DEF CON 27 - XiaoHuiHui - All the 4G Modules Could Be Hacked

  Переглядів 723

HackersOnBoard

HackersOnBoard

4 роки тому

Nowadays more and more 4G modules are built into IoT devices around the world, such as vending machines, car entertainment systems, laptops, advertising screens, and urban cameras etc. But no one has conducted a comprehensive security research on the 4G modules. We carried out this initiative and tested all the major brand 4G modules in the market (more than 15 different types). The results show all of them have similar vulnerabilities, including remote access with weak passwords, command injection of AT Command/listening services, OTA upgrade spoofing, command injection by SMS, and web vulnerability. Through these vulnerabilities we were able to get to the shell of these devices. In addition to using wifi to exploit these vulnerabilities, we created a new way to attack through fake base station system, triggered by accessing the intranet of cellular network, and successfully run remote command execution without any requisites. In this talk, we will first give an overview on the hardware structure of these modules. Then we will present the specific methods we use in vulnerability probe. In the final section we will demonstrate how to use these vulnerabilities to attack car entertainment systems of various brands and get remote control of cars.

КОМЕНТАРІ
Эта Мама Испортила Гендер-Пати 😂
00:40
Глеб Рандалайнен
Переглядів 8 млн
Best OS for programming? Mac vs Windows vs Linux debate settled
8:41
Corel Linux - The (Word)Perfect Operating System
25:40
Michael MJD
Переглядів 124 тис.
DEF CON 27 - WillC - Phreaking Elevators
40:00
HackersOnBoard
Переглядів 2,1 тис.
DEF CON 27 - Xiling Gong - Exploiting Qualcomm WLAN and Modem Over The Air
32:26
DEF CON 27 - Patrick Wardle - Harnessing Weapons of Mac Destruction
48:51
HackersOnBoard
Переглядів 1,1 тис.
Do 10 things that don’t scale - Paul Graham
8:09
Academy of Product Management
Переглядів 20 тис.
Hacking Car Key Fobs with SDR
5:01
LufSec Cyber Security
Переглядів 116 тис.
🤯Самая КРУТАЯ Функция #shorts
0:58
YOLODROID
Переглядів 3,2 млн
Apple ХОЧЕТ, чтобы iPhone ЛОМАЛИСЬ чаще?
0:47
ÉЖИ АКСЁНОВ
Переглядів 342 тис.
APPLE УБИЛА ЕГО - iMac 27 5K
19:34
ЗЕ МАККЕРС
Переглядів 77 тис.
На iPhone можно фоткать даже ночью😳
0:30
GStore Mobile
Переглядів 915 тис.