Slashdot Mirror


You Can Hack Some Mazda Cars With a USB Flash Drive (bleepingcomputer.com)

An anonymous reader writes: "Mazda cars with next-gen Mazda MZD Connect infotainment systems can be hacked just by plugging in a USB flash drive into their dashboard, thanks to a series of bugs that have been known for at least three years," reports Bleeping Computer. "The issues have been discovered and explored by the users of the Mazda3Revolution forum back in May 2014. Since then, the Mazda car owner community has been using these 'hacks' to customize their cars' infotainment system to tweak settings and install new apps. One of the most well-designed tools is MZD-AIO-TI (MZD All In One Tweaks Installer)." Recently, a security researcher working for Bugcrowd has put together a GitHub repository that automates the exploitation of these bugs. The researcher says an attacker can copy the code of his GitHub repo on a USB flash drive, add malicious scripts and carry out attacks on Mazda cars. Mazda said the issues can't be exploited to break out of the infotainment system to other car components, but researchers disagreed with the company on Twitter. In the meantime, the car maker has finally plugged the bugs via a firmware update released two weeks ago.

33 of 52 comments (clear)

  1. Plugged the bugs? by MangoCats · · Score: 2

    Or, blocked the feature? Isn't this "bug" equivalent to shipping the car with an "unlocked" infotainment device?

    1. Re:Plugged the bugs? by someone1234 · · Score: 1

      Or a jobless security researcher who needs some fame and doesn't care about the 'hackers' who just used their cars for more fun.

      --
      Patents Drive Free Software as Hurricanes Drive Construction Industry
    2. Re:Plugged the bugs? by Anonymous Coward · · Score: 1

      This is the essence of "computer security" "research": Make scary noises in hopes it gets you consulting monies and damn the consequences. This constant scaremongering has helped bring into being things like laws that criminalise "computer hacking" without defining what that might be and judges that conclude that calling yourself a "hacker" means you give up your fourth amendment rights.

      I'm now waiting for the hammer to fall on the hobbyists tinkerers because by calling this "hacking" the tinkerers are now "hackers" and therefore guilty of "computer hacking", because even an on-board computer is a computer and thus a protected device under that shoddy bad "computer hacking" law. Though it might be easier to simply shout "DMCA violation", which refers to a different but similarly bad law.

      Anyway, plenty of stupidity to go around, from everybody surrounding and even only tenuously and remotely connected to the computing field. But that the so-called "experts" see fit to pour oil on the fires themselves is pretty damning, yes.

  2. Enable features by CanEHdian · · Score: 1

    This is of course great stuff if it allows you to enable features that are normally locked out unless you paid handsomely for the "upgrade". As an example, DVD-Burners are sometimes identical to their LightScribe-brethern except for the firmware. Flash the correct firmware and poof! Your cheap OEM drive is now a branded Retail unit with everything unlocked.

    --
    When the copyright term is "forever minus a day", live every day like it's the last.
  3. wtf by Anonymous Coward · · Score: 1

    ummm nearly every brand and model has forums devoted to hacking/changing/upgrading the infotainment system, why the fuck is this even news?

  4. Well, I feel better by Snotnose · · Score: 1

    Knowing that newbies to the security scene are pretty much clueless and marketing is driving things.

    1. Re:Well, I feel better by phantomfive · · Score: 1

      Every computer can be hacked by inserting a USB 'drive.' USB is not secure, don't let anything untrusted near it.

      Other than that, I share your concern.

      --
      "First they came for the slanderers and i said nothing."
  5. This is a repeat from the mid 70's to early 90's by Snotnose · · Score: 2, Informative

    The gas crisis hit. Cars suddenly had to hit smog standards. At the same time mandatory seat belt laws came into effect. The result was poorly performing cars with pain in the ass seatbelt restraints. I had an '87 Ford Escort, with a shoulder harness that slid along a track. It sucked. As did the car. In every possible way. As in, replacing all light bulbs within 2 years. Rear seat floor rusting out after 4 years (Just past warranty) (In San Diego, no salted roads). Sold it at 80k miles cuz of fan belt squeal. Caused by a crankshaft pulley way off center that would take an engine rebuild to fix.

    Back then they shaved corners off everything they could, hence shitty cars. Now, they're using shitty firmware that is going to make the cars seriously avoidable for a good 10 years, until they wrap they're hide bound necks around software and security.

    / That '87 Ford Escort?
    // biggest pile of shit I've ever driven
    /// I'll probably never buy another American car again (I'm 59 in 3 weeks, YMMV).

  6. Malicious, maybe - but more like jailbreaking by djrobxx · · Score: 1

    The "all in one" tool they refer to is very much like a jailbreaking tool. It lets you pick from a list of popular hacks, and makes it easy to install.

