HomeSecurityMercedes-Benz: Hackers can control vehicles remotely

Mercedes-Benz: Hackers can control vehicles remotely

Qihoo 360's Sky Go Team , a car hacking group , identified over a dozen vulnerabilities in a Mercedes -Benz E-Class car , which allowed them to open the doors and start the engine remotely .

Mercedes
Mercedes-Benz: Hackers can control vehicles remotely

Many will still remember 2015, when securityCharlie Miller and Chris Valasek remotely hacked a Jeep on a highway.

Most modern cars are equipped with connectivity , giving passengers access to entertainment and navigation, as well as more radio stations. But connecting a car to the internet puts it at greater risk of remote hacking attacks.

Although vehicle security has improved over the past half decade, Sky-Go researchers have shown that even one of the latest Mercedes-Benz models is not immune to attacks.

In a speech this week, Minrui Yan, head of Sky-Go's security research team, said the 19 security vulnerabilities have now been patched, but could have affected up to two million Mercedes-Benz-linked cars in China.

Katharina Becker, a spokeswoman for Mercedes parent company Daimler, pointed to a statement the company issued late last year after it fixed the safety issues. The spokeswoman said Daimler could not confirm the estimated number of affected vehicles.

"We addressed what was identified and fixed all vulnerabilities that could be exploited before any vehicles on the market were affected," the spokeswoman said.

After more than a year of research, the end result was a series of "vulnerabilities," resulting in an attack sequence that could remotely control the vehicle.

Initially, the researchers created a testbed to reverse engineer the car's components and look for vulnerabilities, scrapping the car's software and analyzing the car's internals for vulnerabilities

The researchers then tested a Mercedes E-Series car to verify their findings.

At the center of the research is the E-Series telematics control unit, or TCU, which Yan says is the car's "most critical" component, as it allows the vehicle to communicate with the internet.

By compromising the TCU file system, researchers have access to the highest level of access controls to the vehicle's interior. With this access, researchers could remotely open the doors of the Mercedes car.

The TCU file system also stores the car’s “secrets,” such as passwords and certificates, which protect the vehicle from being accessed or modified without proper authorization. Of course, the researchers were able to extract the passwords of several certificates for various regions, including Europe and China. By obtaining the vehicle’s certificates and passwords, they could gain deeper access to the vehicle’s internal network. The car’s certificate for the China region had a weak password, Yan said, making it easier to hack.

Yan said the goal was to gain access to the car's backend, which is the core of the vehicle's internal network. Since the backend can be accessed externally, the car is vulnerable to attacks, the researchers said.

mercedes vulnerabilities
Mercedes-Benz: Hackers can control vehicles remotely

The way they did it was by hacking the vehicle's built-in SIM card, which allows the car to talk to mobile networks. A security feature meant that the researchers couldn't plug the SIM card into a router without freezing access to the mobile network. The researchers modified their router to spoof the Mercedes vehicle, making the network think it was the car.

With the firmware being dropped, its networking protocols being understood, and its certificates being obtained and broken, they say they could remotely control a vehicle.

They also stated that the car's security design was tough and capable of withstanding various attacks, but it was not impenetrable.

“Keeping every back-end component secure all the time is difficult,” the researchers said. “No company can do it perfectly.”

But at least in the case of Mercedes-Benz, its cars are much safer, and certainly with fewer security vulnerabilities, than they were a year ago.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS