
DEF CON 32 - Compromising Electronic Logger & Creating Truck2Truck Worm -Jake Jepson, Rik Chatterjee
Source: YouTube · DEFCONConference · published Oct 16, 2024 · 19:42
Researchers from Colorado State University demonstrate how they compromised Electronic Logging Devices (ELDs) in commercial trucks, creating the first wireless drive-by attack that could control vehicle functions and potentially spread between trucks 0:00-0:11.
Key Takeaways:
• Commercial trucks with ELDs have significant cybersecurity vulnerabilities as these government-mandated devices lacked proper security standards in their implementation 3:01-4:30
• The researchers successfully performed a wireless drive-by attack, flashing malicious firmware to an ELD that allowed them to disable the accelerator and control the truck's speed 1:53-2:28
• By reverse engineering the ELD firmware, they discovered hardcoded credentials, unsigned firmware updates, and a secret API that allowed arbitrary CAN message transmission 10:47-11:41
• They created a proof-of-concept worm that could spread from truck to truck when vehicles are in close proximity, such as at truck stops or during highway travel 17:15-18:48
While the manufacturer responded responsibly and patched the specific vulnerabilities, the researchers argue that the fundamental security problems in ELDs stem from inadequate government regulations that need to be addressed 19:02-19:28.
Sources:
- 0:00-0:11 Introduction to the topic of compromising ELDs
- 1:53-2:28 Description of the wireless drive-by attack
- 3:01-4:30 Background on trucks, ELDs, and security issues
- 10:47-11:41 Discovery
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 0.5 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
uh that was uh quite the introduction for compromising an electronic logging device uh and creating a truck to truck worm um but that's what we're going to be talking about so my name is Jake this is Rick and uh Rick take it away thanks Jake so we are systems engineering Master students from Colorado State University and we work uh with Dr Jeremy Dy uh and primarily concentrate our research on cyber security of heavy vehicles and here's a video of the work we have done hopefully it plays alongside the truck you reflash the electronic device which is running its soft firmware with a malicious firmware uh that will slow down the truck uh once it starts executing uh we were successful in this attack the car droke up alongside it uh about 30 seconds later the truck begins to slow down and the …