We went over the fourth phase of the cyber kill chain: Exploitation. Rushabh first presents an overview of exploitation, with some examples of real-world exploits and attack vectors, and then Nemi gives a demo of a simulated vehicle being taken over by an attacker.
Timestamps:
00:00 Presentation
17:10 Interlude
19:43 Demo
Links:
17:45 - https://googleprojectzero.blogspot.co...
18:22 - https://citizenlab.ca/2021/09/forcede...
Instrument Cluster simulator: https://github.com/zombieCraig/ICSim
can-utils: https://github.com/linux-can/can-utils
(can-utils is typically available via package managers)
There are also GUI CAN tools available, and you can connect it to a DB to decode CAN signals.
Most signals are manufacturer-specific, and you won't easily find a DB (open-source community has some insight). But some classes of vehicles (like heavy duty) have standardized CAN signals and their databases can be bought (SAE J1939).
-- std_disclaimer.h --
This content is for educational purposes only!
We do not condone the use of any information conveyed in our videos for any illegal or unethical purposes, regardless of intent.