Your BMW Can Be Stolen with a $30 Hacking Kit

Discussion in 'News Aggregator' started by Mr. Penguin, 30 Sep 2012.

  1. Mr. Penguin

    Mr. Penguin Administrator
    Staff Member VIP Admin

    18 May 2012
    Likes Received:
    On-board diagnostics (OBD) security bypass kits, replete with reprogramming modules and blank keys, are reportedly enabling low-intelligence thieves to steal high-end cars such as BMWs in a matter of seconds or minutes.

    According to Login or Signup to view links / downloads the $30 bypass tools are being shipped from China and Eastern Europe in kit form to unskilled criminals. It looks like it's not just BMWs, mind you.

    A post on the car enthusiast site Login or Signup to view links / downloads suggests that devices similar to those used to steal BMWs are also available for Opel, Renault, Mercedes, Volkswagen, Toyota and Porsche Cayennes. UK police are also seeing fancy cars whisked away by criminals believed to be using the kits, with the deprived owners still having the keys in their possession. It's becoming so prevalent, in fact, that Warwickshire police released a Login or Signup to view links / downloads warning BMW owners to take extra precautions, stating that 154 of the high-end cars have been stolen since January.

    In August, London's Metropolitan Police left leaflets under windscreens, warning BMW owners their cars were likely to be targeted, according to a recent Login or Signup to view links / downloads into the thefts.

    The tool was originally designed for garages and car recovery agents to get into different cars after owners had lost their keys. The kits have since been packaged up by criminal hackers, who have picked apart the security weaknesses of the OBD network.

    To use the tool, car thieves first need to intercept the transmission between a valid key fob and a car before they can then reprogram the blank key, which they can then use to start or open the car via the OBD network.

    The BBC rolled its camera skyward while its news reporters were using the key in its Watchdog investigation, but I found online videos showing how easy it is to use the tool - or, at least, a device that fits the tool's description.

    If the video I found is an accurate depiction, even the village idiot could be behind the wheel of a fine ride with a $30 investment and a few minutes.
    (By the way, Naked Security has chosen not to embed the video because it may encourage criminal activity, and we have no wish to promote sales of such tools to unauthorised parties)

    BMW last week put out Login or Signup to view links / downloads saying it's aware of the new method of car thievery and is looking into how to mitigate it.

    One way is to not own a BMW built before September 2011, apparently:
    So what are the security holes in OBD?
    As pointed out by Rob VandenBrink in a Login or Signup to view links / downloads (PDF) delivered at a SANS Technology Institute security conference in July, OBD looks like "a slower, dumber Ethernet (sorta)." For details on those weaknesses, check out his paper.
    In summary, VandenBrink says:
    But wait, there's more. Short of allowing your ride to be stolen, security researchers at the University of Michigan and the University of Washington have shown that OBD shortcomings allow these other automotive WiFi shenanigans:
    This stuff isn't new. The CD Trojan piece goes back to 2011.

    What's new is how erudite hacker knowledge of OBD's limitations has been commoditized and marketed in these easy-to-use, cheap kits.

    Should you shake down your car manufacturer to get better defences?
    Unfortunately, it probably won't do you much good if you do, between the need for mechanics to have some type of tool to get into your car and competition laws requiring open standards. Here's what the Login or Signup to view links / downloads had to say about it.
    What you can do: contact your car dealer to see if they have mitigation techniques that will help, as BMW promises. The Warwickshire Police also offer these safety tips, although they are unlikely to be much of a deterrent to a determined ODB hacker who gains access to your vehicle:
    • Try the door handle after using your key to lock your car, to double check that it is actually locked.
    • Take a good look around when leaving the vehicle to see if you can spot anyone waiting nearby or in a vehicle in the vicinity, especially if you check and find the door to still be open.
    • Report anything suspicious to the police: they want to nab these guys.
    Ultimately, it's worth remembering - as BMW admits - that there's "no such thing as an unstealable car".

    Original Article @ NakedSecurity. Sophos: Login or Signup to view links / downloads
    • Like Like x 2
  2. Crackerz Wave

    Crackerz Wave The Dictator

    20 May 2012
    Likes Received:
    oh vid
  3. emon11

    emon11 Well-Known Member

    29 Jun 2012
    Likes Received:
    • Like Like x 4
  4. Hagiz

    Hagiz Member

    3 Oct 2012
    Likes Received:
    Well, used to tell my parents nothin' can truly be a hundred % secure. Now I got proof :D

    Dad... about that car. I'm gonna take it. Whether you like it or not. Just because I can.
    And a rebell yell to that :D
  5. Senegal

    Senegal New Member

    17 Oct 2012
    Likes Received:
  6. rempit

    rempit Well-Known Member

    4 Jun 2012
    Likes Received:
    How about converting this BMW Programming Kit into TinyCore Linux ? ...and then upload here :joy
  • About Us

    We are a community mixed with professionals and beginners with an interest in wireless security, auditing and pentesting. Feel free to check out and upload resources.

    You can also find us on: Twitter and Facebook

  • Donate to Us

    Did you find our forums useful? Feel free to donate Bitcoin to us using the form below. Those who donate the equivlent of $10 USD or more will be upgraded to VIP membership. Don't have Bitcoin? Use your credit card to GO VIP here. Don't want to fork out some coin? There are other ways to GO VIP. Bitcoin: 1LMTGSoTyJWXuy2mQkHfgMzD7ez74x1Z8K