    One of the more interesting hacks available is enabling Android Auto support. Mazda is using a system called OpenCar.

    These "exploits" that get you access are really simple ones. Mazda obviously didn't consider them to be of big concern, they've been around for quite a while. Then of course the security zealots come in and ruin all the fun. :)

    Will be more interesting to see if the Mazda dealers try to force this update on you. I imagine people will want to update anyway, there are still some really glaring bugs in their infotainment system (maps crashing, spurious restarting of USB playlists, etc).

  7. "Hacked" mine by Anonymous Coward · · Score: 1

    I followed forum instructions and got a USB network adapter. Then SSH'd in as root and turned off a few annoyances. I thought I was cool ;)

  8. That's why I'm sticking with my 1971 Datsun 240Z by halfdan+the+black · · Score: 1

    It's an absolute blast to drive, those triple dual throat carburetors just freaking scream, it actually feels alive. Unlike to soulless crap that's sold today that's all larded up with electronics crap.

  9. Mazda is not GPL compliant by Anonymous Coward · · Score: 5, Interesting

    Their infotainment center is full of GPL code and Mazda is not in compliance: https://mzdopensource.wordpress.com/

    (Their infotainment contains a gstreamer, busybox, modified Linux kernel, and probably other GPL software.)

  10. Is it really hacking? by Spy+Handler · · Score: 1

    I mean, if you have to break the window of the car or jimmy the door open, and then physically insert a flash drive into the USB port on the dashboard, that's a pretty loose definition of "hack".

    If you were willing to go this far and risk burglary rap, might as well just drive off with the car and sell it to the chop shop rather than simply leaving a malware on the infotainment system.

    1. Re:Is it really hacking? by Calydor · · Score: 1

      If you can use this to turn off tracking systems like OnStar, it's actually a pretty big deal. There was some disagreement of whether you could break out of the infotainment system to the rest of the car's systems.

      And surveillance. Imagine if you didn't have to plant a microphone somewhere in the car, but could actually install a recording app in the car's own systems.

      --
      -=This sig has nothing to do with my comment. Move along now=-
    2. Re:Is it really hacking? by sunderland56 · · Score: 1

      If I break into a car, I can:

        - possibly attack it via USB; limited ability to hack, on limited car makes and models

        - plug a laptop into the car's OBD port and have complete, total access to the entire car, on every car on the planet

      Why would I be concerned about USB, when you can reprogram all of the car's computers via OBD?

    3. Re:Is it really hacking? by Zero__Kelvin · · Score: 1

      Well, you could just use your key. No need to break windows or jimmy locks. Guessing you don't know what the term "hack" means.

      --
      Guns don't kill people; Physics kills people! - John Lithgow as Dick Solomon on Third Rock From The Sun
    4. Re:Is it really hacking? by Zero__Kelvin · · Score: 1

      OBD access doesn't afford access to the entire car, at least in almost all cases. It provides access to the ODB CAN Controller, and sometimes but not always more of the system. The fact that you believe you automagically have access to the entire car tells me you really can't do what you claim.

      --
      Guns don't kill people; Physics kills people! - John Lithgow as Dick Solomon on Third Rock From The Sun
    5. Re:Is it really hacking? by sunderland56 · · Score: 1

      The manufacturers I'm familiar with allow firmware updates over OBD2. So if you can't get access to something with stock firmware, flash a new version that does allow it.

      (Assuming that there is connectivity in the first place; if e.g. the entertainment system only connects to 12V and ground, there won't be a remote hack).

    6. Re:Is it really hacking? by Zero__Kelvin · · Score: 1

      Initially you claimed on every car on the planet, but now you are limiting the field quite narrowly aren't you? You would have to have the source and capabilities to build a modified firmware as well, narrowing the field to almost zero. Suddenly your claim that you can plug a laptop into the car's OBD port and have complete, total access to the entire car, on every car on the planet is quite absurd indeed, isn't it?

      --
      Guns don't kill people; Physics kills people! - John Lithgow as Dick Solomon on Third Rock From The Sun
    7. Re:Is it really hacking? by sunderland56 · · Score: 1

      This is a geek site. I didn't think I needed to add the disclaimer "with the right kind of knowledge".

      You need the right kind of knowledge to do anything with the USB port as well. Just sticking in a USB stick with "ABBA's Greatest Hits" on it won't work. (Well, maybe in a Volvo.....)

  11. That probably isn't actually a security problem... by Casandro · · Score: 1

    ... as if you need to have physical access to the inside of a car in order to change its firmware, that's a much more intrusive vector than just cutting the brake lines.

