• Home
  • |
  • Black Hat Europe 2022 Presentation

Back-connect to the Connected Car. Search for Vulnerabilities in the VW Electric Car

The attack surface on modern connected cars is broad – Wi-Fi, Bluetooth, V2X, 2G/3G/4G, custom RF protocols, CAN, OBD2 interfaces, automotive Ethernet, USB ports, remote diagnostics, telematics, and mobile apps. During the presentation, we will show part of the results of penetration testing the modern European electric Volkswagen car model ID3. Our discovered vulnerabilities and security problems in car architecture are also applicable for such Volkswagen models like ID4, ID5 and affect hundreds of thousands of electric cars on the roads.

We will demonstrate how hackers can receive root access in Infotainment and Gateway modules in the cars, install backdoors and what hackers can do remotely with hacked cars. We will demonstrate how hackers can bypass digital signatures in software updating procedures in Automotive Grade Linux, exploit arbitrary code execution vulnerability in the network service of the QNX7 system, extract keys from trusted zones of the Gateway, and use Wi-Fi for remote control of installed backdoors.

Presenter

Yuriy Serdyuk | Lead Security Researcher, NavInfo Europe B.V.
Alexey Kondikov | Embedded Security Researcher, NavInfo Europe B.V.
Sergey Razmakhnin | Head of Cybersecurity, NavInfo Europe B.V.
Khaled Sakr | Security Researcher and Penetration Tester, NavInfo Europe B.V.

download the full report