@alexjplaskett I attempted the method on another vehicle's TCU but was unable to trigger a uevent by a file system read. Two methods that did work:
1.Unplugging and replugging the USB cable.
2.echo add > /sys/class/net/lo/uevent
New writeup from @_specters_ and I: we're finally allowed to disclose a vulnerability reported to Kia which would've allowed an attacker to remotely control almost all vehicles made after 2013 using only the license plate.
Full disclosure:
https://t.co/e2EwvUMgqw
The rocket 🚀 continues fly high @offbyoneconf , @delikely delivered another great presentation for car-hacking enthusiasts and fellow offensive security fans with his paper.
Go go go!
Automotive security enthusiasts – don’t miss you chance to meet @delikely, Security Researcher and Tech Lead at QAX STARV Lab at @offbyoneconf
He will be presenting his paper on "Unlocking Automotive Secrets - Strategies and Tool for accessing hidden services"
#carhacking
Fast and Curious: Emulating Renesas RH850 System-on-Chip using Unicorn Engine
Brought to you by @virtualabs and @Phil_BARR3TT to make your automotive vulnerability research easier
https://t.co/hKF2iIHLIg
New blog post is out! Extracting the SecOC keys used for securing the CAN Bus on the 2021+ RAV4 Prime. https://t.co/iWCiZumQCH
Research started all the way in 2022, but took many evenings of reverse engineering to get code execution.
PoC: https://t.co/ZCDH9EaJjm