    People stop claiming that normal intended features are security critical bugs. Locking people out of the computers they bought is not fixing anything. In fact with routers, blocking OpenWRT usually means that your users won't be able to make their system more secure.

  12. FORD equivalent by a Russian dev... by ELCouz · · Score: 1
  13. Re:This is a repeat from the mid 70's to early 90' by swb · · Score: 1

    Uhh, isn't San Diego on the ocean, that big body of water filled with salt? Might the salt air have added to your corrosion problems?

    Other than that, I agree that Detroit had a lot of problems in the 1980s. Labor problems, economic problems, probably engineering challenges totally overhauling entire product lines to try to compete with smaller and more fuel efficient foreign models.

    What's funny is that I would have thought Ford would have been able to adapt easier because of their extensive experience in Europe. I know at some point in the 1980s they were actually selling some European models in the US.

  14. Re:I love the naievity by AmiMoJo · · Score: 1

    Actually, there are CAN bus firewalls. For example, the diagnostic port is usually firewalled to be mostly read only.

    --
    const int one = 65536; (Silvermoon, Texture.cs)
    SJW, n: "Someone I don't like, and by the way I'm a fuckwit" - AC
  15. Qstn: Where can I find similar tweaks 4 my Toyota? by BcNexus · · Score: 1

    I must have poor google-fu or something. I've searched Google and Reddit off and on but haven't found anything useful (searched my infotainment unit model number, browsed forums and posts, searched for "tweaks" and "hacking" but didn't find anything useful).

    I have a 2014 Corolla with a non-GPS, non-streaming-app, touchscreen infotainment system.

  16. Re:This is a repeat from the mid 70's to early 90' by Dogtanian · · Score: 1

    The result was poorly performing cars with pain in the ass seatbelt restraints.

    Those must have been really badly fitting seatbelts if they hurt you there.

    --
    "Slashdot - News and Chat Sites Deviant". (Click "homepage" link above for details).
  17. Re:This is a repeat from the mid 70's to early 90' by danomac · · Score: 1

    He forgot to mention the seats had springs poking through the upholstery. So when the seat belt auto-tightened on the track, it literally became a pain in the ass!

  18. Re:This is a repeat from the mid 70's to early 90' by Dogtanian · · Score: 1

    I know at some point in the 1980s they were actually selling some European models in the US.

    From what I've read, the original version of the North American Escort (presumably the one referred to above) was *supposed* to be based on the 1980 third-generation European Escort, but in practice ended up having little in common with it beyond a vaguely similar shape.

    (This was apparently also the case with the Chrysler Horizon; the Dodge Omni and Plymouth Horizon apparently shared little with their European counterpart).

    --
    "Slashdot - News and Chat Sites Deviant". (Click "homepage" link above for details).
  19. Can it run Doom? by keith_nt4 · · Score: 1

    That's all I want to know. Because a Porsche 911 definitely can...

    --
    "UNIX is very simple, it just needs a genius to understand its simplicity." -Dennis Ritchie
  20. Protect! by Dishevel · · Score: 2

    Need to protect people from replacing shitt GPS Navigators with Google Maps.

    --
    Why is it so hard to only have politicians for a few years, then have them go away?
  21. Re:That's why I'm sticking with my 1971 Datsun 240 by TechyImmigrant · · Score: 1

    It's an absolute blast to drive, those triple dual throat carburetors just freaking scream, it actually feels alive. Unlike to soulless crap that's sold today that's all larded up with electronics crap.

    I have a younger sibling of that car. The 350Z convertible. It's also a blast to drive and doesn't appear to be weighed down with electronics.

    --
    I should use this sig to advertise my book ISBN-13 : 978-1501515132.
  22. Re:That's why I'm sticking with my 1971 Datsun 240 by halfdan+the+black · · Score: 1

    The 350z is a great car, everyone is saying that it's destined to become a future classic, unlike the 370. The 350 has nice, clean, conservative lines as opposed to the tacky, gaudy 370. Nissan really started hitting the crack coccaine prety hard in their styling dept around 2009.

    I'm just hoping Nissan will get over their current styling fugue state and get back to something decent before they roll out the next Z car.

  23. Re:That's why I'm sticking with my 1971 Datsun 240 by TechyImmigrant · · Score: 1

    FWIW, Mazda went off the rails with the current MX5 styling too. I've had two MX5s (the pop up headlights one and the one after that) and they were both looked great. The high price and the fussy exterior steered me away from the MX5 this time around.

    My Z is bright orange, which was a significant factor in my choice. Convertible of course.

    --
    I should use this sig to advertise my book ISBN-13 : 978-1501515132.