White hat hackers at Pen Test Partners were able to exploit critical vulnerabilities in popular ‘smart’ car alarm apps and unlock vehicles, listen in on driver conversations and even kill the engine whilst running.
Ken Munro, the founder of Pen Test Partners, explains that an advert by one of the vendors concerned and stating the system was unhackable had piqued interest initially. That’s never a great claim to make as any security expert will tell you that there is no such thing as being 100% secure. They invested nearly £4,000 ($5,000) in high-end smart car alarms systems in order to put them to the test. The systems, built by Russian alarm maker Pandora and California-based Viper — or Clifford in the U.K., were vulnerable to an easily manipulated server-side API, according to researchers at Pen Test Partners, a U.K. cybersecurity company. In their findings, the API could be abused to take control of an alarm system’s user account — and their vehicle.
It’s because the vulnerable alarm systems could be tricked into resetting an account password because the API was failing to check if it was an authorized request, allowing the researchers to log in.
Although the researchers bought alarms to test, they said “anyone” could create a user account to access any genuine account or extract all the companies’ user data. In one example demonstrating the hack, the researchers geolocated a target vehicle, track it in real-time, follow it, remotely kill the engine and force the car to stop, and unlock the doors. The researchers said it was “trivially easy” to hijack a vulnerable vehicle. Worse, it was possible to identify some car models, making targeted hijacks or high-end vehicles even easier.
Amongst the vehicles that could be at risk from this particular vulnerability according to Munro are Mazda 6, Range Rover Sport, Kia Quoris, Toyota Fortuner, Mitsubishi Pajero, Toyota Prius 50 and RAV4.
A contact, posted this biblical retelling of a scenario we observe quite often on our beloved "Autos and Car talk section" , I had a good laugh and decided to share.
bettercreature: Leaving your husband because he cheats make no sense especially when you have 3 kids already This is no America or Canada All men cheats Even the broke ones cheats let alone those that has money
Gossiplover: A shared by the Nigerian Army on social media.
"Fellow compatriots, we update you on the brutal murder of Major General Idris Alkali. Following today's recovery of his Toyota car from a pond in Jos, below are some personal belongings of the late Major General, retrieved from the car. His body is yet to be recovered. We will keep you posted with progress. May his soul rest in perfect peace. Ameen".
Weeks back, I inquired for price of a 1MZ engine with VVTi for a Toyota Avalon in the cartalk chatroom and received a mention asking "Why am replacing engine?"
Prior to my enquiry, car was idling roughly and overheating after every 10 - 30km drive, my technician dismantled engine, replaced parts (bearings, 2 pistons and other stuffs) , bill was about 90-110k. 2weeks later car overheated, crankshaft knocked, in fact bad bad things happened.
Conclusion: Grade A Japan engine 270k Borale I heard is between 110 - 160k .