Auer
Well-Known Member
- Thread starter
- #1
Not a Slate thing but here it is:
https://www.devdigest.org/articles/2m-cars-hackable-via-hidden-karr-alarm-patch-now
Over 2 Million Cars Have a Hidden, Hackable Alarm
A team of security researchers at UC San Diego has uncovered a severe vulnerability in the KARR Security System, an aftermarket car alarm installed in more than 2 million vehicles across the US. The flaw allows any attacker within Bluetooth range to unlock the car, disable the ignition, or trigger the horn and lights—all without any physical access. The device is typically installed by car dealers without the buyer's knowledge, and remains in the vehicle even if the buyer declines to pay for it.
The Flaw: A Single Shared Authentication Key
The root cause is a single authentication key shared across all KARR devices. The researchers found this key hardcoded in the KARR smartphone app. By reverse-engineering the app, they created a proof-of-concept Android app that spoofs radio commands accepted by any nearby KARR device.
> "Once we reverse-engineered their application, we quickly realized after understanding their internal authentication protocol that it was so simple that we could extract it and re-implement it as our own application," said Jerry Yu, the graduate researcher who led the analysis.
The key allows the attacker to send commands to unlock doors, disable the ignition (preventing the car from starting), and trigger the horn or lights. The device remains beaconing and accepting Bluetooth signals for up to 10 minutes after the car is turned off, expanding the attack window.
Impact: Theft, Tracking, and Mayhem
The researchers demonstrated multiple attack scenarios:
Additionally, the Bluetooth beacon from the KARR device can be used to track a car's location over time. The researchers used the open-source WiGLE database to estimate the number of affected vehicles and found that they could locate vulnerable cars virtually anywhere.
Also at Wired:
https://www.wired.com/story/a-devic...rable-to-hacking-and-paralysis-patch-it-now/?
https://www.devdigest.org/articles/2m-cars-hackable-via-hidden-karr-alarm-patch-now
Over 2 Million Cars Have a Hidden, Hackable Alarm
A team of security researchers at UC San Diego has uncovered a severe vulnerability in the KARR Security System, an aftermarket car alarm installed in more than 2 million vehicles across the US. The flaw allows any attacker within Bluetooth range to unlock the car, disable the ignition, or trigger the horn and lights—all without any physical access. The device is typically installed by car dealers without the buyer's knowledge, and remains in the vehicle even if the buyer declines to pay for it.
The Flaw: A Single Shared Authentication Key
The root cause is a single authentication key shared across all KARR devices. The researchers found this key hardcoded in the KARR smartphone app. By reverse-engineering the app, they created a proof-of-concept Android app that spoofs radio commands accepted by any nearby KARR device.
> "Once we reverse-engineered their application, we quickly realized after understanding their internal authentication protocol that it was so simple that we could extract it and re-implement it as our own application," said Jerry Yu, the graduate researcher who led the analysis.
The key allows the attacker to send commands to unlock doors, disable the ignition (preventing the car from starting), and trigger the horn or lights. The device remains beaconing and accepting Bluetooth signals for up to 10 minutes after the car is turned off, expanding the attack window.
Impact: Theft, Tracking, and Mayhem
The researchers demonstrated multiple attack scenarios:
- Silent Unlock: Unlock a car at a stoplight to enable theft or carjacking.
- Ignition Disable: Paralyze a parked car so it won't start.
- "Mayhem" Mode: Hack multiple cars to simultaneously honk and flash lights.
Additionally, the Bluetooth beacon from the KARR device can be used to track a car's location over time. The researchers used the open-source WiGLE database to estimate the number of affected vehicles and found that they could locate vulnerable cars virtually anywhere.
Also at Wired:
https://www.wired.com/story/a-devic...rable-to-hacking-and-paralysis-patch-it-now/?
Last edited: