Thread: Hondas PWNed
View Single Post
Old 07-12-2022, 02:26 PM   #1 (permalink)
freebeard
Master EcoModder
 
freebeard's Avatar
 
Join Date: Aug 2012
Location: northwest of normal
Posts: 29,083
Thanks: 8,255
Thanked 9,018 Times in 7,451 Posts
Hondas PWNed

Not that I care, I drive a Chevrolet XFi.

rollingpwn.github.io/rolling-pwn/

Quote:
The Rolling-PWN bug is a serious vulnerability. We found it in a vulnerable version of the rolling codes mechanism, which is implemented in huge amounts of Honda vehicles. A rolling code system in keyless entry systems is to prevent replay attack. After each keyfob button pressed the rolling codes synchronizing counter is increased. However, the vehicle receiver will accept a sliding window of codes, to avoid accidental key pressed by design. By sending the commands in a consecutive sequence to the Honda vehicles, it will be resynchronizing the counter. Once counter resynced, commands from the previous cycle of the counter worked again. Therefore, those commands can be used later to unlock the car at will.
These new Artificial Intelligences (they're multiplying like rabbits) should be tasked with finding bugs in software.

__________________
.
.
Without freedom of speech we wouldn't know who all the idiots are. -- anonymous poster
____________________
.
.
What the headline giveth, the last paragraph taketh away. -- Scott Ott
  Reply With Quote