Jump to content

Nissan cars can be hacked and controlled over internet

WereCat

Source: http://www.troyhunt.com/2016/02/controlling-vehicle-features-of-nissan.html

 

 

Quote

 

The Nissan LEAF is an electric car which is particularly popular in countries like Norway which offer massive financial incentives to stay away from combustion engines. It does all the things you’d expect of a modern EV and because it’s here in the era of the internet of things, it also has a companion app:The LEAF is an electric car which is particularly popular in countries like Norway which offer massive financial incentives to stay away from combustion engines. It does all the things you’d expect of a modern EV and because it’s here in the era of the internet of things, it also has a companion app.

 

What the workshop attendee ultimately discovered was that not only could he connect to his LEAF over the internet and control features independently of how Nissan had designed the app, he could control other people’s LEAFs. I subsequently discovered that friend and fellow security researcher Scott Helme also has a LEAF so we recorded the following video to demonstrate the problem.What the workshop attendee ultimately discovered was that not only could he connect to his LEAF over the internet and control features independently of how Nissan had designed the app, he could control other people’s LEAFs. I subsequently discovered that friend and fellow security researcher Scott Helme also has a LEAF so we recorded the following video to demonstrate the problem.

 

 

The app is apparently indentifying with server just by using VIN number of the car and thats it .. no aditional authentification.

 

UPDATE (reminded by @Ethnod ):

http://www.wired.co.uk/news/archive/2016-02/24/nissan-car-hacked

 

Nissan has pulled its NissanConnect EV app after it was found the software could be hacked to remotely control in-car systems.

The company confirmed the flaw and said it would release an updated version "soon".Nissan has pulled its NissanConnect EV app after it was found the software could be hacked to remotely control in-car systems.

 

The company confirmed the flaw and said it would release an updated version "soon".

 

There is a ton more in the article I just quoted the important bit. Apparently the service was taken offline today but still works for Canadians?

Looks like car makers still dont understand or underestimate the importance of software security. It is not just Nissan problem but as was shown a while ago a lot of cars manufacturers have this problem.

Link to comment
Share on other sites

Link to post
Share on other sites

Time to create the world's biggest game of Rocket League. 

 

How can this still happen? A couple years ago it was Teslas that were hackable. You would think that carmakers would have learned from that.

 

Nova doctrina terribilis sit perdere

Audio format guides: Vinyl records | Cassette tapes

Link to comment
Share on other sites

Link to post
Share on other sites

Can someone give me the source code so that I can hacked the GTR? :D

Budget? Uses? Currency? Location? Operating System? Peripherals? Monitor? Use PCPartPicker wherever possible. 

Quote whom you're replying to, and set option to follow your topics. Or Else we can't see your reply.

 

Link to comment
Share on other sites

Link to post
Share on other sites

Just now, dragoon20005 said:

Can someone give me the source code so that I can hacked the GTR? :D

Oh, you want to go "shopping" ? :D

Link to comment
Share on other sites

Link to post
Share on other sites

Well I think we can take comfort that current cars ARENT that connected as to allow FULL control of the car.

Link to comment
Share on other sites

Link to post
Share on other sites

Just now, WereCat said:

Oh, you want to go "shopping" ? :D

I am in need of a GTR

 

if i can get one for free

 

why not? :D

Budget? Uses? Currency? Location? Operating System? Peripherals? Monitor? Use PCPartPicker wherever possible. 

Quote whom you're replying to, and set option to follow your topics. Or Else we can't see your reply.

 

Link to comment
Share on other sites

Link to post
Share on other sites

Im surr all cheap electric cars will have this issue for a long time to come. 

 

Such a great innovation ruined by simple lack of protection. 

 

Internet is a bitch. 

 

Watch Dogs concept becoming reality.

Connection200mbps / 12mbps 5Ghz wifi

My baby: CPU - i7-4790, MB - Z97-A, RAM - Corsair Veng. LP 16gb, GPU - MSI GTX 1060, PSU - CXM 600, Storage - Evo 840 120gb, MX100 256gb, WD Blue 1TB, Cooler - Hyper Evo 212, Case - Corsair Carbide 200R, Monitor - Benq  XL2430T 144Hz, Mouse - FinalMouse, Keyboard -K70 RGB, OS - Win 10, Audio - DT990 Pro, Phone - iPhone SE

Link to comment
Share on other sites

Link to post
Share on other sites

http://www.wired.co.uk/news/archive/2016-02/24/nissan-car-hacked

 

Nissan have actually taken action, I'm impressed. makes a change, actual action

Never trust a man, who, when left alone with a tea cosey... Doesn't try it on. Billy Connolly
Marriage is a wonderful invention: then again, so is a bicycle repair kit. Billy Connolly
Before you judge a man, walk a mile in his shoes. After that, who cares? He's a mile away and you've got his shoes. Billy Connolly
Link to comment
Share on other sites

Link to post
Share on other sites

Honestly, not a fan of all the computers and automated systems being put into cars today.

Makes them a bitch to work on and vulnerable to outside influences.

Link to comment
Share on other sites

Link to post
Share on other sites

Good thing I have an Nissan Frontier (manual transmission). There's nothing to hack on that car xD even if someone wanted too!

▶ Learn from yesterday, live for today, hope for tomorrow. The important thing is not to stop questioning. - Einstein◀

Please remember to mark a thread as solved if your issue has been fixed, it helps other who may stumble across the thread at a later point in time.

Link to comment
Share on other sites

Link to post
Share on other sites

dont scare me away from owning a GT-R damnit.

Don't fail me now as i've failed you then.

Link to comment
Share on other sites

Link to post
Share on other sites

Awesome :D

Ultimate XP gaming system build log coming soon!  Q8200 // 8GB DDR2 // Asus P5E Deluxe X48 // Asus 4870 DARK KNIGHT X-Fire // Supreme FX sound // BFG Ageia PhysX PCI Co-Processor // AX 860x with Silverstone extensions 

Link to comment
Share on other sites

Link to post
Share on other sites

7 hours ago, Ethnod said:

http://www.wired.co.uk/news/archive/2016-02/24/nissan-car-hacked

 

Nissan have actually taken action, I'm impressed. makes a change, actual action

The action they have taken is weak, the API is still accessible from other domains (see the notes at the bottom of Troy's article).

 

Keep in mind though people, this provides little control over the car. You can get telemetry data and turn on/off the AC, that's about it though! No driving or door locks or anything else. Still a terrible vulnerability, and the people who designed the API made an egregious mistake. 

15" MBP TB

AMD 5800X | Gigabyte Aorus Master | EVGA 2060 KO Ultra | Define 7 || Blade Server: Intel 3570k | GD65 | Corsair C70 | 13TB

Link to comment
Share on other sites

Link to post
Share on other sites

As long as Nissan doesn't act like it's nothing and is actually doing things to properly address the issue then there's not much reason for us to rip them to shreds. It's when they underestimate the extent of a vulnerability that we are obligated to ridicule them.

Link to comment
Share on other sites

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now

×