new·The score now tells you which way it movedA brain's exam only ever grows: its own material writes questions, and so does every question a real caller asked and did not get answered. The score is a percentage over that growing set, so a brain that learned more could post a smaller number — and this week three did. One of them answered two MORE questions than the week before and showed eighteen points less. Printed as a single percentage, that reads as decline to a reader and as punishment to anyone who contributes material.all news →
mozg.beta
Sign in

OWASP Cheat Sheets · all subjects

attack-surface/automotive

9 notes, read out of this brain and free to use. Each one was extracted from a source and is re-checked against its exam.

CAN bus lacks adequate security measures

Controller Area Network (CAN) is used in many vehicles without adequate security measures. Attackers can intercept messages on the CAN bus to send unauthorized commands to critical vehicle systems such as brakes and steering.

OTA updates lack proper authentication and encryption

Over-the-air (OTA) updates may lack proper authentication and encryption controls. Attackers can spoof update servers and deliver malicious firmware that compromises the vehicle's control systems through wireless communication channels including cellular and Wi-Fi.

Telematics systems have insufficient security controls

Telematics units that connect vehicles to cloud services may have insufficient security controls. Weak API security can allow attackers to access sensitive vehicle data or manipulate vehicle settings remotely through cloud interfaces, telematics gateways, and mobile applications.

Third-party software components have known vulnerabilities

Third-party software components integrated into vehicle systems may have known vulnerabilities. For example, vulnerable third-party libraries in infotainment systems can be exploited to execute arbitrary code.

Physical access to OBD-II port enables system manipulation

Physical access to the vehicle allows attackers to connect malicious devices to the OBD-II port to alter vehicle settings or firmware. Attack surface includes diagnostic ports, service stations, and unsecured vehicle access.

Weak authentication in automotive mobile apps

Many automotive systems use weak authentication methods. Mobile apps with easily guessable passwords allow attackers to log in, change vehicle settings, or track location. Attack surface includes mobile applications, web interfaces, and vehicle systems that allow remote access.

Inadequate data protection during transmission and storage

Vehicles collect extensive data that is often inadequately protected. Unsecured data transmission channels can expose sensitive user data such as location history and personal preferences to eavesdroppers. Attack surface includes data transmission channels, cloud storage, and interfaces with third-party services.

Integration vulnerabilities between vehicle systems

Integration of various systems such as infotainment and navigation can create vulnerabilities if not properly secured. Attackers can exploit vulnerabilities in interconnected components to gain access to the vehicle's control systems through APIs and communication channels between systems.

Legacy vehicle systems use outdated security protocols

Many vehicles still use legacy systems with outdated security protocols. Attackers can exploit known vulnerabilities in older vehicle models that have not been patched to gain control over critical systems. Attack surface includes older vehicle models, diagnostic tools, and maintenance interfaces.

Give your agent this brain