Showing posts with label vehicle. Show all posts
Showing posts with label vehicle. Show all posts

Dec 5, 2020

中国AutoX 第5世代車 深圳で、Fortinet いろいろ、Virtual Patching

中国AutoXが完全無人の自動運転車を使った配車サービスを深センで開始! (12/04)

https://techable.jp/archives/143725

『第5世代の自動運転システム

  歩行者に道を譲ったり、路肩に停まっている車を避けるためにレーンを変更したり、と誰もいない運転席のハンドルが自動で動く』


その様子がこれ(↓)

AutoX puts fully driverless RoboTaxis on the roads in China (12/02)

https://www.youtube.com/watch?v=7GVL9Na1_9Q


CVE-2018-13379の件、

前にもここで取り上げた(1, 2)が、続報が先週から色々挙がっている。


6.7 GB worth of sensitive details citing Fortinet SSL VPNs vulnerability have been leaked on a prominent hacker forum. (11/25)

https://www.hackread.com/hacker-leaks-vulnerable-fortinet-ssl-vpns-login-credentials/


Hacker publishes credentials stolen from Fortinet’s FortiGate VPNs (11/25)

https://siliconangle.com/2020/11/25/hacker-publishes-credentials-stolen-fortinet-fortigate-vpns/

『Sridhara added that about 50,000 records belonging to banks, telecoms and government organizations were exposed by this data leak, including session-related information and plain-text usernames and passwords of Fortinet VPN users. “What’s most concerning is that even if the vulnerability is patched, the credentials are still at risk for credential stuffing attacks,” he said.』


2018の発表以降にパッチ適用した or これからする所は、全員パスワード変更した方が良い。

また、同じIDを他のサイトで使っている人は、そっちのパスワード変更もした方が良い。


FortiGate VPN Default Config Allows MitM Attacks (09/25)

https://threatpost.com/fortigate-vpn-default-config-mitm-attacks/159586/

『more than 230,000 vulnerable FortiGate appliances using the VPN functionality, researchers found. Out of those, a full 88 percent, or more than 200,000 businesses, are using the default configuration and can be easily breached in an MitM attack.』


解決には『manually replace the certificate in order to secure their connections appropriately』すれば良い。


また『Fortinet strongly recommends adhering to its provided installation documentation and process, paying close attention to warnings throughout that process to avoid exposing the organization to risk.』にも留意すべし。


Fortinet VPN with Default Settings Leave 200,000 Businesses Open to Hackers (09/25)

https://thehackernews.com/2020/09/fortigate-vpn-security.html

『"The Fortigate issue is only an example of the current issues with security for the small-medium businesses, especially during the epidemic work-from-home routine," Hertz and Tashimov noted.

"These types of businesses require near enterprise grade security these days, but do not have the resources and expertise to maintain enterprise security systems. Smaller businesses require leaner, seamless, easy-to-use security products that may be less flexible, but provide much better basic security."』

IT共同組合のような組織化を行い、多くの中小企業が加盟、インフラは共通化、サポート人員も共通化、ビジネスそのもので勝負、という体制ができれば良いのだろうが。


How to better defend your organization against remote access threats (03/08)

https://www.techrepublic.com/article/how-to-better-defend-your-organization-against-remote-access-threats/

次の脅威への対抗策紹介

  • DDoS attacks
  • VPNs : Palo Alto Networks, Fortinet, Pulse Secure それぞれアップデート他
  • Bluekeep exploits
  • Remote Desktop Protocol Attacks : 停止を安直に呼びかける代わりに、モニタリングを提案
  • Phishing


Why Virtual Patching is Essential for Vulnerability Mitigation (06/26)

https://www.fortinet.com/blog/business-and-technology/why-virtual-patching-essential-for-vulnerability-mitigation

『 A virtual patching is similar to a patch released by a vendor because it provides protection against a specific exploit. But in this case, the difference is that this patch is deployed at the network level using a IPS rule rather than on the device itself. It is sometimes also referred to as a proximity control as it stops a threat before it reaches its intended target.

  ..

In today’s dynamically changing environments, the traditional patch cycle simply cannot scale to keep pace with the sophistication and frequency of attacks, and the rate at which new vulnerabilities are being discovered and exploited as a result of the expansion of the digital attack surface.

Virtual patching should be considered an integral component of every organization’s patch management strategy. 』



Jun 1, 2017

車をハッキング!?

Bluetoothを使って車をハッキング (05/26)

 原文はこちらで、デモビデオも有る模様
     ↓
 Cars with Vulnerable WIFI Dongle can be Hacked via Bluetooth (04/16)

 ARGUS CYBE RSECURITY


Aug 23, 2016

PC1台で100台以上の車を盗んだ2人組が逮捕

PC1台で100台以上の車を盗んだ2人組が逮捕 (8/22)

『犯人たちは、自動車修理の業者が利用しているソフトウェアの海賊版を利用し、
 何もデータの入っていないキーを「持ち主の新しいキー」として登録していた
 可能性が高い。
 ...
 そのソフトウェアで勝手に登録内容を変更できないようにするため
 セキュリティが破られたのか、あるいは最初からそのような対策が
 存在していなかったのかは不明

   関連過去投稿

Aug 11, 2016

カーキーのハッキングと、盗難紛失事後策

・Hackers Steal More Than 100 Vehicles, Transport Them to Mexico
  (ビデオは2016/06/20付け)
  http://abcnews.go.com/GMA/video/hackers-steal-100-vehicles-transport-mexico-41138325
  ←どうやってカーシステムに侵入するのか詳しくは分かっていない?

