight is just fucked up. Not really the same as attacking a Jeep that you specifically told the driver you were going to attack.

---

<div class="post-metadata">

**Author:** ![LZ1](https://avatars.discourse-cdn.com/v4/letter/l/7ab992/32.png) [@LZ1](https://forums.speedlife.net/u/LZ1)\
**Post date:** [July 24, 2015, 8:02am UTC](https://forums.speedlife.net/t/network-security-fail-chrysler-vulnerability/272708/12 "2015-07-24T08:02:39Z")

</div>

Yikes

Fiat Chrysler Recalls 1.4 Million Vehicles to Defend Against Hackshttp://www.bloomberg.com/news/articles/2015-07-24/fiat-chrysler-recalls-1-4-million-autos-to-defend-against-hacks

Next few years are going to really interesting if this sets the standard for car security flaws.

---

<div class="post-metadata">

**Author:** ![JayS](https://yyz2.discourse-cdn.com/flex034/user_avatar/forums.speedlife.net/jays/32/15375_2.png) [@JayS](https://forums.speedlife.net/u/JayS)\
**Post date:** [July 24, 2015, 8:53am UTC](https://forums.speedlife.net/t/network-security-fail-chrysler-vulnerability/272708/13 "2015-07-24T08:53:51Z")

</div>

I was expecting this. Once you end up on the news because someone remotely disabled the brakes on a car it’s no longer a “install this when you get a chance” kind of fix.

---

<div class="post-metadata">

**Author:** ![boxxa](https://yyz2.discourse-cdn.com/flex034/user_avatar/forums.speedlife.net/boxxa/32/5045_2.png) [@boxxa](https://forums.speedlife.net/u/boxxa)\
**Post date:** [July 27, 2015, 10:39am UTC](https://forums.speedlife.net/t/network-security-fail-chrysler-vulnerability/272708/14 "2015-07-27T10:39:53Z")

</div>

Anything connected to the internet will eventually be hacked when enough people get involved and are motivated to.

Well scary, the initial audio controls was done through the web facing hack since they decided to connect their cars to the internet. The physical car control was done by hardware hacking which is really impressive and also not something that was static so needed to be loaded on the fly after the car was running. Not like the movies where you simply can hop all over quickly so this was more sophisticated than what the media is making it seem like OMG ANYONE WITH A LAPTOP CAN TAKE OVER YOUR CAR!

The issue too is the USB drive update so they need to implement the patch but needs to go to the USB stick and manually done which obviously will slow roll out and leave more vulnerable out there.

To make things better, senior Daimler engineering exec said he can’t hack a Mercedes-Benz. Not sure if this is valid but def entertaining.

Guess I’ll buy a Mercedes“There is no way you could hack a Mercedes-Benz from outside the car,” a senior Daimler engineering executive said

> <https://twitter.com/0xcharlie/status/625441569206833152>

It is a common saying, _ **don’t connect things that can kill you to the internet.** _

---

<div class="post-metadata">

**Author:** ![LZ1](https://avatars.discourse-cdn.com/v4/letter/l/7ab992/32.png) [@LZ1](https://forums.speedlife.net/u/LZ1)\
**Post date:** [July 27, 2015, 10:45am UTC](https://forums.speedlife.net/t/network-security-fail-chrysler-vulnerability/272708/15 "2015-07-27T10:45:30Z")

</div>

🙂

[‏@dotMudge](https://twitter.com/dotMudge) [6h6 hours ago](https://twitter.com/dotMudge/status/625636096366481408)  
Mercedes unhackable? Their opensource licenses imply otherwise: libtiff, libpng…[http://moba.i.daimler.com/bai-cars/ba/foss/content/en/assets/FOSS\_licences.pdf](http://moba.i.daimler.com/bai-cars/ba/foss/content/en/assets/FOSS_licences.pdf)  
cc [@0xcharlie](https://twitter.com/0xcharlie) [@nudehaberdasher](https://twitter.com/nudehaberdasher)

---

<div class="post-metadata">

**Author:** ![LZ1](https://avatars.discourse-cdn.com/v4/letter/l/7ab992/32.png) [@LZ1](https://forums.speedlife.net/u/LZ1)\
**Post date:** [August 10, 2015, 5:22pm UTC](https://forums.speedlife.net/t/network-security-fail-chrysler-vulnerability/272708/16 "2015-08-10T17:22:22Z")

</div>

They dropped the full PDF on all their Jeep research [http://illmatics.com/Remote%20Car%20Hacking.pdf](http://illmatics.com/Remote%20Car%20Hacking.pdf)
