
DEF CON 33 - How API flaws led to admin access to 1k+ USA dealers & control of yr car - Eaton Zveare
Source: YouTube · DEFCONConference · published Oct 10, 2025 · 22:28
Optimized Summary (Final Version – Based on Raw Transcript & Feedback):
A critical, low-complexity vulnerability in a major automaker’s nationwide dealer management system—used by over 1,700 U.S. dealerships—allowed a single attacker to gain full national access to customer data, vehicle control, and internal operations. The flaw was one-line missing validation in an invite token check, enabling unauthorized account creation without proper verification.
How the Exploit Worked:
Bypassing Invite-Only Login:
The system required a valid invite token for registration. Using CSS to force display of a hidden registration form, the attacker submitted it with a blank invite token—successfully creating a user account.Exploiting Limited Session Profile Updates:
A feature allowing limited profile edits (e.g., correcting name errors) was abused to establish a temporary session. This granted access to the backend JavaScript files and exposed an internal admin user creation endpoint.Bypassing Frontend Protections:
The attacker patched frontend logic—disabling error messages and redirect blocks—to avoid authentication prompts and gain access to the admin panel.Creating a National Admin Account:
By submitting a user creation request with full admin privileges (national, regional, sales, finance), the attacker successfully created a national admin account with complete access across all dealerships.
What the Attacker Could Do:
Access PII and Financial Data:
Retrieved names, addresses, phone numbers, driver’s license details, insurance info, and dates of birth from loaner car platforms and customer databases (over 650,000 survey entries).Remote Vehicle Control:
Reassigned ownership of vehicles via a flawed enrollment process—effectively enabling remote start, engine control, and real-time tracking without notifying original owners.
*Affected:
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 0.5 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
So, as you as you can probably read from the title, you're probably wondering, is that is that really true? Did that guy really hack a thousand dealerships out there? I'm here to tell you it is true, but it hasn't been disclosed until today. It's a brand new vulnerability that I discovered earlier this year, and happy to be able to disclose it for the first time today. So, thank you so much for coming out. Hope you enjoy it. [Applause] So, a little bit about me. I am I've been dabbling in automaker stuff for a few years now. I started with Toyota and that's where I kind of gained my fame originally and it got me my first job actually and since then I've decided to try and some target some other automakers like Honda Volvo and I've explored a few others since then including this one I unfor…