Thread: Hondas PWNed
View Single Post
Old 07-12-2022, 01:26 PM   #1 (permalink)
freebeard
Master EcoModder
 
freebeard's Avatar
 
Join Date: Aug 2012
Location: northwest of normal
Posts: 29,354
Thanks: 8,351
Thanked 9,116 Times in 7,526 Posts
Hondas PWNed

Not that I care, I drive a Chevrolet XFi.

rollingpwn.github.io/rolling-pwn/

Quote:
The Rolling-PWN bug is a serious vulnerability. We found it in a vulnerable version of the rolling codes mechanism, which is implemented in huge amounts of Honda vehicles. A rolling code system in keyless entry systems is to prevent replay attack. After each keyfob button pressed the rolling codes synchronizing counter is increased. However, the vehicle receiver will accept a sliding window of codes, to avoid accidental key pressed by design. By sending the commands in a consecutive sequence to the Honda vehicles, it will be resynchronizing the counter. Once counter resynced, commands from the previous cycle of the counter worked again. Therefore, those commands can be used later to unlock the car at will.
These new Artificial Intelligences (they're multiplying like rabbits) should be tasked with finding bugs in software.

__________________
.
.
Without freedom of speech we wouldn't know who all the idiots are. -- anonymous poster

___________________
.
.
Impossible is just something we haven't done yet. -- Langley Outdoors Academy
  Reply With Quote