Close Menu
Indo Guard OnlineIndo Guard Online
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
What's Hot

Invitation to Disagreement Link from ASYNCRAT and SKULD Theft, focused on cry

June 14, 2025

More than 269 000 sites infected with malicious JSFiretruC JavaScript software in one month

June 13, 2025

Transition from Monitoring Alert to Risk Measurement

June 13, 2025
Facebook X (Twitter) Instagram
Facebook X (Twitter) Instagram YouTube
Indo Guard OnlineIndo Guard Online
Subscribe
  • Home
  • Cyber Security
  • Risk Management
  • Travel
  • Security News
  • Tech
  • More
    • Data Privacy
    • Data Protection
    • Global Security
Indo Guard OnlineIndo Guard Online
Home » Hackers were able to remotely control Kia cars using only license plates
Global Security

Hackers were able to remotely control Kia cars using only license plates

AdminBy AdminSeptember 26, 2024No Comments3 Mins Read
Remotely Controlled Kia Cars
Share
Facebook Twitter LinkedIn Pinterest Email Copy Link


September 26, 2024Ravi LakshmananAutomotive industry / technology

Kia cars with remote control

Cybersecurity researchers discovered a series of vulnerabilities in Kia vehicles, now patched, that, if successfully exploited, could have allowed key functions to be remotely controlled simply by using just a number plate.

“These attacks could be performed remotely on any vehicle equipped with the hardware in about 30 seconds, regardless of whether it had an active Kia Connect subscription,” security researchers Naika Rivera, Sam Currie, Justin Rinehart and Ian Carroll said.

The problems affect nearly all cars manufactured after 2013, even allowing attackers to secretly access sensitive information, including a victim’s name, phone number, email address and physical address.

Cyber ​​security

Essentially, an adversary can abuse this to add themselves as an “invisible” second user of the vehicle without the owner’s knowledge.

The gist of the investigation is that the issues use Kia’s dealership infrastructure (“kiaconnect.kdealer(.)com”), which is used to activate the vehicle, to register a fake account via an HTTP request and then generate access tokens.

The token is then used in conjunction with another HTTP request to the dealer’s APIGW endpoint and the Vehicle Identification Number (VIN) to retrieve the vehicle owner’s name, phone number, and email address.

What’s more, the researchers discovered that gaining access to a victim’s vehicle could be as simple as sending four HTTP requests and ultimately executing Internet Car commands –

  • Create a dealer token and get the “token” header from the HTTP response using the above method
  • Get the victim’s email address and phone number
  • Change previous owner access using email address and VIN to add attacker as primary account owner
  • Add the attacker to the victim vehicle by adding an email address under their control as the primary owner of the vehicle, allowing them to run arbitrary commands

“There was no notification from the victim that their vehicle was accessed, and their access permissions were not changed,” the researchers noted.

Cyber ​​security

“An attacker can decipher someone’s license plate, enter their VIN through an API, then passively track them and send active commands such as unlock, start, or beep.”

Kia cars with remote control

In a hypothetical attack scenario, an attacker could enter a Kia’s license plate number on a special dashboard, get the victim’s information, and then execute commands on the car in about 30 seconds.

After a responsible disclosure in June 2024, the flaws were fixed by Kia as of August 14, 2024. There is no evidence that these vulnerabilities were ever exploited in the wild.

“Cars will still have vulnerabilities, because in the same way that Meta could make code changes that would allow someone to take over your Facebook account, car manufacturers could do the same to your car,” the researchers said .

Did you find this article interesting? Follow us Twitter  and LinkedIn to read more exclusive content we publish.





Source link

Share. Facebook Twitter Pinterest LinkedIn Tumblr Email Copy Link
Admin
  • Website

Related Posts

Invitation to Disagreement Link from ASYNCRAT and SKULD Theft, focused on cry

June 14, 2025

More than 269 000 sites infected with malicious JSFiretruC JavaScript software in one month

June 13, 2025

Transition from Monitoring Alert to Risk Measurement

June 13, 2025

Band

June 13, 2025

Apple Zero Click’s downside in reports to spy on journalists using spyware Paragon software

June 13, 2025

Both Vextrio and affiliates control the global network

June 12, 2025
Add A Comment
Leave A Reply Cancel Reply

Loading poll ...
Coming Soon
Do You Like Our Website
: {{ tsp_total }}

Subscribe to Updates

Get the latest security news from Indoguardonline.com

Latest Posts

Invitation to Disagreement Link from ASYNCRAT and SKULD Theft, focused on cry

June 14, 2025

More than 269 000 sites infected with malicious JSFiretruC JavaScript software in one month

June 13, 2025

Transition from Monitoring Alert to Risk Measurement

June 13, 2025

Band

June 13, 2025

Apple Zero Click’s downside in reports to spy on journalists using spyware Paragon software

June 13, 2025

Both Vextrio and affiliates control the global network

June 12, 2025

How to Decide Safety Expanding

June 12, 2025

The new tokenbreak attack combines AI moderation with a one -sided character change

June 12, 2025
About Us
About Us

Provide a constantly updating feed of the latest security news and developments specific to Indonesia.

Facebook X (Twitter) Pinterest YouTube WhatsApp
Our Picks

Invitation to Disagreement Link from ASYNCRAT and SKULD Theft, focused on cry

June 14, 2025

More than 269 000 sites infected with malicious JSFiretruC JavaScript software in one month

June 13, 2025

Transition from Monitoring Alert to Risk Measurement

June 13, 2025
Most Popular

In Indonesia, crippling immigration ransomware breach sparks privacy crisis

July 6, 2024

Why Indonesia’s Data Breach Crisis Calls for Better Security

July 6, 2024

Indonesia’s plan to integrate 27,000 govt apps in one platform welcomed but data security concerns linger

July 6, 2024
© 2025 indoguardonline.com
  • Home
  • About us
  • Contact us
  • Privacy Policy

Type above and press Enter to search. Press Esc to cancel.