Subscribe:

Thursday, May 19, 2011

Hacking the Car: Modern Vehicles now at the Mercy of Cyber Attacks.

IDG News Service - University researchers have taken a close look at the computer systems used to run today's cars and discovered new ways to hack into them, sometimes with frightening results.
In a paper set to be presented at a security conference in Oakland, California, next week, the security researchers say that by connecting to a standard diagnostic computer port included in late-model cars, they were able to do some nasty things, such as turning off the brakes, changing the speedometer reading, blasting hot air or music on the radio, and locking passengers in the car.
In a late 2009 demonstration at a decommissioned airfield in Blaine Washington, they hacked into a test car's electronic braking system and prevented a test driver from braking a moving car -- no matter how hard he pressed on the brakes. In other tests, they were able to kill the engine, falsify the speedometer reading, and automatically lock the car's brakes unevenly, a maneuver that could destabilize the car traveling high speeds. They ran their test by plugging a laptop into the car's diagnostic system and then controlling that computer wirelessly, from a laptop in a vehicle riding next to the car.
The point of the research isn't to scare a nation of drivers, already made nervous by stories of software glitches, faulty brakes and massive automotive recalls. It's to warn the car industry that it needs to keep security in mind as it develops more sophisticated automotive computer systems.
"We think this is an industry issue," said Stefan Savage, an associate professor with the University of California, San Diego.
He and co-researcher Tadayoshi Kohno of the University of Washington, describe the real-world risk of any of the attacks they've worked out as extremely low. An attacker would have to have sophisticated programming abilities and also be able to physically mount some sort of computer on the victim's car to gain access to the embedded systems. But as they look at all of the wireless and Internet-enabled systems the auto industry is dreaming up for tomorrow's cars, they see some serious areas for concern.
"If there's no action taken on the part of all the relevant stakeholders, then I think there might be a reason to be concerned," Kohno said. Neither he nor Savage would name the maker of the car they conducted their tests on. They don't want to single out any one auto-maker, they said.
That probably comes as a relief to whomever made the car the researchers probed, as they found it pretty easy to hack.
"In starting this project we expected to spend significant effort reverse-engineering, with non-trivial effort to identify and exploit each subtle vulnerability," they write in their paper. "However, we found existing automotive systems—at least those we tested—to be tremendously fragile."

To hack the cars, they needed to learn about the Controller Area Network (CAN) system, mandated as a diagnostic tool for all U.S. cars built, starting in 2008. They developed a program called CarShark that listens in on CAN traffic as it's sent about the onboard network, and then built ways to add their own network packets.
Step-by-step, they figured out how to take over computer-controlled car systems: the radio, instrument panel, engine, brakes, heating and air conditioning, and even the body controller system, used to pop the trunk, open windows, lock doors and toot the horn.
They developed a lot of attacks using a technique called "fuzzing" -- where they simply spit a large number of random packets at a component and see what happens.
"The computer control is essential to a lot of the safety features that we depend on," Savage said. "When you expose those same computers to an attack, you can have very surprising results, such as you put your foot down on a brake pedal and it doesn't stop."
Another discovery: although industry standards say that onboard systems are supposed to be protected against unauthorized firmware updates, the researchers found that they could change the firmware on some systems without any sort of authentication.
In one attack that the researchers call "Self-destruct" they launch a 60 second countdown on the driver's dashboard that's accompanied by a clicking noise, and then finally warning honks in the final seconds. As the time hits zero, the car's engine is killed and the doors are locked. This attack takes less than 200 lines of code -- most of it devoted to keeping time during the countdown.
Hacking a car isn't for the faint-hearted. At several points the team worried it might have come close to permanently damaging the two identical-make cars it experimented with, but that never happened, Kohno said. "You really don't want software to accidentally change critical parts of the transmission," he said.

Sources:
http://www.computerworld.com/s/article/9176778/Car_hackers_can_kill_brakes_engine_and_more?taxonomyId=17&pageNumber=2




