DEF CON 32 - Speed Bumps and Speed HacksP: Adventures in Car Mfg Security - Paulo Silva, David Sopas

DEF CON 32 - Speed Bumps and Speed HacksP: Adventures in Car Mfg Security - Paulo Silva, David Sopas

Source: YouTube · DEFCONConference · published Oct 16, 2024 · 31:31

Cybersecurity
No ratings yet Log in to rate
Transcript Available
Description

A security assessment of nine car manufacturers reveals critical vulnerabilities in APIs, third-party software, and misconfigurations that can lead to data exfiltration and unauthorized access. The presentation demonstrates how chaining simple vulnerabilities—such as XSS, open redirects, and misconfigured AWS S3 buckets—can result in significant impact and prompt responsible disclosure.

Key Takeaways:
• Swagger UI XSS (3:27–4:26) enables attackers to inject malicious JSON payloads, leading to session hijacking and data theft; 3:27
• Outdated WordPress plugin with arbitrary file read (5:00–6:50) exposes database credentials and internal configurations; 5:00
• API cross-site scripting (9:00–11:35) allows retrieval of sensitive vehicle data (e.g., VIN, fuel levels) without user interaction; 9:00
• Open redirect and UI redressing (17:00–18:50) enables credential theft via phishing with malicious redirect URIs; 17:00
• S3 bucket subdomain takeover (22:00–23:10) allows attackers to create and control content after bucket deletion; 22:00
• Misconfigured Siteminder authentication (21:00–22:00) exposes XSS via user input, enabling token exfiltration; 21:00

Even common third-party tools and misconfigurations can be exploited to gain deep access to vehicle data, underscoring the need for regular audits, timely patching, and responsible disclosure.

Sources:

  • 3:27 Swagger UI XSS vulnerability
  • 5:00 Outdated WordPress plugin exploitation
  • 9:00 API XSS

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Cybersecurity. Commonly maps to: Security and Risk Management, Security Operations. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

okay uh first of all thank you for joining it's a great pleasure to be here today uh I'm not sure how many of you have a driving license but I kindly ask you to fasten your seat belts because this is going to be a quick one uh my name is Paul Sila I'm a security researcher and pentester at CH 49 uh but I've started as a software developer I did it for more than 15 years what it was plenty of time to do all sort of mistakes I'm also co-author of something that you may have heard about like the OAS PPI Security top 10 uh but the topic here today is another one with us we we have David yeah so uh my name is David soos um I'm a security researcher for a long time um more than 15 years I especially like research and uh focusing also on High level pen testing uh I usually I already spoke uh on e…