During the test, Turla only tried simple attacks such as text printing or parodying control voices. Because MZD Connect is a NIX-based system, anyone can create and execute scripts for other types of attacks. Turla said that his scenario was perfect to re-enable SSH support on the MZ Connect System after the feature was removed during the previous firmware update.
Automatic attack by USB
The attack process will automatically take place after the user has inserted the USB into the control panel. "No need to interact with users, you just need to insert the USB into the USB port on the car. Imagine the spontaneous feature on Windows when automatically executing the script".
However, this type of attack also has weaknesses. The vehicle must be in Accessory Mode or the engine must be running before the code is executed. This means you cannot use this method to start or control the vehicle. "You can do it but I don't have a PoC," Turla said. In addition, hackers can create botnets for Mazda cars. Turla also said one of his managers believed that the error could be used to install the RAT (Remote Access Trojans) on the vehicle.
Other researchers looking at MZD Connect's firmware also share similar ideas. "Its CMU (Car Multimedia Unit) is not full of remote execution errors," security researcher Aris Adamantiadis wrote on Twitter, "If you connect to WiFi, you can access (read only) CAN BUS through via DBUS network ".
USB attack error has been fixed in the last update
These things can happen because the error on the car allows users to execute unverified code on the vehicle's information system, and in terms of information security means "anything". If the attacker has the skills and knowledge to write the appropriate code.
According to the MZF-AIO-TI project, the error of executing the USB code was fixed on the firmware MZD Connect version 59.00.502 released last month. Un-updated cars can still be attacked even though there have been no reports of abuse of the bug, except for refining the dashboard of the vehicle infotainment system.
Contacting Bleeping Computer, Mazda dispels all worries that this problem can be used to endanger users.
"On Mazda cars, the functions that Mazda Connect controls are very limited and cannot be accessed remotely by Wi-Fi, meaning that the risk of hacking with USB will only cause minor or minor losses. On the car, The Mazda Connect has limited control settings such as remote control lock, which information will show up on Active Driving Display, when the car responds to lane insertion . Interfering with features This also does not help gain control of the direction, brake or vehicle speed control ".
Below is a list of MZD Connect system models
Mazda CX-3
Mazda CX-5
Mazda CX-7
Mazda CX-9
Mazda2
Mazda6
Mazda MX-5
Turla said he will continue to study car holes. "I'm going to try Tesla Model X, Honda City 2017 or Mitsubishi Montero Sport 2017. Hopefully I will get practical tests on the dashboard and infotainment system that will be unveiled at Car Hacking Village of DEF CON year. now on".
this wikihow teaches you how to copy pictures from your computer to your usb flash drive. plug your flash drive into your mac. your computer most likely has rectangular holes, called usb ports, on the sides of its casing (for laptops) or...
usb flash drive is one of the popular technology devices thanks to its high portability. high demand means that many usb flash models are released by manufacturers.
this wikihow teaches you how to safely remove an external hard drive or flash drive from your windows 10 computer. save any open documents you have on the flash drive. the easiest way to do this in any open window is to hold down and press...
today's wikihow teaches you how to fix a malfunctioning flash drive. for software or driver problems, you can scan and repair the flash drive using your computer's built-in repair utility. if the usb doesn't work because of improper formatting or data corruption, you can reset the drive, but remember that reinstalling the usb will erase all the files inside. finally, if the flash drive still does not work due to hardware damage, you should take the usb to a repair center or professional data recovery service; if that's not possible, you can still fix it yourself by soldering the broken usb circuit to the active usb cable end. however, we do not recommend trying to repair it yourself because you are very likely to destroy the flash drive.
this wikihow teaches you how to use a usb flash drive to install a version of the windows operating system onto a windows computer. using a usb flash drive is useful when your computer doesn't have a cd drive or when you don't have an...
this wikihow teaches you how to move a movie you've downloaded on your windows or mac computer onto a usb flash drive. when downloading movies, make sure you aren't breaking any laws in your country by pirating media. in most cases, you'll...
this wikihow teaches you how to download a google doc document and place it on your flash drive. you can do this on both windows and mac computers. plug your flash drive into your computer. it should insert into one of the thin,...
you can install an operating system onto a flash drive and use it like a portable computer by using rufus on windows or the disk utility on mac. for each method, you'll need to acquire the os installer or image, format the usb flash drive,...
windows xp installation process is slightly different from windows 7 or windows 8 because microsoft does not design windows xp to install from a usb flash drive. read the following article to learn how to install windows xp from a usb flash drive!