DEF CON 27 - XiaoHuiHui - All the 4G Modules Could Be Hacked

  Рет қаралды 738

HackersOnBoard

HackersOnBoard

4 жыл бұрын

Nowadays more and more 4G modules are built into IoT devices around the world, such as vending machines, car entertainment systems, laptops, advertising screens, and urban cameras etc. But no one has conducted a comprehensive security research on the 4G modules. We carried out this initiative and tested all the major brand 4G modules in the market (more than 15 different types). The results show all of them have similar vulnerabilities, including remote access with weak passwords, command injection of AT Command/listening services, OTA upgrade spoofing, command injection by SMS, and web vulnerability. Through these vulnerabilities we were able to get to the shell of these devices. In addition to using wifi to exploit these vulnerabilities, we created a new way to attack through fake base station system, triggered by accessing the intranet of cellular network, and successfully run remote command execution without any requisites. In this talk, we will first give an overview on the hardware structure of these modules. Then we will present the specific methods we use in vulnerability probe. In the final section we will demonstrate how to use these vulnerabilities to attack car entertainment systems of various brands and get remote control of cars.

Пікірлер
小女孩把路人当成离世的妈妈,太感人了.#short #angel #clown
00:53
Which one of them is cooler?😎 @potapova_blog
00:45
Filaretiki
Рет қаралды 6 МЛН
$10,000 Every Day You Survive In The Wilderness
26:44
MrBeast
Рет қаралды 136 МЛН
T SQL For XML PATH Group By as Attribute or Element
4:16
Luke Chaffey
Рет қаралды 3
What's New in Data Governance and Catalog - April 2024
4:02
Informatica Support
Рет қаралды 23
Raspi5-NVMe機 PiBenchmarks を動作させてみた・・・
4:19
Shonanwalker~Beat-On@PC~
Рет қаралды 8
A Software Defined Radio (SDR) Approach to Radar
10:43
QIQ Systems
Рет қаралды 76 М.
ВСЕ МОИ ТЕЛЕФОНЫ
14:31
DimaViper Live
Рет қаралды 70 М.
Samsung S24 Ultra professional shooting kit #shorts
0:12
Photographer Army
Рет қаралды 18 МЛН
📦Он вам не медведь! Обзор FlyingBear S1
18:26
Cadiz smart lock official account unlocks the aesthetics of returning home
0:30