Graphics Card Drivers New Target For Cyber Attacks

It seems like nothing is safe from Internet attacks these days after a security consultancy warned that now graphics card drivers could be a new target for cyber hackers. British security consultancy Context disclosed in an advisory Thursday that security issues in WebGL, a browser Web standard designed to bring 3D graphics to Web pages on the Internet could leave users susceptible to denial of service and other cyber attacks.
WebGL is on by default in Firefox 4 and the recently hackable Google Chrome, and can be turned on in the latest versions of Safari.
The security issues enable hackers to execute malicious code on users' computers via a Web browser, which allows attacks on the GPU and graphics drivers that could render the entire machine unusable.
"These issues are inherent to the WebGL specification and would require significant architectural changes in order to remediate in the platform design," security researcher James Forshaw wrote oin the Context advisory.
The problem occurs in the way that the WebGL is implemented, and the way current PC and Graphics Processor architectures are designed, Forshaw said.
Unlike other browser content, WebGL provides direct access to the graphics hardware, employing shader code that's uploaded then executed directly on the system. However, current hardware and graphics pipeline implementations are not designed to maintain security boundaries, experts say.
"Once a display list has been placed on the GPU by the schedule, it can be difficult to stop it, at least without causing obvious, system-wide visual corruption and instabilities," Forshaw wrote.
Subsequently, hackers could obtain access to the hardware drivers by crafting malicious code, and tricking a victim into installing it by opening a malicious Web page or clicking on infected content embedded on a legitimate site.
In addition, the WebGL API's direct access to the hardware also flings the door wide open for denial of service attacks. Unlike typical DoS attacks, in which the user's Web experience is blocked, the WebGL DoS exploit would crash the operating system or prevent users from being able to access their computer.
Windows 7 and Vista are less susceptible to attacks than XP due to the fact that their OS will be forced to reset if the GPU locks up for around two seconds, stopping all applications from using 3D graphics.
In response to Context's advisory, the 3 to 5 Khronos Group, the open standards consortium that maintains WebGL specification, said it has developed a WebGL extension, called OpenGL, GL_ARB_robustness, "specifically designed to prevent denial of service and out-of-range memory access attacks from WebGL content."
Khronos Group says the extension has already been deployed by some GPU vendors, and predicts that it will rapidly gain adoption down the road. "Browsers can check for the presence of this extension before enabling WebGL content. This is likely to become the deployment mode for WebGL in the near future," Khronos Group said on its Web site.
However, Context said that the extension doesn't go far enough to address the issue, noting that resetting the graphics card and driver "should be seen as a crutch to OS stability" and not standard security mechanism.
Ultimately, Context said that WebGL wasn't ready for mass distribution, while recommending that users disable WebGL in their browsers.
"While there is certainly a demand for high-performance 3D content to be made available over the Web, the way in which WebGL has been specified insufficiently takes into account the infrastructure required to support it securely," according to the Context blog. 'Perhaps the best approach would be to design a specification for 3D graphics from the ground up with these issues in mind."



Source:

http://www.crn.com/news/security/229500616/graphics-card-drivers-new-target-for-cyber-atta

Infected Android apps can hijack your texts

Malware found in at least 11 apps can turn your phone into text spammer
At least 11 Android apps contain malware that is rigged to automatically send text messages from your Google Android smartphone to phone numbers in China.
The apps, which include iBook, iCartoon, iGuide, iCalendar, LoveBaby and Sea Ball, are embedded with malicious code that covertly sends text messages to three different premium-rate numbers without their knowledge or approval.
The texts then sign the victims up for paid subscription services, according to AegisLab, the Taiwanese security firm that discovered the corrupt apps.
Google has removed the offending apps, published by "zsone," from the official Android Market, but researchers at the security firm Kaspersky Lab said it's possible the malware, classified as a Trojan because it hides inside software, affects more than the 11 apps AegisLab found.
If so, this would be the latest example in a string of recent Android security slip-ups.
On Tuesday (May 10), the IT company Juniper Networks released a paper that found that malware specifically targeting Android devices has jumped 400 percent since last summer.
In late April, amid the publicity about Apple tracking users locations on their iPhones, it turns out Google does the same thing with its Android customers.
Another April blunder: Skype's Android app was found to contain a security flaw that could be exploited to give hackers access to users' names, email and home addresses and phone numbers.
One from late March: Android.Walkinwat, a pirated copy of Android's legitimate Walk and Text app, harvested users' sensitive data and sent it to an external server.
The real problems, however, really began in early March, when more than 50 free Android apps were found to harbor DroidDream, a particularly nasty Trojan that could steal sensitive data from phones and download malicious code to phones from remote servers.
Coupled with these dangerous Android apps — and the realization that Google may not have as much control over its Android App market as it would like — is the fact that even though smartphone technology and connectivity is increasing, users aren't keeping pace on the security side.
Juniper's paper showed that the "vast majority" of smartphone users — not just Android owners — don't have any antivirus software on their phones, and don't stop to check whether the apps they download come from legitimate sources.



We provide a mobile security app for Android. just call for more info.



Source:

http://www.msnbc.msn.com/id/43032487/ns/technology_and_science-security/