08.23追記、ここから--->
 これか
  ↓
 PC1台で100台以上の車を盗んだ2人組が逮捕 (8/22)

『犯人たちは、自動車修理の業者が利用しているソフトウェアの海賊版を利用し、 何もデータの入っていないキーを「持ち主の新しいキー」として登録していた 可能性が高い。 ...
 そのソフトウェアで勝手に登録内容を変更できないようにするため セキュリティが破られたのか、あるいは最初からそのような対策が 存在していなかったのかは不明 』
08.23追記、ここまで--->
・How to Safeguard Your Car From Hackers
  http://abcnews.go.com/WNT/video/safeguard-car-hackers-40362889
 ←車に送信するキーのコード(パスワードみたいなもの?)を、盗んで悪用する手口のよう。
  防ぐには、車をロックした後 数回キーボタンを押せ、とのこと。
  こうすると、初回の盗まれたかもしれないコードが別のコードに変わるので、とのこと

・自転車が盗まれた時にスマホを利用した追跡方法とは? (2016/07/24)
  http://amazingnewtech.com/TrackR/JP/a-315/
  ←GPSデバイスを付けておき、万一の時、スマホアプリで探す
  民生GPSの精度の限界にも注意が必要かも。
 
 Amazonにもありました 
 https://www.amazon.co.jp/s/ref=nb_sb_noss?field-keywords=TrackR

Mar 30, 2016

スマホロック解除。car hack ほか

・「故人のスマホロックを外したい」、デジタル遺品取得の壁 (2016/03/29)
  http://itpro.nikkeibp.co.jp/atcl/column/16/032400070/032400002/

・スマートキーをハックして遠隔チームプレイで手際よく高級車を盗み出す驚愕の手口が明らかに (2016/03/24)
  http://gigazine.net/news/20160324-car-smartkey-amplifier-attack/

  > 自動車のセンサーが送る信号を増幅して、遠隔地のスマートキーに信号を送りつけて、
  > あたかもドライバーが車内にいるかのように偽装してエンジンをかける窃盗手口

 前述手段を実行できる人なら
 『車内に侵入しさえすれば』という所は、ネックにはならない、ということかな?

・WindowsとSambaに重大な脆弱性、「サーバ管理者はパッチ公開に備えて」とMS (2016/03/24)
  http://www.itmedia.co.jp/enterprise/articles/1603/24/news057.html

  > WindowsおよびSambaのほぼ全バージョンに存在する
  > 重大な脆弱性に関する情報を4月12日に開示し、パッチを提供する

  > この脆弱性は「Badlock」と命名

Mar 1, 2016

脆弱性 (3/1)

・日産「リーフ」のアプリに脆弱性、他人の車を遠隔操作可能に (2016/02/25)
  http://www.itmedia.co.jp/enterprise/articles/1602/25/news067.html

 『リーフのアプリのAPIには認証の仕組みが実装されておらず
  個々の車に割り当てられている車両識別番号(VIN)の
  下5ケタさえ分かれば、
  他人のリーフを制御できてしまう』

 『実験ではハント氏の操作でヘルム氏のリーフの
    エアコンやファンを作動させることに成功。
  リーフの走行日時や距離などの運転履歴も取得できた。』

  とは言え、ハンドルやアクセル、ブレーキまでは制御出来てない模様。

 以前の同様案件も参考までに
  ↓
・クライスラーのcar hackingの件 (2015/07/26)
  http://akasaka-taro.blogspot.jp/2015/07/car-hacking_1.html

Jul 26, 2015

クライスラーのcar hackingの件

・クライスラー社の車、システムハッキングで遠隔操作される危険性が明らかに (2015.07.22)
 http://www.gizmodo.jp/2015/07/post_17726.html
 ←飛行機さえハックされる時代。
  実機デモで社会の関心が一気に高まった。

 元記事はこちら。デモビデオあり
 ↓
 Hackers Remotely Kill a Jeep on the Highway—With Me in It (2015/07/21)
 http://www.wired.com/2015/07/hackers-remotely-kill-jeep-highway/

・クライスラー、ハッキング対策で140万台リコール
 ソフト更新し遠隔操作防ぐ (2015/7/25)
 http://www.nikkei.com/article/DGXLASGM25H19_V20C15A7MM0000/
 >社会的な関心が高まっていることから自主的リコールに切り替えた
 ←良い判断。
  今後はパッチチューズディみたいな自動化が必要になるのかな?

・DEFCON 22 Car Hacking with Charlie Miller & Chris Valasek (2014/08/15)
 https://www.youtube.com/watch?v=lpZulZ1rFmY
 ←チャーリーとクリスが、インタビューに答えている。
  「Car Hackingを二年前からやっている」との事。
  チャーリーがオチャメです。

・How to Hack a Car: Phreaked Out (Episode 2) (2014/05/29)
 https://www.youtube.com/watch?v=3jstaBeXgAs

・Charlie Miller - Car Hacking (2013/11/13)
 https://www.youtube.com/watch?v=kWiOVwP5GTE
 ←ごく初期のものらしいデモ
  プリウスで?

・Car Hacking DARPA (2013/06/29)
 https://www.youtube.com/watch?v=zurrQiETDHA

・まとめ的リンク(ソフトウェアアップデート、対象車種一覧ほか)
 ↓
 http://www.st.ryukoku.ac.jp/~kjm/security/memo/2015/07.html#20150723_Uconnect

---> 2016.07.16追記
・自動車大手のFiat Chryslerがバグ報奨プログラムを導入、1件あたり最高1500ドル (07/14)
  http://itpro.nikkeibp.co.jp/atcl/news/16/071402093/