A GPS hack was detected in the iTrack and Protrack navigation apps and allows you to remotely turn off your car's engines with the push of a button.
The hacker behind this discovery goes by the name L&M and is using this exploit to expose vulnerabilities in security systems car. He has no intention of causing any real harm.
GPS Hack: How to do it
According to L&M, the exploit in these apps mainly involves weak default passwords and built-in functionality from manufacturers.
Most of these GPS tracking apps come with the default password “123456” and most users don’t change it. Once hackers realize this, they will exploit it.

L&M was able to successfully crack several accounts with ease and obtained complete information about the user's location. In some cases, the hacker gained access to the username, email, phone number, physical home address, and more.
According to a leaked screenshot and confirmation from Concox, whose hardware is used by Protrack and iTrack, the car's engine can be turned off remotely. If the car is running at 20km/h (12 mph) or if it is stopped for a few seconds due to traffic, its engine can be easily turned off using this GPS hack.
The hacker tested the exploit in several countries including India, the Philippines, South Africa, etc.
The hardware used in ProTrack is made by a company in China called iTryBand Technology, while iTrack is made by SEEWORLD, also based in China. It is believed that the ability to turn off the car engine is built into the hardware by the manufacturers themselves. Furthermore, the apps do not inform their users about their weak codes when they connect.
If you have one of these two apps, try the password “123456” to see if any security changes have been made.
In the iTrack app, there was no warning that the password was weak or could be exploited. On the other hand, in the ProTrack app, users were immediately informed that the password was at risk.
